The UK’s National Cyber Security Centre, alongside the NSA, CISA, and agencies from 18 countries, issued a joint advisory this week naming Russian FSB-linked hackers as the group behind a global campaign exploiting poorly configured routers. Unlike most state-backed cyber activity, which tends to target specific high-value organisations, this one is opportunistic — the attackers are scanning the entire internet for any device left exposed, then using whatever they find as a foothold to pivot deeper into a network. Communications, energy, financial services, and healthcare networks have already been compromised across the US and its allies, and there’s no reason to think UK small businesses are being deliberately excluded — they’re simply not the headline.
That’s the detail that matters most here: this isn’t a targeted attack on any one company. It’s a trawl. If your router is running on factory-default settings, an outdated management protocol, or a weak password nobody’s changed since installation, it doesn’t matter how small your business is — it will eventually get found.
What the attackers are actually exploiting
The advisory is specific about the method, and it’s refreshingly unglamorous. Russian FSB Center 16 actors are relying on three things: legacy management protocols like old versions of SNMP that were never designed with today’s threat landscape in mind, default or weak router credentials that were never changed after setup, and unnecessary services left switched on that widen the attack surface for no operational benefit. None of this requires sophisticated malware or a zero-day exploit. It requires a business that hasn’t looked at its router configuration since the day an engineer plugged it in.
Five checks that take under an hour
You don’t need a security team to close most of this gap. Log into your router’s admin panel — usually via a browser at an address printed on the device itself — and work through this list: change the default admin password to something unique and long; disable SNMP if you don’t actively use it for network monitoring, or upgrade to SNMPv3 if you do; check the firmware version against the manufacturer’s site and update if you’re behind; turn off remote management access unless you specifically need it; and disable any services (UPnP, Telnet, unused VPN endpoints) you don’t recognise or use. If your business doesn’t have anyone confident doing this, it’s a reasonable one-off ask for whoever manages your IT, or a good first job for an MSP relationship if you don’t have one yet.
Why this is worth doing even if you think you’re not a target
The instinct for a lot of small businesses is to assume state-sponsored hacking groups have no interest in them — and in a targeted sense, that’s usually true. But this campaign isn’t targeted. A compromised router in a 15-person accountancy firm is just as useful to an attacker building a botnet or pivoting toward a bigger supply-chain target as one in a large enterprise. KeepSafe tracks exactly this kind of incident pattern across UK businesses, and the consistent finding is that opportunistic, infrastructure-level compromises like this one are far more common — and far more preventable — than the targeted attacks that make headlines.
Who should own this task
For most small businesses, the router is the one piece of network hardware nobody actually owns. It’s not exciting enough for anyone to have taken responsibility for it, and it’s easy to assume “the internet company set it up, so it must be fine.” That assumption is exactly what this advisory is warning against — an ISP-supplied router configured years ago, with default credentials nobody thought to change, is precisely the kind of device this campaign is scanning for. If you have an IT contact, MSP, or even just a technically confident member of staff, assign this explicitly rather than assuming it’s covered.
The takeaway
This is a rare cybersecurity advisory where the fix genuinely costs nothing and takes under an hour: log into your router, change the password, update the firmware, and turn off what you don’t use. Do it this week rather than waiting for a reason to.