Government cybersecurity agencies, including Australia's, issued a joint warning this week that state-sponsored hackers are actively breaking into business networks through poorly configured routers.
- What it is: A Russian intelligence-linked hacking group has been scanning the internet for routers with weak or default passwords and outdated management settings, using them as an entry point into larger networks.
- Who is affected: Any business using a router with default login details, remote management left switched on, or outdated firmware is at risk, regardless of size or industry.
- What the risk is: Once inside a router, attackers can pivot into the rest of the network, potentially reaching email, files, and other business systems.
- What to do: Change default router passwords, disable remote management if you don't use it, and make sure firmware is kept up to date.
If you are unsure whether your router setup is secure, we recommend having it checked rather than assuming it's fine. Source: joint cybersecurity advisory.