The Security Service of Ukraine (SSU) , in cooperation with the Federal Bureau of Investigation (FBI) and law enforcement agencies from the European Union and Poland, has uncovered a large-scale cyber-espionage operation conducted by Russia’s military intelligence service (GRU), UATV English
According to the SSU, Russian operatives hacked hundreds of office and Wi-Fi routers (SOHO devices) belonging to citizens in Ukraine, the EU, and the United States. The operation specifically targeted devices that did not meet modern cybersecurity standards.
Once access was gained, the attackers redirected internet traffic through a network of controlled DNS servers. This allowed them to act as intermediaries in online communications and collect sensitive data, including passwords, authentication tokens, and even emails that are typically protected by SSL and TLS encryption protocols.
Investigators believe the stolen data was intended for use in future cyberattacks, disinformation campaigns, and intelligence-gathering operations. Particular attention was given to communications involving government officials, members of Ukraine’s Defense Forces, and employees of the defense-industrial sector.
As a result of the joint international cyber operation, more than 100 servers were blocked and hundreds of compromised routers in Ukraine were secured, significantly weakening the GRU’s intelligence capabilities and preventing potential sabotage at the software level.
Efforts are ongoing to identify and hold accountable all individuals involved in the cybercrime.
The SSU urged all router owners to check their device models and software versions, install the latest security updates, and replace outdated equipment if it is no longer supported by manufacturers. Users are also advised to change access passwords, disable remote access from the internet, and review device settings for suspicious activity.
Telecommunication providers have been called on to assist their customers in implementing these cybersecurity measures.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
