UK exposes Russian cyber unit hacking home routers to hijack internet traffic
2026-04-07T14:52:00Z•29342af6b7d10c32727dbd2036f4686540423ff8b517b05b404c3110e8dd626e
C2KDDoSIC3MedusaRostelecomRussiaSOHO routerscrypto theftcybercrimedata exfiltrationeducation sectorfraudnation-statenetwork interceptionoutdated firmwareransomwarerapid lateral movementrouter compromisetraffic hijackingweak-credentialszero-day
What happened
Multiple concurrent cyber incidents and trends pose elevated risk: UK authorities disclosed a Russian cyber unit is compromising small office/home office (SOHO) routers and similar internet‑exposed network devices—often via weak/default settings or outdated firmware—to hijack and redirect internet traffic. Separately, a large DDoS disrupted services from Russian ISP Rostelecom, Northern Ireland’s centralized C2K school network suffered a disruptive intrusion, and Microsoft warned the Medusa ransomware group is leveraging zero‑days to move from initial access to exfiltration and encryption in ~
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- therecord_media
- Record identifier
- 29342af6b7d10c32727dbd2036f4686540423ff8b517b05b404c3110e8dd626e
- Enrichment time
- 2026-04-07T14:52:00Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.