Russian State Hackers Are Targeting Your Routers : Here’s What to Do

Let me ask you something: Would you leave your office’s front door wide open overnight?

Of course you wouldn't. You check the locks, you set the alarm, and you probably have a camera or two keeping watch. It makes sense. You’ve worked hard to build your business, and you want to protect it.

But here’s the problem: Most small business owners are unknowingly leaving their digital "front door" wide open.

And right now, some of the most sophisticated state-sponsored hackers in the world are looking for those open doors. Specifically, the Russian Foreign Intelligence Service (FSB) is actively targeting the very routers that connect your business to the internet.

The Threat: FSB Center 16 is Scanning Your Network

Earlier this month, a major joint advisory (AA26-194A) was released by CISA, the FBI, and the NSA. It revealed that a group known as FSB Center 16 is running a massive, multi-year campaign to compromise routers.

They aren't just looking for high-level government secrets. They are targeting energy, communications, healthcare, and financial services : including small businesses that support these sectors.

Business professional reviewing a security dashboard on a tablet

Here’s how they do it: They scan the internet for devices using old, insecure protocols like SNMP (Simple Network Management Protocol) versions 1 and 2c.

If your router is still using these out-of-date settings or, worse, still has the default "public" or "private" passwords, these hackers can walk right in. Once they are inside your router, they don't just sit there. They copy your configuration files, see your entire network map, and use that access to move deeper into your systems.

And if that's not enough to worry you, there's another front opening up. We are seeing a surge in exploitation of Microsoft SharePoint Server. Specifically, attackers are moving fast to use vulnerabilities like CVE-2026-45659 and CVE-2026-58644 to gain unauthorized access to internal files and documents.

It’s a double-sided attack. One side hits your hardware (routers), while the other hits your collaboration tools (SharePoint).

Why Your Small Business is at Risk

You might be thinking, "Why would Russian state hackers care about my small business?"

It’s a fair question. But here’s the truth: It’s not always about who you are. It’s about what you are connected to.

Many small businesses use consumer-grade or entry-level SMB routers that aren't properly configured for high-level security. These devices often come out of the box with "Smart Install" features enabled or default administrative credentials that are easily guessed.

Close-up of professional network cables and switches

For a group like FSB Center 16, your poorly configured router is a golden opportunity. It’s a quiet, low-effort way for them to establish a "foothold."

Once they control your router, they can:

  • Intercept your unencrypted internet traffic.
  • See who you are communicating with.
  • Launch further attacks against your customers or partners.
  • Steal VPN credentials to get full access to your internal servers.

Think of it like a thief getting a master key to your building. They might not rob you today, but they can come and go as they please until you change the locks.

The SharePoint Problem

While the router threat focuses on your perimeter, the SharePoint exploitation hits where your data lives.

SharePoint is the heart of collaboration for many of the businesses we serve at Platinum Web Services. It holds your contracts, your employee data, and your strategic plans.

The latest vulnerabilities (like CVE-2026-56164) allow attackers to bypass security checks if your server hasn't been patched. This means that even if you’ve locked your "front door" router, a hole in your software could let them climb in through a digital "window."

It’s not about blame – it’s about awareness. Most business owners are too busy running their companies to read technical advisories every morning. That’s why we’re here.

Platinum Insight: How to Secure Your Network Today

So, what can you do? You don’t need to be a cybersecurity expert to take the first steps toward safety.

Here is a checklist of actionable steps you should take immediately to protect your business from these state-sponsored threats.

1. Audit Your SNMP Settings

SNMP is a protocol used to manage devices, but the older versions (v1 and v2c) are incredibly insecure.

  • Disable SNMP entirely if you don't use it to monitor your network.
  • If you must use it, upgrade to SNMPv3, which uses encryption and real authentication.
  • Change the "Community Strings." If your router still uses "public" or "private" as a password, change it to something long and complex immediately.

Team of professionals collaborating in a modern conference room

2. Turn Off Cisco Smart Install

If you use Cisco equipment, check if "Smart Install" (SMI) is enabled. While it's meant to help set up new devices, it’s a favorite target for hackers because it often allows unauthenticated access.

  • Use the command no vstack to disable it on your switches and routers.

3. Lock Your Firewall Ports

Your firewall should act as a strict bouncer.

  • Block UDP ports 161 and 162 (SNMP) from the public internet.
  • Block UDP port 69 (TFTP), which hackers use to "pull" your configuration files out of your router.
  • Only allow management traffic from trusted, known IP addresses.

4. Patch Your SharePoint Server

If you run an on-premise SharePoint Server, you cannot afford to wait on updates.

  • Apply the latest Microsoft security patches for CVE-2026-45659 and CVE-2026-56164 immediately.
  • If you aren't sure how to do this, or if your version is reaching "end of life," it may be time to consider moving to managed Cloud Services where security updates are handled for you.

5. Update All Firmware

Just like your phone or your laptop, your router has an operating system (firmware). Manufacturers release updates specifically to close holes that hackers are using.

  • Check your router manufacturer's website for the latest firmware version.
  • Set a reminder to check for these updates at least once a month.

We’re Here to Help

Keeping up with international hacking groups and complex CVE numbers is a full-time job. You shouldn't have to worry about the security of your routers while you’re trying to scale your business.

At Platinum Web Services, we specialize in Cybersecurity Solutions that take this burden off your shoulders. We provide proactive strategy, meticulously handling system updates and using predictive analytics to ensure your IT infrastructure stays secure and operational.

Modern Wi-Fi router in a bright, clean office environment

Whether you need a full network audit or just want someone to handle your Laptop and Desktop Repairs, we offer personalized IT solutions that prioritize your peace of mind.

Don't wait for a "what if" to become a "what now." Let's work together to turn your network from a vulnerability into a fortress.

If you’re concerned about your router security or your SharePoint environment, get in touch with us today. We help businesses like yours stay safe every day.

For more updates on the latest threats, keep an eye on our Security Hub.

0 Comments