{"id":675606,"date":"2026-07-05T21:01:40","date_gmt":"2026-07-05T21:01:40","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/675606\/"},"modified":"2026-07-05T21:01:40","modified_gmt":"2026-07-05T21:01:40","slug":"russia-has-attacked-the-united-kingdom-again","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/675606\/","title":{"rendered":"Russia has attacked the United Kingdom \u2013 again"},"content":{"rendered":"<p>        Russian hackers have stolen government login credentials by hijacking Wi-Fi routers and silently redirecting victims\u2019 internet traffic through servers controlled by Moscow, <a href=\"https:\/\/www.telegraph.co.uk\/news\/2026\/07\/05\/russian-hackers-steal-government-logins\/\" rel=\"nofollow noopener\" target=\"_blank\">it has been reported<\/a>, in a campaign that Western intelligence agencies attribute to Russian military intelligence.<\/p>\n<p>The theft of British government logins,<a href=\"https:\/\/www.telegraph.co.uk\/news\/2026\/07\/05\/russian-hackers-steal-government-logins\/\" rel=\"nofollow noopener\" target=\"_blank\"> reported by The Telegraph on Sunday<\/a>, stems from a long-running operation by the hacking group known as APT28 or Fancy Bear, which the UK\u2019s National Cyber Security Centre assesses is almost certainly Unit 26165 of Russia\u2019s GRU. The group compromised thousands of poorly secured home and small office routers, including devices made by MikroTik and TP-Link, and altered their settings so that victims\u2019 web traffic passed through Kremlin-controlled infrastructure, a technique known as DNS hijacking.<\/p>\n<p>Once traffic is flowing through their servers, the hackers can redirect users to convincing spoof versions of login pages and harvest passwords along with the authentication tokens that keep users signed in, allowing the attackers to access accounts without needing two-factor authentication codes. Ukraine\u2019s security service, which took part in the international investigation, said the hackers acted as intermediaries in the online space to collect credentials and emails that would normally be protected by encryption.<\/p>\n<p>Research by Lumen\u2019s Black Lotus Labs identified at least 18,000 victims across around 120 countries, with government departments, law enforcement agencies and email providers among those compromised. The NCSC, which published its attribution in April, described the operations as \u201clikely opportunistic in nature,\u201d with the group casting a wide net before narrowing in on targets of intelligence interest as attacks developed.<\/p>\n<p>The FBI, whose Operation Masquerade sent commands to compromised routers on American soil to evict the Russian presence and reset their settings, said the GRU had indiscriminately compromised a wide pool of victims before \u201cespecially targeting information related to military, government and critical infrastructure.\u201d Intelligence and law enforcement services from the US, UK, Ukraine, Poland, Germany, Italy, Canada, Romania and other allies took part in the investigation that exposed the network.<\/p>\n<p><a href=\"https:\/\/www.telegraph.co.uk\/news\/2026\/07\/05\/russian-hackers-steal-government-logins\/\" rel=\"nofollow noopener\" target=\"_blank\">The Telegraph\u2019s reporting<\/a> indicates British government credentials were among the material taken, with the paper describing the operation as hijacking Wi-Fi systems to transfer secrets to the Kremlin. The government has not published detail on which departments were affected or what the stolen logins provided access to.<\/p>\n<p>Graeme Downie, the Labour MP for Dunfermline and Dollar, told the UK Defence Journal the pattern of Russian activity against the UK now spans every domain. \u201cWe\u2019ve now had Russian attacks on the UK on land, through poisonings of British citizens and arson attacks on the Prime Minister\u2019s car, in the air through drone incursions, at sea via threats to sub sea cables and now another cyber attack after involvement in the attack on JLR,\u201d he said.<\/p>\n<p>\u201cThe government need to rapidly increase UK preparedness and make sure the public know the impact and costs of these attacks on their daily lives. The public will then demand action to protect them from this ongoing conflict with Russia.\u201d<\/p>\n<p>The campaign adds to a lengthening record of Russian cyber operations against the UK as the NCSC and allies formally attributed the Star Blizzard political interference campaign to the FSB\u2019s Centre 18 in April, targeting parliamentarians across parties, and a New York Times investigation last month attributed the Jaguar Land Rover attack, the most economically damaging hack in British history at an estimated $2.5 billion, to a Russian group, prompting Defence Secretary Dan Jarvis to warn that hostile states had realised the most effective way to attack is by quietly hollowing out the economy rather than through direct military confrontation.<\/p>\n<p>The head of the NCSC, Richard Horne, said in April that the most serious cyberattacks against the UK now come from hostile states including Russia, Iran and China, urging British organisations to prepare for large-scale attacks. Advice published alongside the router attribution urges users and organisations to update firmware, change default passwords, disable remote management interfaces and treat unexpected certificate warnings with suspicion.<\/p>\n","protected":false},"excerpt":{"rendered":"Russian hackers have stolen government login credentials by hijacking Wi-Fi routers and silently redirecting victims\u2019 internet traffic through&hellip;\n","protected":false},"author":2,"featured_media":511866,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[59,57,58,50,56,54,55],"class_list":["post-675606","post","type-post","status-publish","format-standard","has-post-thumbnail","category-united-kingdom","tag-gb","tag-great-britain","tag-greatbritain","tag-news","tag-uk","tag-united-kingdom","tag-unitedkingdom"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/675606","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=675606"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/675606\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/511866"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=675606"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=675606"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=675606"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}