FSB hijacks thousands of Finnish business routers

Russian espionage targets the forgotten hardware sitting at the edge of Europe's networks.
Image composition · tobriefThe useful target for Russian espionage is rarely the smart fridge or the voice assistant. It is the router nobody has updated since it was installed, sitting in a server cupboard, quietly forwarding every byte of a company's traffic. Finnish and Dutch intelligence agencies said so this month, in warnings that deserve closer reading than the headlines suggested.
Why a router is the perfect spy
A router is the front gate and mailroom of every network. Nearly all traffic flows through it. If an attacker controls that device, a compromised business router can make Russian intelligence traffic look as if it came from an ordinary company in Helsinki rather than a state-controlled server. That alone is valuable: it hides the origin of espionage behind someone else's internet connection (NSA).
But attribution masking is just the start. A compromised router can also harvest login credentials passing through it and redirect traffic to hostile servers without anyone inside the network noticing.
Finland's security police Supo and military intelligence warned companies about Russian cyber espionage tied to the FSB's 16th Center, a specific unit within Russia's Federal Security Service (Supo, Finnish Defence Forces). The targets are what security professionals call "edge devices," the equipment that sits at the boundary between a private network and the open internet. In practice, that means business routers and network gateways. A July 2026 joint advisory from the NSA and partner agencies published specific tactics the FSB uses and mitigations companies can apply (NSA, Supo).
The entry methods are mundane. Default passwords never changed. Firmware years out of date. Admin panels left accessible from the open internet. Supo assessed the warning could concern at least thousands of Finnish companies (MTV Uutiset).
A warehouse camera becomes a military sensor
The Dutch case shows how the same neglect creates a different kind of threat. The Netherlands' intelligence services AIVD and MIVD confirmed that Russian state actors compromised IP cameras along Dutch military-logistics routes to monitor weapons shipments heading to Ukraine (Rijksoverheid, AIVD). A camera installed for ordinary building security becomes a military-intelligence sensor the moment it overlooks the wrong loading bay.
The Dutch services described a "large-scale" international operation targeting NATO member states, though only a small number of Dutch cameras were confirmed compromised (Rijksoverheid). Estonia's ERR reported the same findings as a warning for every country along Ukraine's supply chain (ERR).
The law fixes tomorrow's devices, not yesterday's
Europe has a regulatory answer. The EU Cyber Resilience Act requires connected products sold in the EU to be secure by design, with mandatory vulnerability handling through their support period (EUR-Lex). That should improve the next generation of routers and cameras reaching the market.
The practical gap is obvious: millions of devices are already deployed. Routers in server cupboards, cameras on warehouse walls, intercoms at building entrances, many running outdated software with factory credentials. Regulation shapes what gets sold tomorrow. It cannot patch what was bolted to a wall five years ago (European Commission).
The advice from Finnish and Dutch agencies comes down to treating these devices like the small computers they are: change default passwords, update firmware, disable remote access that isn't needed, and stop leaving admin panels open to the internet (Supo, AIVD).
What the Finnish and Dutch cases share is a lesson about geography reshaping risk. The same weak password on the same always-on device means corporate espionage in Helsinki, military surveillance in Rotterdam and NATO logistics exposure in Tallinn. Russia does not need every connected device to be compromised. It needs enough neglected ones in useful places. Based on the public evidence so far, routers and IP cameras are providing exactly that: Europe's vast layer of forgotten infrastructure, quietly trusted and rarely maintained.
How was this article?
Help us get better
Help us get better
Details about this article
- Model:
- claude-opus-4-6
- Generated:
- 7/15/2026, 2:43:22 AM
- Pipeline run:
- eu_pipeline_20260715_005006
- Watermark:
- SynthID (Google's invisible watermark)
- Human review:
- None before publication