FSB hijacks Finnish business routers

Russian espionage targets the forgotten hardware sitting at the edge of Europe's networks.
Cumadóireacht íomhá · tobriefThe most useful target for Russian espionage is often not the flashy device in the corner of the house. It is the router in a company server cupboard, installed years ago, barely thought about since, and quietly carrying every bit of traffic in and out of the business. Finnish and Dutch intelligence agencies have now put that neglected box at the centre of their warnings about Russian cyber activity.
Why a router is the perfect spy
A router is both the front gate and the sorting office of a network. Almost everything passes through it. If an attacker controls it, Russian intelligence traffic can be made to look as though it is coming from an ordinary company in Helsinki rather than from a state-linked server. That matters because it gives espionage the cover of someone else's internet connection (NSA).
That kind of disguise is only part of the value. A compromised router can also collect login credentials as they pass through, or steer traffic towards hostile servers, while the people inside the company see nothing unusual.
Finland's security police, Supo, and its military intelligence service warned companies about Russian cyber espionage linked to the FSB's 16th Center, a named unit inside Russia's Federal Security Service (Supo, Finnish Defence Forces). The targets are what cyber-security people call "edge devices": the kit that sits between a private network and the open internet. In plain terms, that means business routers and network gateways. A July 2026 joint advisory from the NSA and partner agencies set out the FSB's tactics and the steps companies can take to reduce the risk (NSA, Supo).
The way in is usually banal. Default passwords left unchanged. Firmware not updated for years. Administration panels reachable from the public internet. Supo assessed that the warning could apply to at least thousands of Finnish companies (MTV Uutiset).
A warehouse camera becomes a military sensor
The Dutch case shows the same problem from another angle. The Netherlands' intelligence services, AIVD and MIVD, confirmed that Russian state actors had compromised IP cameras along Dutch military-logistics routes to monitor weapons shipments bound for Ukraine (Rijksoverheid, AIVD). A camera bought for ordinary building security becomes a military-intelligence asset once it is pointed at the wrong loading bay.
The Dutch services described a "large-scale" international operation against NATO member states, while confirming only a small number of compromised cameras in the Netherlands itself (Rijksoverheid). Estonia's ERR reported the same findings as a warning for every country on the supply chain carrying support to Ukraine (ERR).
The law fixes tomorrow's devices, not yesterday's
Europe does have a regulatory answer. The EU Cyber Resilience Act requires connected products sold in the EU to be secure by design, with mandatory handling of vulnerabilities during their support period (EUR-Lex). That should make the next generation of routers and cameras less careless by default.
The weakness is in the stock already out there. Across Europe, there are routers in server cupboards, cameras on warehouse walls and intercoms at building entrances, many running old software and still using factory credentials. Regulation can shape what is sold next. It cannot patch the device fixed to a wall five years ago (European Commission).
The advice from the Finnish and Dutch agencies is simple because the failure is simple: treat these devices as small computers. Change default passwords, update firmware, turn off remote access where it is not needed, and stop leaving administration panels open to the internet (Supo, AIVD).
The Finnish and Dutch cases point to the same lesson: geography changes the meaning of a weak password. The same always-on device can become a corporate espionage tool in Helsinki, a military surveillance post in Rotterdam or a NATO logistics risk in Tallinn. Russia does not need every connected device to be compromised. It needs enough neglected devices in useful places. On the public evidence so far, routers and IP cameras are giving it that: Europe's broad layer of forgotten infrastructure, quietly trusted and rarely maintained.
How was this article?
Help us get better
Help us get better
Details about this article
- Model:
- claude-opus-4-6
- Generated:
- 7/15/2026, 2:43:22 AM
- Pipeline run:
- eu_pipeline_20260715_005006
- Watermark:
- SynthID (Google's invisible watermark)
- Human review:
- None before publication