FSB Hijacks Finnish Business Routers

Russian espionage targets the forgotten hardware sitting at the edge of Europe's networks.
Image composition · tobriefThe useful target for Russian espionage is rarely the smart fridge or the voice assistant. It is the router nobody has touched since the installer left, sitting in a server cupboard and carrying every byte of a company's traffic. Finnish and Dutch intelligence agencies said as much this month. Their warnings deserve more attention than the headlines gave them.
Why a router is the perfect spy
A router is the front gate and the mailroom of a network. Almost everything passes through it. If an attacker controls that device, Russian intelligence traffic can be made to look as though it came from an ordinary company in Helsinki rather than from a state-controlled server. That matters because it hides espionage behind someone else's internet connection (NSA).
That is only the first use. A compromised router can also collect login credentials moving across the network and redirect traffic to hostile servers without anyone in the office noticing.
Finland's security police Supo and military intelligence warned companies about Russian cyber espionage linked to the FSB's 16th Center, a named unit inside Russia's Federal Security Service (Supo, Finnish Defence Forces). The targets are what security people call "edge devices": equipment sitting between a private network and the open internet. In normal language, that means business routers and network gateways. A July 2026 joint advisory from the NSA and partner agencies set out the FSB's tactics and the basic mitigations companies can apply (NSA, Supo).
The entry points are ordinary enough to be embarrassing. Default passwords left unchanged. Firmware not updated for years. Admin panels exposed to the open internet. Supo assessed that the warning could concern at least thousands of Finnish companies (MTV Uutiset).
For Malta, this is not a remote northern European problem. A small economy built around financial services, iGaming, professional services and logistics depends on always-on networks that often sit in offices, server rooms and outsourced facilities few people ever inspect after installation. In a micro-state, one badly maintained device in the wrong business can expose far more than one company.
A warehouse camera becomes a military sensor
The Dutch case shows how the same neglect creates a different kind of risk. The Netherlands' intelligence services AIVD and MIVD confirmed that Russian state actors compromised IP cameras along Dutch military-logistics routes to monitor weapons shipments heading to Ukraine (Rijksoverheid, AIVD). A camera installed for ordinary building security becomes a military-intelligence sensor once it points at the wrong loading bay.
The Dutch services described a "large-scale" international operation targeting NATO member states, though only a small number of Dutch cameras were confirmed as compromised (Rijksoverheid). Estonia's ERR reported the same findings as a warning for every country along Ukraine's supply chain (ERR).
That logic travels easily. Cameras at ports, warehouses, business parks and industrial estates are not glamorous technology. They are part of the background, like the intercom at a block of flats or the router in a back office. But when they overlook cargo, diplomats, military contractors or sensitive commercial activity, they become useful intelligence collection points.
The law fixes tomorrow's devices, not yesterday's
Europe has a regulatory answer. The EU Cyber Resilience Act requires connected products sold in the EU to be secure by design, with mandatory vulnerability handling throughout their support period (EUR-Lex). That should improve the next generation of routers and cameras reaching the market.
The gap is practical and immediate. Millions of devices are already in use: routers in server cupboards, cameras on warehouse walls, intercoms at building entrances, many running outdated software with factory credentials. Regulation shapes what is sold tomorrow. It does not patch what was screwed to a wall five years ago (European Commission).
The advice from Finnish and Dutch agencies is blunt because the problem is basic. Treat these devices like the small computers they are: change default passwords, update firmware, disable remote access that is not needed, and stop leaving admin panels open to the internet (Supo, AIVD).
The Finnish and Dutch cases show how geography changes the meaning of the same weakness. The same weak password on the same always-on device can mean corporate espionage in Helsinki, military surveillance in Rotterdam and NATO logistics exposure in Tallinn. In Malta, where critical economic sectors are concentrated and relationships between business, state and service providers are unusually close, the margin for neglect is thinner than it looks.
Russia does not need every connected device to be compromised. It needs enough neglected devices in useful places. On the public evidence so far, routers and IP cameras are providing just that: Europe's wide layer of forgotten infrastructure, trusted by default and maintained only when something finally breaks.
How was this article?
Help us get better
Help us get better
Details about this article
- Model:
- claude-opus-4-6
- Generated:
- 7/15/2026, 2:43:22 AM
- Pipeline run:
- eu_pipeline_20260715_005006
- Watermark:
- SynthID (Google's invisible watermark)
- Human review:
- None before publication