Alleged Russian compromise of networking equipment
Date of report
  • April 2018
  • Believed to be associated with Sandworm. Also known as VPNFilter.
The U.S. Department of Homeland Security and the UK National Cyber Security Centre issued a joint alert warning of a Russian state-sponsored campaign to compromise networking equipment, such as routers and switches, to support their cyber operations. A few weeks later, the FBI took control of a botnet with over five hundred thousand compromised devices and issued a public request that individuals with certain router models restart them.
Suspected victims
  • Worldwide
  • Ukraine
  • United States
  • United Kingdom
Suspected state sponsor
  • Russian Federation
Type of incident
  • Sabotage
Target category
  • Private sector
Victim government reaction
  • Yes
Policy response
Suspected state sponsor response