decrypted · 14 july 2026 · ransomware and cybercrime · vulnerabilities and patching · uk policy and law

Routers left on factory settings, and the sanctions that came the same day

On 13 July the UK, alongside eleven other countries, published a joint technical advisory on router security while the Foreign Office and the EU sanctioned two dozen Russian-linked cyber actors and the US Treasury separately sanctioned the VPN service and the credential-cleaning tool that ransomware crews rent by the month. Three announcements, one target: the infrastructure Russian state and criminal cyber operations run on. It is a useful reminder that "cyber security" isn't only patches and passwords, it is also economics, and this week the UK leaned on both levers at once.

The default password nobody changed

The advisory, co-signed by the NCSC and seventeen other agencies across twelve countries, describes a campaign by FSB Centre 16, the unit also known as Berserk Bear, Energetic Bear or Dragonfly, that has been mass-scanning the internet for routers running with factory settings switched on. Specifically: legacy SNMPv1 and SNMPv2 left enabled with their default "public" and "private" community strings, and Cisco Smart Install left active and unpatched. None of this requires a zero-day. SNMP community strings are effectively passwords baked into a 1980s protocol, and huge numbers of routers still ship, or get installed, with the default ones intact. It is less a lock being picked than a master key sitting under a doormat that half the street never bothered to move.

The affected sectors read like a list of what keeps a country running: communications, defence, energy, financial services, government and healthcare. The same FSB unit was formally attributed this week to the December 2025 attack on Poland's energy grid, an intrusion that could have cut power to 500,000 people in winter. The advisory's core recommendation is blunt: move to SNMPv3, kill the legacy versions outright, patch Smart Install, and use unique credentials on every management interface. NCSC director of national resilience Jonathon Ellison called it "decisive, actionable direction from the global security community that network defenders should implement."

The Secure by Design lesson is not subtle. A protocol that ships with a shared, guessable default credential is insecure by design, and asking thousands of network administrators to remember to change it is a strategy that has failed for decades. UK organisations running their own edge kit, and that includes plenty of mid-sized manufacturers and utilities who assume routers are boring, boxed-off infrastructure, should treat this advisory as a prompt to audit what is listening on their network edge, not just what is patched.

Sanctions as the other lever

The same day, the UK designated 24 individuals and entities and the EU a further nine people and four organisations, in what is being described as the first joint UK-EU cyber sanctions package. Targets included senior GRU figures accused of directing hybrid operations, the Rybar media network accused of election interference across Europe, and the operators behind Lumma Stealer, which Foreign Secretary Yvette Cooper's department says has hit at least 2,100 UK victims in six months through stolen credentials. Separately, the US Treasury sanctioned First VPN Service, its administrator, and a Belarusian seller of "cryptors" that help ransomware evade detection, coordinated with the UK's Foreign, Commonwealth & Development Office.

None of these sanctions will stop a determined FSB unit overnight. What they do is raise the operating cost of the infrastructure ransomware crews and state proxies both rent: no-log VPNs, cryptor services, bulletproof hosting. Technical hygiene and financial pressure are two sides of the same policy, and seeing them deployed together in one week is more coordinated than usual.

Also this week

A tutoring site that was actually a botnet. Researchers at JFrog traced 148 npm packages, dressed up as student proxy tools with names like "Riverbend Tutoring", that let schoolkids dodge content filters while quietly turning their browsers into a DDoS botnet against a US school's servers. One npm account published 116 of the packages in under 35 minutes with no rate limiting from the registry. It's a supply-chain story with no clever exploit at its centre, just an unmoderated package registry and a remote code loader the operators could rearm without ever shipping a new version. UK teams treating dependency scanning as a one-time SBOM exercise should note that this payload changed after installation, which a static scan would have missed entirely.

Hyperscalers become UK financial infrastructure, officially. From 13 July, AWS, Google Cloud, Microsoft and Oracle are formally Critical Third Parties to the UK financial sector, giving the Bank of England, PRA and FCA the power to demand information, run resilience tests and enforce rules directly on these providers. The oversight is narrow: it covers only the systemic services that underpin banks and insurers, not the general commercial cloud. It follows a 2024 finding that three providers handle 73% of UK financial-sector cloud workloads. Useful regulatory teeth where they exist, but a reminder that everyone outside financial services is still relying on the hyperscalers' own word for resilience.

Sources

If any of this raises questions about your own network edge or supply chain, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.