AKMSecure
Back to Insights
Industry News

Your Routers Are Guarded By A Password Anyone Can Read

AKMSecure AKMSecure · Jul 23, 2026 · 7 min read

On July 13, nineteen government agencies from thirteen countries issued a joint warning: Russian intelligence has spent more than a decade quietly living inside the equipment that runs the world's networks. The advisory names the Defense Industrial Base directly, alongside energy, communications, financial services, healthcare, and state and local government.

The alarming part is not the break-in. It is how they got in. They did not crack any encryption, and they did not use a secret flaw. They logged in with a password that was never really secret in the first place.

How do you walk into a defense network without breaking anything?

The equipment that directs traffic around a network, the routers and switches sitting in every facility, is managed remotely. To do that, it asks for a password.

That password has three problems. It is set at the factory and published in the manual, so it is not confidential. It is shared across many devices and many people, so no one owns it. And it travels across the network unscrambled, so anyone watching the wire can simply read it.

Russian operators scan the internet looking for equipment that still accepts these passwords, and then they sign in. That is the whole technique. The agencies are explicit about it: the primary method is scanning.

Why does one weak password become a hundred?

This is the part worth understanding, because it explains how a decade-long presence is even possible.

  • Once inside, the intruder asks the device to send a copy of its own settings file. The device complies, because handing over that file is a normal, intended function.
  • That settings file lists more passwords, for other equipment across the business.
  • Some of those are stored in a format that can be unscrambled in seconds. Others are simply written out in plain text.
  • Those passwords open the next device, which holds the next settings file.

One guessed password does not get you one router. It gets you the map. The thing meant to protect the equipment is stored on the equipment, in a file the equipment will mail to anyone who asks politely.

The agencies also note that other adversaries use these same techniques. Different opponent, same unlocked door.

Doesn't changing the password fix it?

No, and this is where most security programs quietly stall.

Change it and you have a new password that also never changes, is also shared, also travels readable, and is also written into the settings file that the next intruder will collect. You have changed the lock without fixing the flaw, and the flaw is having a fixed secret at all.

The agencies say as much themselves. Their recommendation is not "choose better passwords." It is to stop using the older systems that depend on them, because those systems, in the advisory's own words, rely on "clear text shared passwords." That is nineteen agencies co-signing a document arguing that the shared secret itself is the defect.

What should an executive take from this?

Accept that premise and it does not stay contained to routers. Every fixed credential in the business makes the same bet: that a secret can sit unchanged for years and never be discovered by anyone. It is the same bet PKI makes, and more than 40% of reported attacks involve stolen PKI credentials. The bet keeps losing.

This is also what Zero Trust actually asks for, underneath the vocabulary. Verify every session on its own merits. Leave nothing behind that is worth stealing. A device guarded by a password that never changes fails that test before the conversation starts, and no amount of monitoring further downstream repairs it.

Where AKM fits

AKMSecure builds Autonomous Key Management™, a patented protocol that replaces PKI. The difference is simple to state. Instead of storing a fixed password on the device and hoping nobody finds it, AKM generates fresh keys for every session, automatically, and leaves nothing behind when the session ends. There is no certificate authority to depend on, no certificates to chase, and nothing sitting in a settings file waiting to be copied. Provision once, runs forever.

It also fits the equipment in this advisory, which matters, because most security products do not. AKM is small enough to run on constrained network and industrial hardware. It works without internet connectivity, which is what an isolated management network is supposed to be anyway. Organizations deploying it see credential risk fall by more than 95%, because the thing worth stealing stops existing between sessions.

Russian intelligence is not outsmarting cryptography on these devices. It is walking through doors that were never locked, in equipment that never had a real identity to verify. Thirteen countries just signed their names to that finding. The steps they recommend will hold the line, and they are worth taking this quarter. They will not close the gap, because the gap is the fixed secret, and you cannot manage your way out of that.

Defense Industrial Base organizations can sign up for NSA's cybersecurity services for the sector, and the advisory is worth forwarding to whoever owns your network. Then ask them a simple question: how many devices here are still guarded by a password anyone can read?

About AKMSecure

AKMSecure delivers a patented Autonomous Key Management™ protocol built to replace outdated PKI approaches with a dynamic, quantum-secure, air-gapped-capable architecture. Instead of relying on persistent credentials that can be stolen, reused, or abused, AKM enables independently verified sessions with no standing privileges left behind. The result is a model that better aligns with Zero Trust principles, reduces certificate-based risk, and supports resilient operations across enterprise IT, OT and Tactical Edge environments. Built to NSA-grade security standards and deployable as a lightweight SDK, AKMSecure helps organizations modernize trust at the protocol layer without rebuilding everything around it.

Share

Stay Ahead of Emerging Threats

Subscribe to our weekly threat briefing. No spam — just actionable cybersecurity intelligence.