LeakySensey Rents Out Hacked Routers as a Proxy Network

Brendan Smith
Brendan Smith - Cybersecurity Analyst
4 Min Read
A router produces a rental ticket, illustrating the resale of compromised connections.
LeakySensey monetized unauthorized access to internet-facing devices.

A business renting out access to other people’s routers was exposed by an unsecured server of its own. Cybernews researchers call the operator LeakySensey: their September investigation describes a proxy inventory built by guessing weak credentials on internet-facing VPN devices, then selling access through websites, Telegram bots and resellers.

The discovery dates to July 20, 2026, when researchers found the operator’s server open. This is newly reported research into an older operation, not evidence that 87,000 routers were attacked this week.

The router becomes somebody else’s exit point

According to Cybernews, the operation searched for exposed PPTP, L2TP and SSH services and tried weak account credentials. Its targets included old routers, dedicated VPN appliances and network-attached storage. Successful access could be converted into a proxy endpoint that paying customers used to relay their traffic.

A proxy makes the compromised connection the visible departure point for somebody else’s requests. That is the practical distinction from simply stealing a Wi-Fi password: an intruder can monetize remote access to a device even when its owner still has working internet. Our guide to proxyjacking explains the broader bandwidth-theft model.

Exposed VPN access, a weak password and a rented proxy shown as three linked stages.
Explanatory diagram of the reported access-to-resale sequence; not a screenshot from the operation.

87,000 addresses were not 87,000 active rentals

The researchers reported more than 87,000 IP addresses in the compromised inventory. At discovery, 17,858 had proxy credentials marked ready or connected. Those figures describe different sets; neither should be presented as a verified count of individual households or simultaneously paying customers.

Payment records reportedly showed about $202,000 across more than 24,000 transactions since 2024. The operator also left evidence of being compromised: researchers found traces of a cryptominer and the removal of 37 unauthorized accounts from its Git service. The infrastructure used to exploit weak security had its own security failures.

These findings are attributed to Cybernews; we have not accessed the exposed server or its customer records. They do not establish that every reseller knew how the endpoints were obtained. Nor does a Russian-language infrastructure, by itself, demonstrate government direction.

Check the exposed device, not just the laptop

The useful question for an owner is whether a router, NAS or VPN appliance offers unnecessary access from the internet—and whether its manufacturer still supplies security fixes. In separate, older guidance on criminal router proxies, the FBI recommends replacing end-of-life equipment, applying available firmware updates, disabling unnecessary remote administration and using unique strong passwords. That May 2025 advisory concerns other activity; it is background guidance, not independent confirmation of LeakySensey.

Review the device’s configuration for accounts and proxy services you did not authorize. If you find suspicious changes, preserve the relevant settings and logs and ask the vendor, ISP or responsible administrator for an appropriate recovery procedure. Changing a Wi-Fi password does not necessarily change the credentials of a VPN service or the router’s administrator account.

A PC malware scan also cannot certify that a separate router is clean. The earlier Dysphoria router-proxy investigation illustrates the same reason to include network devices in an incident review, although it is a different campaign. For LeakySensey, the central lesson is concrete: a still-functioning connection can be an asset somebody else is selling.

References

  1. Ernestas Naprys. “Solo Russian hacker built six-figure proxy empire by brute-forcing neglected routers, VPNs.” Cybernews, September 2026; accessed September 19, 2026. Original investigation.
  2. FBI Internet Crime Complaint Center. “Cyber Criminal Proxy Services Exploiting End of Life Routers.” May 7, 2025. Router-proxy safety advisory.
Share This Article
Cybersecurity Analyst
Follow:
Brendan Smith has spent over 15 years knee-deep in cybersecurity, chasing down malware from the gritty reverse-engineering of old-school trojans all the way to wrangling full-blown incident responses for small-to-medium businesses that couldn’t afford a full-blown breach. Over at Gridinsoft, he’s the guy piecing together those double-checked guides on nasty stuff like AsyncRAT, a remote access tool used in malware campaigns—helping readers make sense of the threat and work through cleanup without the extra headache.
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?