A business renting out access to other people’s routers was exposed by an unsecured server of its own. Cybernews researchers call the operator LeakySensey: their September investigation describes a proxy inventory built by guessing weak credentials on internet-facing VPN devices, then selling access through websites, Telegram bots and resellers.
The discovery dates to July 20, 2026, when researchers found the operator’s server open. This is newly reported research into an older operation, not evidence that 87,000 routers were attacked this week.
The router becomes somebody else’s exit point
According to Cybernews, the operation searched for exposed PPTP, L2TP and SSH services and tried weak account credentials. Its targets included old routers, dedicated VPN appliances and network-attached storage. Successful access could be converted into a proxy endpoint that paying customers used to relay their traffic.
A proxy makes the compromised connection the visible departure point for somebody else’s requests. That is the practical distinction from simply stealing a Wi-Fi password: an intruder can monetize remote access to a device even when its owner still has working internet. Our guide to proxyjacking explains the broader bandwidth-theft model.

87,000 addresses were not 87,000 active rentals
The researchers reported more than 87,000 IP addresses in the compromised inventory. At discovery, 17,858 had proxy credentials marked ready or connected. Those figures describe different sets; neither should be presented as a verified count of individual households or simultaneously paying customers.
Payment records reportedly showed about $202,000 across more than 24,000 transactions since 2024. The operator also left evidence of being compromised: researchers found traces of a cryptominer and the removal of 37 unauthorized accounts from its Git service. The infrastructure used to exploit weak security had its own security failures.
These findings are attributed to Cybernews; we have not accessed the exposed server or its customer records. They do not establish that every reseller knew how the endpoints were obtained. Nor does a Russian-language infrastructure, by itself, demonstrate government direction.
Check the exposed device, not just the laptop
The useful question for an owner is whether a router, NAS or VPN appliance offers unnecessary access from the internet—and whether its manufacturer still supplies security fixes. In separate, older guidance on criminal router proxies, the FBI recommends replacing end-of-life equipment, applying available firmware updates, disabling unnecessary remote administration and using unique strong passwords. That May 2025 advisory concerns other activity; it is background guidance, not independent confirmation of LeakySensey.
Review the device’s configuration for accounts and proxy services you did not authorize. If you find suspicious changes, preserve the relevant settings and logs and ask the vendor, ISP or responsible administrator for an appropriate recovery procedure. Changing a Wi-Fi password does not necessarily change the credentials of a VPN service or the router’s administrator account.
A PC malware scan also cannot certify that a separate router is clean. The earlier Dysphoria router-proxy investigation illustrates the same reason to include network devices in an incident review, although it is a different campaign. For LeakySensey, the central lesson is concrete: a still-functioning connection can be an asset somebody else is selling.
References
- Ernestas Naprys. “Solo Russian hacker built six-figure proxy empire by brute-forcing neglected routers, VPNs.” Cybernews, September 2026; accessed September 19, 2026. Original investigation.
- FBI Internet Crime Complaint Center. “Cyber Criminal Proxy Services Exploiting End of Life Routers.” May 7, 2025. Router-proxy safety advisory.

