Your Business Internet Connection Might Be Someone Else's Alibi. The FBI Just Explained How.

FBI Advisory Network Hygiene
August 2026  ·  7 min read

Most cyberattacks try to take something from you. This one is different: it doesn't steal your data, it borrows your identity on the internet. The FBI has warned that criminals are routing their traffic through home and small business internet connections — using ordinary devices as cover so their activity looks like it's coming from an ordinary business. Yours. Here's how a device gets quietly conscripted, what it costs you, and the short list of fixes.


Every attack this series has covered has one thing in common: someone wanted something you had. Your credentials, your files, your customers' data, your money. The threat in this post breaks that pattern, and that's exactly why most businesses never see it coming.

In a public service announcement, the FBI warned about what are called residential proxies. Strip out the jargon and the idea is simple. A proxy is just a middleman — a connection routed through somebody else's internet line so that, to whoever's on the other end, the traffic appears to come from that somebody else. A residential proxy uses the ordinary internet connections assigned to homes and small businesses.

The FBI's own wording is worth noting, because it names the audience directly: criminals obscure their true identities and locations by routing internet traffic through home and small business internet networks. Not data centres. Not enterprise infrastructure. The kind of connection your office runs on.

Which means the thing being stolen here isn't your data. It's your legitimacy.

2 million

consumer devices were hijacked to build a single one of these networks, before it was dismantled in July

Law enforcement, working with private-sector partners, took down one such network this summer. It had been assembled from more than two million hijacked everyday devices — streaming boxes, smart televisions, tablets. In a single week, researchers observed hundreds of separate criminal and state-linked groups routing their activity through it. Every one of those devices belonged to somebody who had no idea.

How an ordinary device ends up in one of these networks

The FBI describes two routes, and the distinction matters because only one of them involves anything you'd recognise as an attack.

Two ways a device gets enrolled

Route one — the device is compromised, and nobody knows

Malware or a manufacturer's backdoor turns the device into a relay point. Nothing visibly changes. The device keeps working, the owner has no reason to look, and the traffic passes through quietly in the background. The FBI specifically flags cheap streaming devices advertising free sports, films and television as a common source — hardware that arrives with something extra already installed.

Route two — consent nobody really gave

Some proxy operators pay app developers to bundle a small piece of software into otherwise ordinary apps. When someone installs the app and taps through the terms, that software runs in the background and routes other people's traffic through their connection. Technically consented to. Practically invisible. Some free connection-privacy tools work the same way — the product is the user's bandwidth.

This is the part that makes it a small business problem rather than a consumer curiosity. Think about what's actually connected to your office network: the router, obviously, but also the tablet at reception, the television in the meeting room, the streaming stick somebody brought in, the smart display, the phones on the guest network, whatever the last contractor plugged in. Any one of them can be the doorway. And unlike a laptop, none of them are being watched by anybody.

What it costs you — even though nothing was taken

The FBI's advisory lists what these networks get used for, and the pattern is consistent: they exist to make illegitimate activity look legitimate. Attack infrastructure gets hidden behind an ordinary-looking address. Stolen credentials get used from a location that doesn't trigger a fraud alert. Automated attempts get spread across a huge pool of addresses so that rate limits and lockouts never trip. Stolen data gets moved out of networks in a way that's harder to trace.

In one example the advisory gives, an attacker with stolen banking credentials uses an address in the victim's own city — so the bank sees a login from the right place and doesn't flag it. That address belongs to somebody. It might belong to a business a few streets away that has no idea it's involved.

Here's what that means for the business whose connection is being used:

Your address becomes the return address Activity traced back to the traffic's origin leads to your connection, not the person responsible. That's an uncomfortable conversation to have with anyone who comes asking.
You get quietly blocklisted Once an address develops a reputation, services start refusing or challenging it. Email delivery suffers. Sites throw endless verification checks. Nobody tells you why.
Your connection gets slower Someone else's traffic is using the bandwidth you pay for. It rarely looks like a security problem — it looks like your internet being mysteriously worse than it used to be.
The compromised device is still compromised Whatever enrolled the device is sitting inside your network with a foothold. Relaying traffic today doesn't mean that's the limit of what it can do tomorrow.
8–9m estimated residential proxy endpoints operating worldwide, across more than twenty distinct network families 2026 industry threat report
4bn malicious sessions tracked over 90 days that were statistically indistinguishable from ordinary user traffic Network threat research 2026
316 separate threat groups seen routing activity through one network in a single week — including state-linked actors Threat intelligence research 2026

The part that changes how you should think about defence

There's a second lesson here that's easy to miss, and it matters for every business regardless of whether your own devices are involved.

For years, a standard piece of security advice was to judge traffic by where it comes from: block addresses from countries you don't do business with, be suspicious of data-centre addresses, trust logins from ordinary residential connections. That advice quietly stopped working. When attacks arrive from millions of genuine home and small-business connections — statistically indistinguishable from real customers — the address tells you almost nothing.

This is why identity and behaviour have replaced location as the thing worth watching. Not "where did this connection come from" but "does this session behave like the person it claims to be" — the timing, the sequence, the pattern of requests. It's the same conclusion the token-theft story led to from a different direction: the checkpoint you were relying on is no longer where the decision gets made.

Five fixes — all cheap, most one-time

1

Update everything that connects — including the things you don't think of as computers

Free · FBI's own advice

The FBI's primary recommendation to businesses is the least exciting one: keep software and operating systems current. Enrollment usually happens through a known, unpatched weakness. Updates close it.

Do this weekRouter and firewall firmware first, since those are permanently exposed and almost never updated. Then phones, tablets, and anything else on the network with an update button. Turn on automatic updates wherever the option exists.
2

Write down everything on your network — then remove what shouldn't be there

30 minutes · Free

You can't protect a device you've forgotten exists, and forgotten devices are exactly what these networks are built from. Most small offices have accumulated several over the years.

How to do itLog into your router and look at the list of connected devices. Anything you can't identify, investigate. Anything you no longer use, unplug. Anything that doesn't need to be on the main network — televisions, displays, guest devices — move to a separate guest network so it can't reach your business systems.
3

Be wary of hardware that promises free premium content

Free · FBI's own advice

The FBI explicitly warns that streaming devices advertising free sports, films and television may ship with malware or backdoors already installed. If a device's selling point is access to content that normally costs money, the economics have to work somehow — and frequently the answer is that the buyer's connection is the product.

The practical ruleBuy connected hardware from established retailers and manufacturers, and keep anything of uncertain origin off the network your business runs on.
4

Retire equipment the manufacturer has stopped supporting

Low cost

A router that no longer receives security updates has permanently open, publicly documented weaknesses. It will keep working perfectly well for years, which is precisely the problem — nothing prompts you to replace it.

Ask this question"Is our router still receiving firmware updates from the manufacturer?" If the answer is no, replacing it is one of the cheapest meaningful security purchases a small business can make. While you're in there, turn off remote management and change any default password.
5

Learn the symptoms, because nothing will alert you

Free · Awareness

There is no alarm for this. The signs are ambient and easy to blame on something else: your connection slower than it should be, particularly outside working hours; websites suddenly making you complete verification checks; your email being rejected or landing in spam more often; unfamiliar devices appearing on the network.

If several of these are trueAsk your IT provider to look at outbound traffic from your network, especially overnight. A connection carrying somebody else's work tends to be busiest when your office is empty.
Notice the uncomfortable asymmetry running through this whole story. You could have excellent passwords, well-configured multi-factor authentication, current backups and a tested response plan — and still have a forgotten device in a cupboard quietly lending your business's name to somebody else's activity. Identity protection and network hygiene are separate jobs. Most small businesses have started the first and never started the second.
The Veriti Spottr CyberScore's Exposure component exists for exactly this blind spot: what of yours is visible and reachable from the internet, and what condition it's in. Our Threat Intelligence feed tracks the device and network vulnerabilities being actively exploited to build these networks. The devices nobody is watching are the ones being used — and visibility is the entire defence.

The short version

Most security advice assumes the attacker wants to take something from you. This one wants to borrow who you are — to make what they're doing look like something an ordinary small business would do. Your address becomes the cover story, and the first you're likely to hear about it is an unexplained blocklisting, a sluggish connection, or a question you can't answer.

The fixes are the same unglamorous list as ever: update the things that connect, know what's on your network, get rid of what you don't use, replace what can't be patched. Nothing here costs much or takes long. It's just that until somebody points at the streaming stick in the meeting room and asks who's using it, nobody ever does.

Find out what of your business is visible from the internet — and what condition it's in.

View the Threat Intelligence feed → Find Out More About Veriti Spottr →
VS
Veriti Spottr Team AI-powered cyber risk clarity for SMBs  ·  veritispottr.com

Comments

Popular posts from this blog

The Hidden Cost of Cybersecurity Inaction for Small Businesses

Small Business Ransomware Protection Guide (2026 Edition)

Your Biggest Cyber Risk Isn't Outside Your Firewall. It's on Your Payroll.