Your Business Internet Connection Might Be Someone Else's Alibi. The FBI Just Explained How.
Most cyberattacks try to take something from you. This one is different: it doesn't steal your data, it borrows your identity on the internet. The FBI has warned that criminals are routing their traffic through home and small business internet connections — using ordinary devices as cover so their activity looks like it's coming from an ordinary business. Yours. Here's how a device gets quietly conscripted, what it costs you, and the short list of fixes.
Every attack this series has covered has one thing in common: someone wanted something you had. Your credentials, your files, your customers' data, your money. The threat in this post breaks that pattern, and that's exactly why most businesses never see it coming.
In a public service announcement, the FBI warned about what are called residential proxies. Strip out the jargon and the idea is simple. A proxy is just a middleman — a connection routed through somebody else's internet line so that, to whoever's on the other end, the traffic appears to come from that somebody else. A residential proxy uses the ordinary internet connections assigned to homes and small businesses.
The FBI's own wording is worth noting, because it names the audience directly: criminals obscure their true identities and locations by routing internet traffic through home and small business internet networks. Not data centres. Not enterprise infrastructure. The kind of connection your office runs on.
Which means the thing being stolen here isn't your data. It's your legitimacy.
consumer devices were hijacked to build a single one of these networks, before it was dismantled in July
Law enforcement, working with private-sector partners, took down one such network this summer. It had been assembled from more than two million hijacked everyday devices — streaming boxes, smart televisions, tablets. In a single week, researchers observed hundreds of separate criminal and state-linked groups routing their activity through it. Every one of those devices belonged to somebody who had no idea.
How an ordinary device ends up in one of these networks
The FBI describes two routes, and the distinction matters because only one of them involves anything you'd recognise as an attack.
Route one — the device is compromised, and nobody knows
Malware or a manufacturer's backdoor turns the device into a relay point. Nothing visibly changes. The device keeps working, the owner has no reason to look, and the traffic passes through quietly in the background. The FBI specifically flags cheap streaming devices advertising free sports, films and television as a common source — hardware that arrives with something extra already installed.
Route two — consent nobody really gave
Some proxy operators pay app developers to bundle a small piece of software into otherwise ordinary apps. When someone installs the app and taps through the terms, that software runs in the background and routes other people's traffic through their connection. Technically consented to. Practically invisible. Some free connection-privacy tools work the same way — the product is the user's bandwidth.
What it costs you — even though nothing was taken
The FBI's advisory lists what these networks get used for, and the pattern is consistent: they exist to make illegitimate activity look legitimate. Attack infrastructure gets hidden behind an ordinary-looking address. Stolen credentials get used from a location that doesn't trigger a fraud alert. Automated attempts get spread across a huge pool of addresses so that rate limits and lockouts never trip. Stolen data gets moved out of networks in a way that's harder to trace.
In one example the advisory gives, an attacker with stolen banking credentials uses an address in the victim's own city — so the bank sees a login from the right place and doesn't flag it. That address belongs to somebody. It might belong to a business a few streets away that has no idea it's involved.
Here's what that means for the business whose connection is being used:
The part that changes how you should think about defence
There's a second lesson here that's easy to miss, and it matters for every business regardless of whether your own devices are involved.
For years, a standard piece of security advice was to judge traffic by where it comes from: block addresses from countries you don't do business with, be suspicious of data-centre addresses, trust logins from ordinary residential connections. That advice quietly stopped working. When attacks arrive from millions of genuine home and small-business connections — statistically indistinguishable from real customers — the address tells you almost nothing.
Five fixes — all cheap, most one-time
Update everything that connects — including the things you don't think of as computers
Free · FBI's own adviceThe FBI's primary recommendation to businesses is the least exciting one: keep software and operating systems current. Enrollment usually happens through a known, unpatched weakness. Updates close it.
Write down everything on your network — then remove what shouldn't be there
30 minutes · FreeYou can't protect a device you've forgotten exists, and forgotten devices are exactly what these networks are built from. Most small offices have accumulated several over the years.
Be wary of hardware that promises free premium content
Free · FBI's own adviceThe FBI explicitly warns that streaming devices advertising free sports, films and television may ship with malware or backdoors already installed. If a device's selling point is access to content that normally costs money, the economics have to work somehow — and frequently the answer is that the buyer's connection is the product.
Retire equipment the manufacturer has stopped supporting
Low costA router that no longer receives security updates has permanently open, publicly documented weaknesses. It will keep working perfectly well for years, which is precisely the problem — nothing prompts you to replace it.
Learn the symptoms, because nothing will alert you
Free · AwarenessThere is no alarm for this. The signs are ambient and easy to blame on something else: your connection slower than it should be, particularly outside working hours; websites suddenly making you complete verification checks; your email being rejected or landing in spam more often; unfamiliar devices appearing on the network.
The short version
Most security advice assumes the attacker wants to take something from you. This one wants to borrow who you are — to make what they're doing look like something an ordinary small business would do. Your address becomes the cover story, and the first you're likely to hear about it is an unexplained blocklisting, a sluggish connection, or a question you can't answer.
The fixes are the same unglamorous list as ever: update the things that connect, know what's on your network, get rid of what you don't use, replace what can't be patched. Nothing here costs much or takes long. It's just that until somebody points at the streaming stick in the meeting room and asks who's using it, nobody ever does.
Find out what of your business is visible from the internet — and what condition it's in.
View the Threat Intelligence feed → Find Out More About Veriti Spottr →📚 Credential Security Series — Read the full series

Comments
Post a Comment