Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cyber Operations topic

No spam. Unsubscribe anytime.

FBI Cyber Division details extradition in HAFNIUM case and disruption of GRU router network

Ahead of the Threat (podcast) · May 6, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

FBI Cyber Division leaders said international cooperation led to the extradition of an alleged contractor tied to the HAFNIUM campaign, and described a court-authorized operation that disrupted a GRU-run DNS hijacking network affecting thousands of routers, urging deeper industry–government threat sharing.

Brett Leatherman, assistant director of the FBI Cyber Division, and Todd Hemmen, deputy assistant director for the Cyber Capabilities Branch, described a string of recent operations the FBI says illustrate how law enforcement, international partners and industry can deter and disrupt nation-state and criminal cyber campaigns.

Leatherman said Italian authorities transferred Xu Zewei, a 34-year-old PRC national, into U.S. custody on April 26 to face a nine-count federal indictment alleging he worked on behalf of the Shanghai State Security Bureau and targeted U.S. researchers and Microsoft Exchange servers in the campaign tracked as HAFNIUM (also referenced as Silk Typhoon). "The charges are allegations. Xu is presumed innocent unless and until proven guilty," Leatherman said.

Todd Hemmen told the program the extradition reflected close cooperation with Italian law enforcement and the FBI’s embedded cyber assistant legal attache in Rome, and called the outcome "a very, very rare extradition" for this type of case. He credited the Italian Polizia Postale and other partners for time-sensitive coordination that enabled the transfer for prosecution in the United States.

The officials also discussed Operation Masquerade, a court-authorized disruption announced April 7 that the FBI and Justice Department say targeted a DNS hijacking network the agencies attribute to GRU Unit 26165 (often identified in open sources as APT28). Leatherman and Hemmen said roughly 18,000 TP-Link routers with outdated firmware were manipulated to redirect victims’ traffic to attacker infrastructure; the campaign is described as affecting hundreds of organizations across multiple states and countries.

"We're seeing a lot more victimization occur on the edge of networks," Hemmen said, adding that compromised edge devices can allow credential theft and lateral movement into victims’ environments. The pair emphasized that while the FBI has authorities and unique indicators — Hemmen said Cyber Division is "uniquely in possession of more than 50% of our national security cyberthreat indicators" — broader operational resilience requires industry partners to act on shared intelligence.

Leatherman and Hemmen also referenced a multiagency advisory led by the U.K. National Cyber Security Center (April 23) that warned PRC‑nexus actors are increasingly building covert networks from compromised consumer routers, IoT devices and residential proxies. Hemmen said static mitigation steps such as IP blocklists are no longer sufficient when large botnets and residential proxies are involved and called for more mature bilateral threat-sharing arrangements so industry defenders can operationalize the intelligence law enforcement holds.

The officials cited legal authorities they said undergird operations and intelligence collection, and urged victims to contact local FBI field offices for help with incident response and containment. They framed disruption, prosecution and defensive support as complementary levers to increase cost for malicious cyber actors and to protect victims.

The news segment closed with Leatherman summarizing three themes: accountability through prosecution, disruption via court-authorized operations, and improving resilience through information sharing with industry.