Short answer: the signs that government advisories actually describe are settings you didn’t change (especially the router’s DNS settings), browser certificate warnings on sites you use every day, and a router that overheats or keeps losing its connection. If you see them, check and correct the settings, update the firmware, change the admin password, turn off remote management and restart the router. If settings were changed or the signs come back, factory reset it and set it up again. If it no longer gets security updates, replace it.

This page is about what to do when you suspect a problem. For locking a router down beforehand, see the router security checklist.

What the warning signs actually are

Settings you didn’t change

The FBI lists changes to settings that the owner doesn’t recognise among the common signs of malware on a router, alongside overheating and connectivity problems.

The setting that matters most is DNS, the service that turns website names into addresses. In an April 2026 advisory, the FBI described attackers changing hacked routers’ DHCP and DNS settings to point at DNS servers they controlled. Laptops and phones on the network then picked up those settings automatically. Every device in the house can end up asking an attacker’s server where to go.

Certificate warnings on familiar sites

The same advisory explains why that’s dangerous: the fake answers send people to impostor sites, and the attack works on encrypted connections if the user clicks through a browser certificate warning. The FBI’s advice is to take certificate warnings seriously. A sudden warning on your bank’s or email provider’s site, on several devices at once, is a reason to check the router.

Heat and dropouts, but only alongside other signs

Overheating and connectivity problems are on the FBI’s list, but they have far more common causes: a hot cupboard, a failing power adapter, a firmware bug. On their own, work through why a router keeps rebooting first.

What isn’t a reliable sign

Is your router more at risk?

Two things make a router a likelier target, according to the FBI:

  • It no longer gets security updates. The FBI reported end-of-life routers being taken over by a malware variant called TheMoon, which doesn’t even need a password, and says routers from 2010 or earlier are unlikely to still get updates.
  • Remote management is on. The compromised routers in that report had remote administration turned on.

What to do, in order

1. Check the DNS and admin settings

Log in to the router and look at its internet (WAN) DNS settings and its DHCP settings. If you didn’t set a custom DNS server, they should normally be automatic or show your provider’s servers; see how to change your DNS server for where to find them. Also look for admin accounts, port-forwarding rules or remote-access settings you didn’t create.

2. Update, change the password, turn off remote management, restart

For suspicious activity, the FBI’s advice is to apply security and firmware updates, change the password and reboot the router. Its 2026 advisory adds changing default user names and passwords and disabling remote management from the internet. NETGEAR gave owners the same steps in its own security advisory: reboot, run the latest firmware, change the default admin password and make sure remote management is off. The FTC also recommends turning remote management off.

3. Factory reset if settings were changed or the signs return

If you found settings you didn’t make, or the problems come back after step 2, reset the router to factory defaults and set it up again by hand. CISA’s recovery guidance for compromised network edge devices, a category that includes routers, is to factory reset them and reinstall firmware from trusted, verified sources. CISA wrote that guidance for organisations, but the logic is the same at home: a reset clears whatever was saved in the settings.

Don’t restore a settings backup made after the problem started; it could bring the bad settings back. How to reset your router explains what a reset erases and what to do afterwards.

4. Replace it if it no longer gets updates

CISA and the FBI both advise replacing routers that no longer receive security updates. A reset can’t fix an unpatched flaw that can be used again. When to replace your router explains how to check whether yours is still supported.

5. Afterwards: passwords for accounts you used

The 2026 attacks were after passwords, authentication tokens and email. If you clicked through certificate warnings or signed in to important accounts while the router’s settings were wrong, change those passwords from a device on a trusted connection, and turn on two-step verification where the service offers it.

Keep it from happening again

Prevention is a separate job, covered step by step in the router security checklist. The short version from the advisories: keep the firmware updated, use strong unique admin credentials, leave remote management off, and replace the router when it stops getting updates.