The warning signs to look for, and what to do in the next 30 minutes if you think yours is compromised.
Published October 2026 · ismyroutersafe.com
The most common signs of a hacked router are settings you did not change, a connection that keeps dropping, and a router that runs hot. The FBI lists exactly those three as common signs of router malware. If you see them, update the firmware, change the passwords, and reboot. If the router no longer gets security updates, replace it.
Signs your router was hacked
No single sign proves a hack, but each is worth checking.
Settings you did not change. The FBI names this as a common sign of infection. Check the Wi-Fi name, admin password, port forwarding and DNS.
Your passwords stop working. The FTC warns that a hacker with admin access can change settings, including the Wi-Fi password.
Unknown devices. CISA advises watching for unauthorized devices. Your router’s device list shows what is connected.
Overheating or a flaky connection. The FBI lists both as common signs.
Odd DNS settings. If the DNS server is an address you do not recognize, read our DNS hijacking guide.
Remote management is on. Not proof of a hack, but the FBI found a recent variant of TheMoon malware on end-of-life routers with remote administration turned on.
Most router infections show no sign at all. The FBI said VPNFilter’s use of encryption made its activity hard to detect. The FBI notified KV botnet router owners after the fact.
From the team behind this checker
Want a router that takes this seriously by default?
SecureRooms. Smart devices live apart from your computers.
Set new admin and Wi-Fi passwords. The FBI recommends unique, random passwords of 16 to 64 characters.
Turn off remote management and UPnP. The FBI and NSA say to disable remote administration. The NSA adds UPnP.
Only then reconnect. CISA warns a device reconnected before its password is changed can be reinfected quickly.
Check it is still supported. If it is end of life, the FBI says to replace it. See our end-of-life guide.
Secure your accounts and report it. The FBI suggests changing account passwords and filing a complaint at ic3.gov.
Does a reboot remove malware?
Sometimes, but not reliably. CISA says Mirai lives in memory, so a reboot clears it. The NSA recommends rebooting at least weekly.
But a reboot does not close the hole the attacker used, and some malware survives it. That is why the FBI and NSA have called for a factory reset, a firmware update and new passwords.
Check your router’s risk
You can check your router’s grade in a few seconds. It shows support status, known CVEs and an action plan for your model.
Frequently Asked Questions
Yes. A strong password stops password guessing, not attacks on software flaws. The FBI says TheMoon malware infects routers without a password, so keep the firmware updated and remote management off.
Do not count on it. In the 2023 KV botnet case, the FBI notified owners as part of a special operation. Check your router yourself.
It is the right first step. The FBI and NSA advised a factory reset, then a firmware update and new passwords. If the router no longer gets security updates, replace it.
It can. The FBI said VPNFilter could potentially collect information passing through infected routers. A 2024 FBI and NSA advisory said Russian state actors used hacked routers to harvest credentials.
File a complaint with the FBI’s Internet Crime Complaint Center at ic3.gov. The Justice Department also points people to CISA’s online reporting.
Sources
Dates show when each source was published or when we checked it.