Your Home Router Could Be Compromised, and Thousands Across 23 States Already Were, FBI Says

Source: Shutterstock

Most people rarely give their home Wi-Fi router a second thought. Once it’s plugged in and connected, it quietly keeps phones, laptops, smart TVs, and security cameras online. But according to the FBI, that everyday device has also become an attractive target for foreign hackers. After disrupting a Russian cyber operation that compromised thousands of routers across 23 states, federal officials are warning Americans that the job isn’t over until router owners take action themselves.

A Hidden Campaign That Lasted For Years

Source: Shutterstock

The operation was carried out by Russia’s military intelligence agency, specifically Unit 26165 of the GRU, a hacking group also known as APT28, Fancy Bear, and Forest Blizzard. According to the Justice Department, the group had been exploiting vulnerable routers since at least 2024, quietly taking control of devices in homes and small offices before using them in broader espionage campaigns targeting military, government, and critical infrastructure organizations.

Thousands Of Routers Were Caught In The Middle

Source: Unsplash

Investigators say the hackers compromised more than 200 organizations and roughly 5,000 consumer devices across at least 23 U.S. states. Rather than attacking every router for the information stored on it, the group used many of the devices as stepping stones, routing internet traffic through compromised networks while searching for higher-value targets. Many owners had no indication their routers had been enlisted in the operation.

How An Ordinary Router Became A Spy Tool

Source: Shutterstock

The attackers exploited known vulnerabilities in older TP-Link routers and altered their Domain Name System, or DNS, settings. That allowed internet traffic to pass through servers controlled by the hackers, who could then redirect victims to fake websites or intercept sensitive information. According to the Justice Department, some attacks mimicked legitimate services such as Microsoft Outlook Web Access to capture passwords, authentication tokens, emails, and other data.

The FBI Took An Unusual Step

Source: Ceri Breeze / Shutterstock

Rather than waiting for individual victims to discover the intrusion, the FBI obtained court authorization for an operation known as Operation Masquerade. Agents remotely sent commands to compromised routers that removed the hackers’ malicious DNS settings and blocked their access without collecting users’ personal data or disrupting normal internet service. Officials stressed, however, that the intervention did not permanently secure the affected devices.

Why The Risk Hasn’t Disappeared

Source: Unsplash

Although the hackers’ access was disrupted, the same vulnerabilities can still be exploited if routers remain outdated. The FBI says many of the affected devices had reached end-of-life or end-of-support status, meaning they no longer receive regular security updates. Once manufacturers stop releasing firmware patches, older hardware becomes increasingly vulnerable to newly discovered cyber threats.

Which Routers Were Most At Risk?

Source: Ruslan Lytvyn / Shutterstock

Authorities identified numerous older TP-Link models as particularly vulnerable, though officials cautioned the list may not be exhaustive. CNET noted that many of the affected devices had been discontinued years ago, and TP-Link has encouraged customers using those legacy models to replace them if possible. While the campaign primarily targeted small office and enterprise routers, some of the same models were also sold for home use, making it worthwhile for consumers to check whether their router is among the affected devices.

The Steps Every Router Owner Should Take

Source: Canva Pro

Federal agencies say protecting a home network does not require advanced technical skills. Their guidance starts with updating router firmware, changing default usernames and passwords, disabling remote management if it is not needed, and replacing devices that no longer receive security updates. They also recommend verifying DNS settings and remaining cautious if web browsers display unexpected certificate warnings, which can signal an attempted interception.

Why Hackers Keep Going After Routers

Source: Shutterstock

Cybersecurity experts say routers occupy a uniquely valuable position because nearly every internet-connected device in a home depends on them. Unlike computers or smartphones, routers often remain powered on continuously and can go years without maintenance. As Forescout’s vice president of security intelligence Rik Ferguson told CNET, every piece of online communication passes through the router, making an outdated device an especially attractive target for attackers seeking long-term access.

A Few Minutes Of Maintenance Can Go A Long Way

Source: Canva Pro

The recent operation shows that cybersecurity is no longer limited to large corporations or government agencies. Everyday household devices have become part of the same digital battlefield, sometimes without their owners realizing it. The FBI says simple steps such as installing the latest firmware, replacing aging routers, and changing default credentials can significantly reduce that risk. For many households, spending a few minutes checking a router’s security settings today could help prevent a much bigger problem tomorrow.