The FBI has warned that criminals are compromising outdated home and small-office routers, folding them into networks of hijacked machines used to disguise online crime. The devices most at risk are older models that manufacturers no longer support with security updates, which leaves known vulnerabilities permanently open. Because a router that has been quietly taken over usually keeps working normally, most owners have no idea their equipment has become a tool for someone else.
The bureau’s public advisories have gone a step further than general caution by identifying specific end-of-life router models that attackers have targeted, giving owners a concrete list to check against the box under their desk. The core problem is not that these routers were poorly made but that they have aged past the point where the companies that built them will patch newly discovered flaws, turning ordinary household hardware into an unlocked door.
What “end of life” means for a router
Every network device runs firmware, the built-in software that controls how it handles traffic and enforces security. Manufacturers periodically release firmware updates to fix vulnerabilities that researchers and criminals discover over time. When a product reaches end of life, the maker stops issuing those updates, so any flaw found afterward stays exploitable forever. An end-of-life router can sit on a shelf for years accumulating publicly documented weaknesses that will never be repaired.
The FBI’s public service announcement on router hijacking describes how attackers scan the internet for these unpatched devices and use automated tools to install malicious software on them. Once compromised, the router can be controlled remotely without the owner’s knowledge, and the malware often survives ordinary reboots. The bureau has singled out a range of older consumer models, several of them budget wireless routers from a decade or more ago, as devices actively being exploited.
From a home router to a criminal proxy
The most common use for a hijacked router is as part of a proxy network, a service that routes other people’s internet traffic through the compromised device to hide its true origin. Criminals rent access to these networks so that their activity appears to come from an ordinary residential address rather than from their own systems. A fraudster logging into stolen accounts, for instance, looks far less suspicious to a bank’s security systems when the connection seems to originate from a home in a normal neighborhood.
Compromised routers are also assembled into botnets, large collections of infected devices that can be directed in unison to overwhelm websites with traffic or to carry out coordinated attacks. In either case the owner of the router is an unwitting participant, contributing bandwidth and a legitimate-looking address to operations they know nothing about. The stealth is the point, because a router that suddenly stopped working would prompt the owner to replace it and end the criminal’s access.
The signs a router has been compromised
Detecting a hijacked router is difficult precisely because it is designed to keep functioning. Some owners notice symptoms such as unusually slow internet, the device running hot or its indicator lights behaving oddly, or settings that appear to have changed without explanation. Overheating and sluggish performance can reflect the extra workload of routing strangers’ traffic, but none of these signs is definitive, and many infections produce no visible symptom at all.
That ambiguity is why the FBI’s guidance emphasizes the age and support status of the hardware over any attempt to spot an active infection. A router on the bureau’s list of exploited models, or any device the manufacturer no longer updates, should be treated as a risk regardless of whether it seems to be behaving. The safest assumption for an unsupported device is that its known vulnerabilities are exposed, whether or not an attacker has acted on them yet.
Replacing the hardware and locking it down
The most reliable fix for an end-of-life router is replacement with a current model that still receives security updates. Because the underlying problem is the absence of patches, no amount of careful configuration fully protects a device the manufacturer has abandoned. Owners who cannot immediately replace a flagged router can reduce their exposure by restarting the device to clear some forms of malware, installing the last available firmware, and disabling remote-management features that let the router be administered over the internet.
Basic security practices matter on any router, old or new. Changing the default administrator password, using strong network encryption, and turning off features that are not in use all shrink the openings an attacker can exploit. The federal cybersecurity guidance for home networks recommends keeping firmware current and retiring hardware that can no longer be updated, the same logic the FBI applies to the specific models it has named.
An aging layer of household infrastructure
The broader issue is that routers tend to be installed once and forgotten, running untouched for years while the software inside them ages out of support. Unlike a phone or laptop that people replace on a regular cycle, a router often stays in service until it physically fails, long after the manufacturer has stopped defending it. That neglect is what makes the installed base of outdated home routers such an attractive target for criminals building proxy networks and botnets.
The practical response is straightforward even if it is easy to postpone. Owners can check the model number of their router against the manufacturer’s support status and the FBI’s published list, confirm that it still receives updates, and replace it if it does not. A device that quietly moves internet traffic for a household is worth the same periodic attention as any other part of a home’s security, precisely because its silence is what attackers rely on.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- Card skimmers hidden on gas pumps and ATMs are draining accounts, and here’s the tell
- The FBI says hackers are hijacking outdated home routers, and it named the models to check
- Older Teslas are wearing out in ways early owners never saw coming
- A common childhood virus is now tied to multiple sclerosis years later