Morning Overview

The FBI says hackers are hijacking outdated home routers, and it named the models to check

Federal cyber officials have repeatedly warned that criminals are quietly taking over old home and small-office routers, the kind of internet boxes that manufacturers have stopped updating, and folding them into networks used to disguise online crime. Because these devices no longer receive security patches, known flaws in them stay open indefinitely, and their owners usually have no sign anything is wrong. The FBI has gone as far as naming specific end-of-life models and urging households and small businesses to check their hardware and, in many cases, replace it.

Why end-of-life routers are such easy targets

A router reaches “end of life” when its maker stops issuing software updates, which means any security hole discovered afterward is never fixed. Attackers scan the internet for these unsupported models, exploit the unpatched vulnerabilities, and install malware that lets them route their own traffic through the device without the owner noticing. The bureau has warned that criminal proxy services build much of their infrastructure this way, hijacking outdated routers and reselling access to them, a threat detailed in the FBI’s alert on criminal proxy services exploiting end-of-life routers. Devices with remote administration switched on are especially exposed, because that feature gives an attacker a ready-made door.

The appeal to criminals is that a compromised home router looks, to the outside world, like an ordinary residential internet connection. That makes traffic passing through it hard to flag as malicious, which is exactly why such devices are prized for hiding fraud, credential attacks, and other crimes.

The models and dates the FBI has flagged

The warnings are not generic. In an advisory issued in 2025 and escalated with a bureau notice in March 2026, investigators identified specific end-of-life router models across several major brands and pointed owners to check their equipment against the list, guidance laid out in the FBI’s March 2026 industry notification. The affected hardware spans well-known consumer names, and the common thread is age: routers that have passed the point where their manufacturers provide support. Officials have tied the compromises to malware variants that specifically hunt for such devices and enlist them into proxy networks used across dozens of countries.

The practical instruction is to identify the exact model number and check whether the manufacturer still supports it. Owners often cannot recall how old a router is, and a device that has been reliably passing internet traffic for years can feel fine while being fully compromised, which is why the FBI stresses checking the model rather than relying on whether the box appears to work.

From petty proxies to a state-run botnet

The router threat is not limited to for-profit criminals. The FBI has also acted against nation-state operations built on the same weakness. In one case, the bureau disrupted a botnet assembled from thousands of home and office routers and attributed it to a Russian military intelligence unit, an operation described in an FBI public service announcement on the router botnet takedown. That effort showed the far end of the spectrum: the same neglected devices that fuel ordinary fraud can also be marshaled by a government-backed group for espionage and disruption.

The overlap matters for ordinary owners because it means an unsupported router is not just a personal risk but a potential building block for large-scale campaigns. A device left online and unpatched can end up serving purposes far beyond what its owner would ever imagine.

What owners of old hardware can actually do

The bureau’s core recommendation is blunt: if a router has reached end of life, replace it with a current, supported model. For devices that are merely outdated but still supported, the advice is to install the latest firmware, disable remote administration, and set a strong, unique password in place of any factory default. Rebooting a router can clear some kinds of malware temporarily, but it does not close the underlying vulnerability, so it is a stopgap rather than a fix.

Checking a router is a modest task with an outsized payoff. Finding the model number, looking up whether the manufacturer still supports it, and either updating or replacing it takes far less effort than dealing with the fallout of a compromised home network. Because these advisories describe a threat that remains active rather than a one-time incident, the guidance stays relevant well beyond the date any single warning was issued.

Why a household device became a national security issue

The router sits at a peculiar intersection: it is a cheap consumer appliance most people forget about, and it is also the single gateway between a home and the internet. That combination is what makes neglected models so valuable to attackers, from small-time fraud rings to foreign intelligence services, and it is why federal warnings about them have grown more pointed over time. The devices are numerous, long-lived, and rarely maintained, and each unsupported one is a standing invitation. The FBI’s repeated message reduces to a single habit worth adopting: know what router is in the house, know whether it is still supported, and retire it when it is not.

This article was researched and written with the assistance of AI and reviewed by an editor prior to publication.


More from Morning Overview