Morning Overview

The NSA now tells every home-router owner to reboot the device at least once a week

The National Security Agency and the Federal Bureau of Investigation are now directing home-router owners across the United States to reboot their devices at least once a week. The guidance is not routine housekeeping advice. It is tied directly to active Russian state-sponsored operations, specifically by FSB Center 16, that have exploited Simple Network Management Protocol (SNMP) vulnerabilities and end-of-life networking equipment to collect configuration files from thousands of devices connected to critical infrastructure sectors over the past year.

Russian FSB Center 16 operations behind the reboot directive

The weekly reboot recommendation sits inside a broader set of hardening steps that U.S. agencies issued after tracking a specific threat actor. FSB Center 16, a unit within Russia’s Federal Security Service, targeted networking devices across multiple critical infrastructure sectors. According to the FBI Internet Crime Complaint Center, these actors collected configuration files for “thousands of networking devices” tied to U.S. entities. The exploitation occurred over the past year and relied heavily on SNMP, a protocol that many older routers leave enabled by default.

SNMP is designed for monitoring and managing network equipment, but when exposed to the internet with weak or default credentials, it becomes an efficient reconnaissance tool. By querying SNMP, attackers can pull down configuration files that reveal how a device is set up, what services it runs, and how it connects to the rest of a network. For critical infrastructure operators, that information can provide a roadmap for deeper intrusions or follow-on operations.

A reboot clears volatile memory, where many implants reside. If malware has not written itself into firmware or non-volatile storage, a power cycle removes it entirely. The logic behind a weekly schedule is straightforward: it caps the window during which an attacker can maintain a foothold on a compromised device. For routers that have not received firmware patches, and many end-of-life models never will, this is the single fastest action an owner can take to disrupt an active intrusion.

The NSA framed the threat in terms that extend well beyond government networks. Its earlier best-practices release identified telework and home networks as persistent attack surfaces, noting that remote workers connect to employer systems through consumer-grade equipment that rarely receives professional security oversight. A compromised home router does not just put one household at risk. It can serve as a proxy node in a larger attack chain aimed at corporate or government targets.

What the agencies say to do beyond rebooting

Rebooting alone is not a complete defense. The NSA and FBI listed several baseline actions for small-office and home-office (SOHO) router users: change default credentials, disable remote management features, apply firmware updates when available, and replace devices that have reached end-of-support status. In a joint statement, the NSA emphasized that older equipment should be retired, and it publicly backed FBI efforts that highlight Russian threats against routers as a continuing concern.

The FBI separately flagged that routers manufactured around 2010 or earlier are likely no longer receiving security patches from their vendors, making them prime targets for exploitation. Devices that vendors have stopped supporting often retain outdated encryption standards, exposed management interfaces, and known vulnerabilities that are widely cataloged in public exploit databases. Attackers can scan the internet for these models and compromise them at scale.

One specific threat illustrates why old hardware is so dangerous. The FBI documented how end-of-life routers have been compromised by variants of TheMoon botnet and then repurposed as proxy infrastructure for criminal and state-sponsored actors alike. In a detailed alert, the Bureau described how cybercriminal proxy services exploit end-of-life routers to hide malicious traffic behind unsuspecting households and small businesses. Once enrolled in a proxy network, a router’s internet connection can be used to mask the true origin of cyberattacks, fraud campaigns, or espionage operations. The owner typically has no indication that anything is wrong.

The joint Cybersecurity Advisory released by the NSA and partner agencies specifically named FSB Center 16 and outlined router hygiene measures designed to counter that group’s known tactics. The advisory built on earlier warnings, including a 2018 CISA technical alert about Russian state-sponsored targeting of network infrastructure and a separate 2025 CISA advisory on mitigations for operational technology environments. The NSA and its international counterparts urged organizations to follow practical steps in their guidance on improving router hygiene, which covers both enterprise and consumer-grade equipment.

Cisco Talos research was also referenced in the FBI’s alert as supporting evidence for the exploitation patterns described. That research documented how attackers chain multiple vulnerabilities and misconfigurations-such as exposed SNMP, outdated firmware, and weak credentials-to pivot from a compromised router into more sensitive segments of a victim’s network. For FSB Center 16, this kind of access can provide both intelligence value and a platform for further operations.

Gaps in the evidence and what router owners should watch

The agencies have not published data showing how much a weekly reboot actually reduces infection rates or attacker dwell time on consumer routers. No before-and-after metrics exist in the public record. The recommendation rests on a sound technical principle, that clearing volatile memory disrupts non-persistent implants, but no controlled ISP-level flow-data analysis has been released to quantify the effect. Without that data, the claim that weekly reboots create a measurable drop in FSB Center 16 implant persistence remains a reasonable inference rather than a proven outcome.

There is also no public count of how many consumer routers in the United States currently run vulnerable firmware versions or have SNMP exposed to the open internet. The FBI’s reference to “thousands” of compromised device configurations provides scale, but it describes what attackers collected, not the total number of devices at risk. The true exposure is almost certainly larger, especially when factoring in small businesses and remote workers who rely on consumer-grade equipment for professional access.

For anyone with a home router, the first practical step is simple: unplug the device, wait ten seconds, and plug it back in. Do this weekly. Then log into the router’s administration panel, typically accessible at 192.168.1.1 or a similar local address, and check three things. First, confirm that remote management is turned off so that administrative access is limited to devices inside your home network. Second, change the admin password if it still matches the factory default printed on the device label or in the quick-start guide. Third, check whether a firmware update is available and apply it, even if the process requires a manual download from the vendor’s support site.

Owners of very old routers should consider replacement rather than incremental tuning. If a vendor’s support page lists your model as end-of-life, or if the last firmware update is several years old, it is unlikely to receive patches for newly discovered vulnerabilities. In that scenario, no amount of rebooting will fix the underlying exposure. Upgrading to a currently supported device, then disabling unnecessary features and changing default settings, offers a more durable defense.

Finally, router owners should treat unusual internet behavior-sluggish performance, unexplained bandwidth spikes, or warnings from online services about suspicious logins-as potential indicators that their device is being misused. While these signs are not conclusive proof of compromise, they warrant a closer look at router logs, a fresh reboot, and, if problems persist, consultation with an internet service provider or security professional. Weekly reboots, stronger configurations, and timely hardware replacement will not eliminate the risk of advanced state-sponsored activity, but together they narrow the attack surface that FSB Center 16 and similar actors have been exploiting at scale.

More from Morning Overview

*This article was researched with the help of AI, with human editors creating the final content.