We got the “is my router hacked?” call from a family member last spring: her bank’s website suddenly had a certificate warning, her browser homepage had changed itself, and the internet crawled every evening. Two of those three symptoms turned out to be innocent. The third was a DNS setting on her router that neither of us had put there.
That’s the frustrating thing about this question — most “hacked router” symptoms have boring explanations, but the genuine signs are easy to shrug off. So here are the nine warning signs ranked by how seriously to take them, a triage checklist you can run in ten minutes, and the full factory-reset walkthrough for when the evidence points the wrong way.
Why routers are worth hacking at all
A router sits between every device you own and the internet. Someone who controls it can redirect you to fake versions of real websites, quietly watch where your traffic goes, use your connection to attack others, or simply rent your router out as part of a botnet — a pattern the FBI’s Internet Crime Complaint Center has repeatedly warned home users about. Attackers rarely target you specifically — they scan the whole internet for routers with old firmware, default passwords, or exposed remote management, and take whatever answers. Which is good news, in a way: the fixes are generic too.
The 9 warning signs, ranked
| # | Sign | Severity |
|---|---|---|
| 1 | DNS settings changed to servers you don’t recognize | High |
| 2 | Browsers redirect to wrong/fake sites; certificate warnings on major sites | High |
| 3 | Admin password no longer works | High |
| 4 | Remote management enabled — and you didn’t do it | High |
| 5 | Unknown port-forwarding rules or a DMZ entry | High |
| 6 | Unknown devices on your network list | Medium |
| 7 | New or changed WiFi network names broadcasting from your router | Medium |
| 8 | Router lights blazing at 3 am / constant heavy traffic with everything “off” | Low-Medium |
| 9 | Internet suddenly, persistently slow | Low |
The high-severity four (1–5)
Changed DNS is the classic smoking gun. DNS is your internet’s phone book; controlling it lets an attacker hand you a counterfeit bank login page at the real address. Log into your router’s admin panel and find the DNS settings (usually under Internet/WAN). “Automatic/from ISP” is normal. So are well-known resolvers you chose — 1.1.1.1, 8.8.8.8, 9.9.9.9. Random numeric addresses you never entered are not.
Redirects and certificate warnings on major sites (your bank, Google) are the visible symptom of the same attack. One odd warning on one obscure site means little; warnings on big-name sites across multiple devices mean check DNS now.
A locked-out admin password — assuming you’re sure of the password and haven’t fat-fingered it — means someone changed it. There’s no innocent firmware explanation for that.
Remote management enabled when you didn’t enable it, or port-forwarding rules you never created, are doors propped open on purpose. These settings don’t turn themselves on.
Any one of these four: skip to the factory reset section below.
The judgment calls (6–9)
Unknown devices are usually your own gadgets wearing confusing names (“ESP_8F2A31” is probably the smart plug), and modern phones randomize their WiFi addresses, which makes old devices look new. Rename what you can identify; investigate what you can’t.
Mystery WiFi networks from your own router (check the admin panel’s wireless section, not just your phone’s WiFi list — that neighbor’s “FBI Surveillance Van” isn’t yours) can indicate tampering, but some ISP routers legitimately broadcast hidden hotspot or mesh networks.
Nighttime activity and slowdowns are the weakest signals — backups, updates, and streaming devices phone home constantly, and evening slowdowns are usually just your neighborhood using the internet. They only matter combined with the signs above.
The 10-minute triage checklist
Run this before doing anything drastic:
- Log into the admin panel (address on the router’s sticker; also check our walkthrough of where the firewall settings live per brand — same panels). Can’t get in with the correct password? That’s a finding.
- Check DNS (Internet/WAN settings). Anything you didn’t set?
- Check remote management (sometimes “Remote Access,” “Web Access from WAN,” or the vendor cloud settings). Should be off unless you use it.
- Check port forwarding and DMZ. Should be empty in most homes.
- Check the device list. Count roughly matches your household?
- Check firmware version against the manufacturer’s latest.
- From a laptop, visit your bank’s site. Certificate padlock clean?
All clear? You’re very probably fine — do the prevention steps at the end anyway. One or more high-severity findings? Continue.
The factory-reset walkthrough
A factory reset wipes router malware and attacker changes in one stroke. Done in the wrong order, though, it reopens the same door that let them in. Follow the sequence:
Step 1: Note what you’ll need to rebuild
Photograph or write down your ISP connection details (PPPoE username/password if your ISP uses one — check your welcome letter), your WiFi network names, and any settings you legitimately customized. Do not back up the router config file to restore later — that would faithfully restore the attacker’s changes too.
Step 2: Reset
With the router powered on, hold the recessed Reset button (paperclip) for about 10 seconds until the lights blink differently, then release. App-managed systems like eero and Deco can also be reset from the app or by their own button procedures — the manual is right for your model; the paperclip is right for almost everyone.
Step 3: Rebuild in this exact order
- Set a new, unique admin password first — before anything else. This is the password the attacker likely abused. Generate a long random one and store it in a password manager (1Password Families is what we use, and router admin passwords are exactly the kind of thing it exists for).
- Update the firmware immediately, before reconnecting your devices. If the attacker got in through a known firmware flaw, skipping this step means reinfection.
- Set new WiFi passwords (WPA2 or WPA3). Yes, you’ll re-join every device — that’s the point. If the WiFi password was compromised, keeping it re-invites the neighbor’s “borrowed” access too.
- Turn off the risky conveniences: remote management, WPS, and UPnP unless you have a specific need. Our full guide to these settings covers what each one is and what breaks.
- Re-create only the customizations you understand, one by one. Every port-forward you don’t restore is a door that stays closed.
- Recheck DNS a day later. If it changes again on its own, the router may be compromised at a level a reset can’t fix (or the attacker is inside a device on your network) — at that point, replace the hardware and scan your computers with a reputable antivirus.
Step 4: Aftercare
If you found high-severity signs, assume passwords typed while the router was compromised may have been exposed on any site without HTTPS, and change your critical ones (email, banking) from a clean device. Turn on two-factor authentication where it’s offered — it’s the single best containment for leaked passwords.
Prevention: the boring list that works
- Firmware updates on automatic, or a calendar reminder quarterly if your router can’t self-update. Old firmware is how the overwhelming majority of these compromises begin — it’s also the first item in CISA’s home network security guidance.
- Unique admin password, never the sticker default.
- Remote management, WPS, UPnP: off by default, on only with a reason.
- Smart devices on a guest network so a compromised gadget can’t reach your real machines — ten-minute setup guide here.
- Retire unsupported routers. A router that stopped receiving security updates is a vulnerability with antennas. If yours is more than five or six years old, check the manufacturer’s support page and see our current router picks.
- Want to actually see your traffic? The reason these hacks go unnoticed for months is that routers are black boxes. A monitoring firewall like the Firewalla Purple SE alerts you when a device starts talking to somewhere new — sign #8 stops being a guess and becomes a notification.
The bottom line
Most scary router symptoms are innocent, but changed DNS, unknown port forwards, mystery remote access, or a hijacked admin password are not — and the cure is a clean reset done in the right order: new admin password, firmware update, new WiFi passwords, conveniences off. If this episode taught you that you have no idea what’s happening on your own network, that’s fixable: the Firewalla Purple SE is the device we recommend to anyone who wants to answer “is my router hacked?” with data instead of vibes.
