NSA Says Reboot Your Router: What the Warning Means and What to Do

In April 2026 the FBI took over thousands of hijacked home routers and the NSA told everyone to reboot theirs weekly. Here is what was going on, why a reboot helps, what it cannot fix, and the four checks that decide whether your router stays or goes.

Updated on
NSA Says Reboot Your Router: What the Warning Means and What to Do

In April 2026 a lot of people got the same push alert: the NSA wants you to reboot your router. The headlines made it sound like an emergency. The advice behind it is older and calmer than that, and most of it is the kind of maintenance a router should be getting anyway. This guide explains what prompted the warning, why rebooting helps against one specific kind of attack, what a reboot cannot fix, and the four checks that tell you whether your router needs a reboot, a settings change, or a replacement.

Key Takeaways

  • The warning followed an FBI operation on April 7, 2026 that cleaned up thousands of home and small-office routers hijacked by a Russian military intelligence unit.
  • The attackers changed the routers' DNS settings so they could see and redirect traffic from every device in the house. The vulnerable models were TP-Link routers running old firmware.
  • The NSA's guidance is to reboot your router at least weekly, change default passwords, turn off remote management, keep firmware current, and replace routers that no longer get updates.
  • A reboot clears malware that lives only in the router's memory. It does not close the hole the malware came in through. Firmware updates and replacement do that.
  • The most useful check you can do today takes two minutes: open your router's settings and confirm the DNS servers listed are ones you recognize.

What Happened in April 2026

On April 7, 2026 the Department of Justice and the FBI announced a court-authorized operation, which the FBI called Operation Masquerade, to clear the U.S. portion of a network of compromised home and small-office routers. According to the DOJ press release, the routers had been taken over by GRU Military Unit 26165, the Russian military intelligence group better known as APT28 or Fancy Bear.

The method matters, because it is the reason the advice that followed focused on reboots and DNS. Since at least 2024 the group had been using known, already-patched vulnerabilities in TP-Link routers to steal the routers' login credentials. Once inside, they changed one setting: the DNS servers. DNS is the phone book that turns a name like outlook.com into an address your device can connect to. By pointing the router at their own DNS servers, the attackers could see every site request from every device in the house, and for targets they cared about, they could serve a fake address for a real service and capture passwords, login tokens, and email on the way through.

The DOJ describes the initial targeting as indiscriminate. The group compromised routers first and sorted out which ones were interesting later, which is why routers in ordinary homes across more than 23 states ended up in the network. The FBI's operation sent commands to the affected U.S. routers to remove the rogue DNS servers and restore the ISP's, without otherwise touching the owners' settings.

The NSA's "reboot your router" message came a few days later. It was not a new advisory. The agency pointed people back to its Best Practices for Securing Your Home Network information sheet, first published in February 2023, which opens with the line every news outlet quoted: "Don't be a victim!"

What the NSA and FBI Are Asking You to Do

Between the NSA sheet and the FBI's remediation steps, the ask comes down to a short list.

  • Reboot your router at least weekly. The NSA sheet says that at a minimum you should schedule weekly reboots of your router, phones, and computers, because regular reboots help remove implants.
  • Replace routers that have reached end-of-life or end-of-support. This is the FBI's first remediation step and the NSA's as well. A router that no longer receives firmware updates cannot be patched against the next vulnerability.
  • Update to the latest firmware. The vulnerabilities used in this operation were already known and already fixed. The routers that got hijacked were the ones that had not installed the fix.
  • Verify the DNS servers in your router's settings. The FBI's third step, and the one most directly tied to what these attackers did.
  • Change default usernames and passwords, and turn off remote management from the internet. The NSA sheet calls this limiting administration to the internal network. If the router's settings page cannot be reached from outside your house, a stolen password is far less useful.

The NSA sheet goes further for people who want to: use WPA3 (or WPA2/WPA3 mixed mode) for WiFi security, put guests and smart home devices on a separate guest network, and disconnect devices you are not using. None of it requires special equipment.

Why a Reboot Helps, and What It Cannot Do

Most home router malware never touches the router's permanent storage. It runs in memory, the same way a program runs on your computer until you close it. Pull the power and that memory is wiped, and the malware is gone. That is the entire reason the NSA recommends a weekly reboot: it evicts anything living in memory on a regular schedule, whether you knew it was there or not.

What a reboot does not do is fix the reason the malware got in. If the router has an unpatched vulnerability, the attackers can come right back, and in an automated operation like this one they will. A reboot also does not undo a settings change. The GRU's DNS change survived reboots because it was saved to the router's configuration, not held in memory. The FBI had to send commands to reverse it.

So the reboot is the cheap, repeatable habit. The firmware update is what closes the door. The DNS check is what tells you whether someone has already been through it. And replacement is the answer when the manufacturer has stopped shipping fixes.

If you have not restarted a router in a while and want the correct order for a modem and router, or how to set up an automatic weekly reboot on NETGEAR, TP-Link, and ASUS routers, our guide on how to restart your router covers all of it, including the difference between a restart and a factory reset.

The Four Checks

Is your router still supported?

Find the model number on the label and search the manufacturer's support site for it. Every major brand publishes an end-of-life or end-of-service list; TP-Link's is here, and the DOJ pointed affected owners to it directly. If your model is on the list, or the last firmware release is more than a couple of years old, the router is done as a security device no matter how well it still moves traffic. Our guide on how long routers last covers the other signs that a router has aged out.

Is the firmware current?

Log into the router's settings page and look for Firmware Update, usually under Administration, System, or Advanced. Most routers made in the last five years can check for and install updates from that screen, and many can be set to update automatically, which the NSA sheet recommends. If you have never done this, the first update may take several minutes and reboot the router on its own. If you cannot get into the settings page, start with how to log into your router.

Are the DNS servers ones you recognize?

This is the check that speaks directly to what happened. On the same settings page, find the DNS or Internet settings. You should see one of three things: "Obtain automatically from ISP," a well-known public resolver you set yourself (Cloudflare's 1.1.1.1, Google's 8.8.8.8, Quad9's 9.9.9.9, and so on), or nothing at all because the router is in automatic mode. If you see server addresses you do not recognize and never entered, set the router back to automatic or to a resolver you trust, then update the firmware and change the admin password. For brand-by-brand menu paths, see how to change DNS on your router; for which resolver to pick, see the best DNS servers.

Is remote management turned off?

Look for Remote Management, Remote Access, Web Access from WAN, or similar. It should be off. This setting lets the router's settings page be reached from the internet, which is convenient for exactly nobody in a normal household and is the front door for credential attacks. While you are there, if the admin password is still the one printed on the label, change it, and if the WiFi password is the factory one, change that too.

Reboot, Fix, or Replace?

Putting the four checks together gives you a clear answer.

  • Supported, firmware current, DNS clean, remote management off: you are in good shape. Set a weekly automatic reboot and move on.
  • Supported, but firmware behind or a setting wrong: update the firmware, fix the setting, change the admin password, reboot. Then schedule the weekly reboot.
  • DNS servers you do not recognize: treat the router as compromised. Fix the DNS, update, change every password, and consider a factory reset to clear anything else that was changed. Then decide whether you trust it going forward.
  • End-of-life or no updates in years: replace it. No amount of rebooting fixes a router that cannot be patched.

If It Is Time to Replace

A replacement does not have to be expensive to fix the problem. Any current WiFi 6 router from a major brand is still receiving firmware updates, supports WPA3, and has a modern automatic-update setting. For a smaller home or apartment, the NETGEAR R6700AX WiFi 6 router covers the basics without paying for features a two-bedroom will never use. As an Amazon Associate, ModemGuides earns from qualifying purchases. For more options, including refurbished units we test and cover with a 90-day warranty, see our WiFi 6 routers.

One more thing the NSA sheet says that gets less attention: it suggests owning your own router rather than relying only on the one your ISP provides, because provider equipment does not always get updates on a reliable schedule. If your ISP has told you your equipment is no longer supported, our guide on what to do when your modem is no longer supported walks through the options.

Frequently Asked Questions

Do I need to reboot my router right now?

It does not hurt, and if you have never done it, go ahead. But the one-time reboot is the least important part of the advice. The firmware update, the DNS check, and the end-of-life check are what protect you against the next version of this.

I don't have a TP-Link router. Does this apply to me?

Yes. TP-Link was the brand in this particular operation because of specific vulnerabilities in specific models, but the same playbook (known vulnerability, old firmware, stolen credentials, changed settings) has been run against NETGEAR, ASUS, Cisco, Ubiquiti, and MikroTik routers in earlier operations. The four checks apply to every brand.

How do I know if my router was one of the compromised ones?

The FBI said it is working with internet providers to notify affected customers, so watch for a message from your ISP. On your own, the DNS check above is the best indicator. If the DNS servers in your router's settings are ones you never set, the router was changed by someone. The FBI asks anyone who believes their router was compromised to file a report at ic3.gov.

Will a factory reset remove router malware?

A factory reset wipes the configuration, which undoes changed settings like DNS, and reboots the router, which clears memory. It does not update firmware, so if the vulnerability is still there the router can be compromised again. Reset, then update, then change the passwords, in that order.

Is a weekly reboot bad for the router?

No. Routers are built to be power cycled. A scheduled reboot at 3 or 4 AM is invisible to the household and is exactly what the NSA sheet recommends.

Should I stop using the router my ISP gave me?

Not necessarily, but you should know whether it still gets updates. Provider gateways are updated by the provider, on the provider's schedule, and some models are left behind. If yours is several years old and the provider offers a newer one, or you would rather own your equipment, that is a reasonable moment to switch.

Related Guides

USA-Based Modem & Router Technical Support Expert

Our entirely USA-based team of technicians each have over a decade of experience in assisting with installing modems and routers. We are so excited that you chose us to help you stop paying equipment rental fees to the mega-corporations that supply us with internet service.

Updated on

Leave a comment

Please note, comments need to be approved before they are published.