Your router is the most attacked device in your house that you never think about. It runs 24/7, it sits directly on the internet, and most people set it up once in 2019 and never touched it again. Attackers know this. It is why home gateways have quietly become one of the favourite targets going into 2026.
Here are the three threat categories doing the most damage right now, how to tell if you are caught up in one, and how to shut the door. None of this requires you to be technical. It mostly requires you to stop ignoring the box in the corner.
Threat 1: Botnets That Recruit Your Router
This is the big one, and it traces back to Mirai, the malware that broke half the internet in 2016 and never really went away. Its descendants are still everywhere. The play is dumb and effective: scan the internet for routers and smart devices, try a list of default usernames and passwords, and the moment one works, the device joins a botnet.
Your router does not get bricked. That is the point. It keeps working while quietly being rented out to launch denial-of-service attacks or to act as a residential proxy, so someone else’s shady traffic looks like it is coming from your home address. You only find out when your internet crawls or your IP gets blacklisted, which is why it pays to know every device on your network.
The tell: sluggish internet for no reason, the router running hot, or your ISP emailing you about “unusual activity.”
Threat 2: Exploits Against end-of-life Routers
If your router is old enough that the manufacturer stopped shipping firmware updates, it is a sitting duck, and attackers specifically hunt for these models. Every unpatched security hole stays open forever. The FBI has gone as far as warning the public about specific end-of-life router models being mass-compromised, which is not something they do lightly.
The difference from Threat 1 is that this does not need your password at all. The attacker walks through a flaw in the router’s own software. No amount of clever password choice helps if the door frame itself is rotten.
The tell: you cannot remember the last firmware update, or the manufacturer’s website no longer lists your model. If support ended years ago, assume the worst.
Threat 3: DNS Hijacking

This one is sneaky because nothing looks broken. An attacker who gets into your router changes one setting: the DNS server, which is the address book your network uses to turn “yourbank.com” into a real destination. Point that at a malicious server and they can quietly redirect you to fake login pages while the address bar still shows the right name.
It is the perfect crime for stealing credentials, because you typed the correct website and got sent somewhere else without a single warning. Banking and email logins are the obvious prizes.
The tell: sudden certificate warnings, login pages that look slightly off, or being logged out of accounts for no reason. Check your router’s DNS setting and confirm it is your ISP’s or one you chose, like Cloudflare or Google.
The 2026 Wrinkle: It Is All Automated Now
None of these threats are new. What changed is the scale. Attackers run automated tools that scan the entire internet in hours, test thousands of devices, and exploit anything vulnerable without a human lifting a finger.
You are not being personally targeted. You are being swept up by a machine that never sleeps and does not care who you are. That actually makes basic hygiene more important, not less, because the bar is just “be slightly harder than the next router.”
How To Lock Yours Down In Ten Minutes
| Do this | Why it kills the threat |
|---|---|
| Change the admin password (not the Wi-Fi one, the login for the router itself) | Stops botnet brute-forcing in its tracks |
| Update the firmware, then turn on auto-updates | Closes the holes exploit campaigns hunt for |
| Replace any router past its support date | An unpatchable router cannot be secured, full stop |
| Check your DNS setting is one you recognise | Catches a hijack you would otherwise never see |
| Turn off remote management and WPS | Removes the two doors attackers love most |
If you do one thing today, change the router’s admin password and check for a firmware update. That single step shuts out the majority of the automated junk hammering your gateway right now. The corner box deserves ten minutes a year.
Give it that and you drop off the easy-target list entirely.