Compromised router or gateway
In plain terms
Everything your household does goes through the router. Compromised, it can send every device in the home to fake sites — without anything being installed on those devices.
Definition
A compromised home router is a household's internet access equipment whose configuration has been altered by a third party, letting them redirect or observe the traffic of every connected device.
How it works
Access is gained through the admin interface: a factory password left unchanged, an interface accessible from the internet, or firmware that was never updated. Once in, the change most useful to the attacker is the DNS servers, the directory that translates a domain name into an address: by replacing them, the attacker can send a perfectly correct address to a server of their choosing. Nothing is installed on phones or computers, which makes the problem invisible to antivirus software, and the effect hits the whole household at once, including smart devices. Encryption limits the damage — a browser will flag a certificate that doesn't match — but the redirection remains effective toward pages designed for exactly this.
Warning signs
- Certificate warnings on several sites and several devices at once
- Unexpected redirects affecting the whole household, not a single device
- Router DNS servers different from the internet provider's
- Router admin password that no longer works
- Unknown devices in the list of connected equipment
- Remote access to the admin interface enabled from outside
How to verify
Log into the router's admin interface and check three settings: the DNS servers, remote administration, and the list of connected devices. A certificate warning appearing on several devices at the same time points to the network rather than the devices, and it's the clearest signal.
What to do
Change the admin password as soon as you set it up, disable remote administration from the internet, apply firmware updates, and use a guest network for smart devices. These four steps remove most of the entry paths.
If it already happened
Reset the router to factory settings, then reconfigure it with a unique password and your provider's DNS servers. Update the firmware before anything else. Then change the passwords of sensitive accounts used from this network, since traffic may have been redirected during the affected period.
Frequently asked questions
- My antivirus isn't detecting anything, is that normal?
- Yes: nothing is installed on your devices. The change is in the router, upstream, which puts it out of an antivirus's reach. That's what makes the collective symptom — several devices, at the same time — more telling than any scan.
- Is resetting the router enough?
- It's the right first step, provided you don't put the factory password back or re-enable remote administration afterward. Also update the firmware: if the entry point was a software flaw, a reset alone leaves it open.
Related attacks
Official sources
This article is part of the Phones and connected devices family. Last updated: 2026-09-03.