Why broadband router security matters right now
Most of us treat the router in the hallway cupboard the way we treat the fuse box: we assume it works and we never look at it again. That’s the whole problem with broadband router security. It’s invisible until it isn’t.
In April 2026 the UK’s National Cyber Security Centre (NCSC) publicly named Russian military intelligence as being behind a campaign hijacking vulnerable routers for DNS hijacking attacks, describing the targeting as “likely opportunistic in nature, with the actor casting a wide net”. Separately, NCSC has issued an advisory on compromised internet edge routers, where attackers obtained credentials, pulled down configuration files and set up tunnels to intercept traffic passing through.
Two things are worth being straight about. Both of those advisories are addressed to network operators, organisations and network defenders rather than to households, so nobody is claiming your specific hallway router is on a target list. But the weaknesses they describe, unpatched firmware, exposed management interfaces and weak credentials, are the same weaknesses sitting in a lot of home routers. That is why the household checks below are worth five minutes, alongside the usual home wifi security basics like a strong wifi password and a separate guest network.
That’s the Do-Nothing Default at work. Providers ship a router once, at the start of your contract, and most households never think about it again until the wifi drops out. Meanwhile the box quietly stops getting security updates.
Is my router actually at risk?
Probably worth five minutes to check, without losing sleep over it. The pattern in NCSC’s advisories is consistent: old devices, unpatched firmware, and management interfaces reachable when they don’t need to be.
If your router was supplied when you signed up years ago and you’ve never logged into its settings, updated its firmware, or changed the admin password, you’re carrying the same weaknesses the advisories describe. That doesn’t mean you’ve been hacked. It means your broadband router security is currently resting entirely on luck.
This isn’t a UK-only quirk either. NCSC’s April 2026 attribution was published alongside international partners, because the vulnerable equipment involved is sold worldwide, not because British households are being singled out.
The five-minute broadband router security checklist
The short version: attackers don’t need to breach your provider or your bank. They just need an old router with a known flaw sitting on a network, quietly forwarding traffic somewhere it shouldn’t. The checks below are our own household translation of the mitigations NCSC recommends, which centre on protecting management interfaces, keeping devices and software up to date, and turning on two-step verification where it’s offered.
| Sign to check | Why it matters | What to do about it |
|---|---|---|
| Router is 4+ years old | Older hardware often stops receiving firmware updates | Ask your provider if a free upgrade is due, or budget for a new one |
| Still using the default admin password | Default logins are published online and are the first thing attackers try | Change it via the router’s settings page or app |
| Remote management left switched on | Exposes the router’s management interface from outside your home network | Turn it off unless a technician has specifically asked you to enable it |
| Firmware update ignored or never checked | Updates usually patch the exact flaws attackers rely on | Check for an update in the router’s app or admin page |
None of these checks require a computing degree. They’re closer to checking your smoke alarm has a battery in it: dull, quick, and the sort of thing that only matters on the one day it matters.
How do I check my router in five minutes?
Log into your router’s settings, usually through an app from your provider or by typing an address like 192.168.1.1 into a browser. From there you’re looking for four things: the admin password, the firmware version, remote management, and the age of the device itself.
Change the admin password to something unique if it’s still the default printed on the sticker. Update the firmware if an update is sitting there waiting. Switch off remote management unless you have a specific reason to keep it on. If the router is old enough that none of those options are clearly labelled, that’s usually a sign it’s due for retirement anyway.
Roughly five minutes, once. Compare that to the Do-Nothing Default, which costs you nothing today and potentially your login details next year.
Should you buy a new router or wait for your provider?
Some providers will replace an old router for free if you ask, particularly if you’re still in contract and complain about slow wifi rather than security. Others will only swap it out when you take out a new deal. It’s worth ringing and asking before you assume you have to pay, and worth knowing what you’d actually be getting: our WiFi 7 router guide covers whether the newest kit is worth chasing or overkill for most homes.
If your contract is coming to an end anyway, switching provider is often the cheapest way to get new kit, since a new router typically comes bundled with a new deal at no extra cost. Broadband switching in the UK now runs through Ofcom’s One Touch Switch process, so your new provider handles the move and you’re not left juggling two contracts or a gap in service. For a lot of households, that’s the easiest broadband router security upgrade available: a new box, arranged as part of a switch you were probably going to do anyway.
It won’t fix broadband router security on its own if you then leave the new box on default settings too. But it does mean you’re not stuck defending five-year-old hardware because switching felt like too much hassle.
Key takeaways
- NCSC named Russian military intelligence in April 2026 over a campaign hijacking vulnerable routers, describing the targeting as opportunistic and wide.
- Those advisories are aimed at operators and network defenders, but the weaknesses they describe are common in home routers too.
- Broadband router security mostly comes down to four checks: password, firmware, remote management, and age.
- Providers don’t always replace old routers unprompted, so it’s worth asking directly.
- A new contract or switch often comes with a new router as standard, which can be a simple way to retire old hardware.
Frequently asked questions about broadband router security
- How do I know if my router has been hacked?
- Common signs include unfamiliar devices on your network, a router that keeps rebooting or slowing down for no clear reason, or your provider or bank flagging unusual login activity. If in doubt, restart the router, change the admin password, and check for a firmware update.
- Is my ISP-supplied router safer than one I buy myself?
- Not automatically. What matters is how old it is and whether it still gets security updates, not who sold it to you. A recent router from any reputable brand, kept updated, is generally fine.
- Will changing my wifi password fix broadband router security?
- It helps, but it’s only one part of the picture. The wifi password protects who can join your network, while the separate admin password protects the router’s own settings. Proper broadband router security covers both.
- How often should I replace my router?
- There’s no fixed rule, but many routers stop receiving firmware updates after around four to five years. If yours is older than that and support has ended, it’s worth asking your provider about a replacement or budgeting for a new one.
- Does switching broadband provider get me a new router?
- Usually, yes, though it depends on the deal. Most new contracts include a router as standard, which can be a straightforward way to retire an old one, but it’s worth checking the specifics before you switch.




