FBI Warned of Cybercriminals Targeting Legacy Routers

The FBI revealed that attackers are exploiting unsupported home routers to mask malicious internet traffic.

Updated on Oct. 2, 2026 in Cybersecurity

Bold flat-color editorial illustration of a black home internet router, representing the security risk of legacy hardware.
The FBI warned that cybercriminals are compromising unsupported home routers to tunnel malicious traffic through legitimate residential internet connections. AI Illustration. Upload story photo >

Live Poll

Is now a good time to replace your old home network routers to improve security?

The FBI has issued a warning regarding threat actors who are compromising end-of-life router hardware to host residential proxy nodes. These compromised devices allow cybercriminals to tunnel malicious traffic through legitimate home internet connections.

Why it matters

Cybercriminals prefer residential IP addresses over commercial data center IPs because they appear legitimate to security filters, allowing them to bypass bot detection systems. This practice can lead to legitimate homeowners becoming targets of investigations into illegal activity.

Legacy hardware like the Linksys E1000, E1200, and E2500 often features vulnerable preinstalled remote management tools. These devices remain at risk because they have not received firmware patches in over five years.

The players

FBI

The Federal Bureau of Investigation is the domestic intelligence and security service of the United States.

Linksys

Linksys is a manufacturer of networking hardware known for its widely distributed home router models.

The details

Threat actors actively scan for vulnerable remote management daemons on older hardware to gain persistent root access. Once compromised, these routers are integrated into botnets that facilitate credential stuffing, phishing, and DDoS attacks.

Timeline

  1. Routers that have not received a firmware patch in over five years are considered vulnerable to exploitation.

The Tech Race

The emergence of residential proxy-as-a-service botnets marks a shift where cybercriminals utilize millions of residential endpoints to blend in with legitimate traffic. This development forces security professionals to contend with an evolving threat landscape where home devices are weaponized to replace traditional data center attack infrastructure.

Owners of older, unsupported routers should immediately upgrade to hardware that still receives regular manufacturer security patches. Continued use of abandoned devices risks unauthorized access to your home network and potential involvement in cybercriminal activity.

The takeaway

Maintaining modern, patched network hardware is the primary defense against having your home connection turned into a proxy for criminal activity. Check manufacturer websites periodically to confirm if your device is still supported by firmware updates.

Further reading

Learn more about the latest digital threats in the Cybersecurity section.

Source note: This article includes information reported by XDA-Developers.

Live Poll

Is now a good time to replace your old home network routers to improve security?