Many end-of-life home routers remain vulnerable to cybercriminal attacks, FBI warns

A recent survey reveals that most users neglect crucial router security updates, leaving millions of legacy devices susceptible to malware and abuse, prompting fresh concerns over internet safety and manufacturer responsibilities.

Home routers are one of the few consumer devices that still rely heavily on user discipline for basic security. That is a problem, because many users do not manage firmware updates, change default passwords or alter factory settings, even though most know they should. A 2025 survey of 3,242 internet users found that 84% had never updated their router’s firmware, 81% had never changed the default administrator password and 47% had never changed the factory defaults, according to broadband.co.uk and Bitdefender.

The risk is not theoretical. In May 2025, the FBI warned that criminals were targeting end-of-life routers and loading them with malware from the TheMoon family to turn them into proxy devices for anonymous cybercrime. The bureau said these routers are often old enough that they no longer receive security updates, which leaves known weaknesses exposed. TechRadar and GovTech reported the same alert, noting that compromised routers can be rented out as proxy infrastructure.

The scale of abuse has already been significant. The FBI’s warning came amid ongoing efforts to disrupt proxy-for-hire operations, including a Justice Department case that alleged $46 million in proceeds from one such network. Researchers have also tracked rapid mass-compromise campaigns: a newer TheMoon variant reportedly infected thousands of Asus routers in a matter of days, reaching tens of thousands of devices across dozens of countries.

There is, however, an important distinction between old and newer hardware. Many recent mesh systems, ISP-supplied gateways and some standalone routers now update themselves automatically, which reduces the burden on users who never check firmware manually. But that does not help devices that have reached end of support. The FBI said many of the routers being abused were from 2010 or earlier, and once support ends, the device effectively stops receiving the fixes that keep it safe.

That makes the practical advice straightforward. Users should check the model number on the router label, confirm whether the manufacturer still issues firmware updates and replace devices that have fallen off the support list. The FBI also recommends disabling remote management and using strong, unique passwords. In Europe, the regulatory direction is also moving towards stronger baseline security, with default-password rules and update obligations placing more pressure on manufacturers to build in protection rather than leave it to customers.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.