Monthly router reboots are no longer enough to counter advanced cyber threats, experts warn

Recent US and allied cyber guidance emphasises that simple monthly restarts of home routers are insufficient against sophisticated state-backed cyber attacks. Security experts advise updating firmware, replacing unsupported devices, and implementing stricter network controls to safeguard critical infrastructure and personal networks.

Restarting a home router once a month is sensible maintenance, but the broader lesson from recent US and allied cyber guidance is that rebooting is only the first line of defence. In July 2026 the National Security Agency and partner agencies warned that Russian state-backed operators were still exploiting poorly secured networking equipment across sectors including communications, energy, financial services, government facilities and healthcare, turning ordinary routers into useful stepping stones for wider attacks.

That does not make a restart pointless. Consumer guidance published by the National Cybersecurity Alliance in April 2026, after US agencies disrupted a Russian intelligence-linked router network, said even equipment supplied by an internet provider should be unplugged for 30 seconds to a minute. The group said monthly restarts were “a good place to start”, because the process can clear temporary connections and sometimes interrupt limited forms of malicious activity. Its more important point, however, was that a reboot should prompt users to check for firmware updates and enable automatic updates where the router supports them.

The reason is that unsupported routers are now a distinct security risk. In a May 2025 alert, the FBI said end-of-life models, especially devices dating from 2010 or earlier, are attractive targets because their manufacturers no longer release patches. The bureau said variants of TheMoon malware had been found on some such devices and listed overheating, erratic connectivity and unexplained settings changes as warning signs. Its advice went well beyond restarting: replace unsupported hardware where possible, disable remote administration, and use unique random passwords between 16 and 64 characters.

The official warnings also explain why routers matter to attackers. In an August 20, 2025 public service announcement, the FBI said operators linked to Russia’s FSB Center 16 had been exploiting SNMP and unpatched Cisco flaws, including CVE-2018-0171 in Smart Install, to collect configuration files from thousands of networking devices associated with US entities across critical infrastructure. In some cases, the attackers altered those files to preserve access and to scout applications tied to industrial control systems. TechRadar’s account of the later multinational advisory said configuration data was then exfiltrated over TFTP, and that the warning also pointed to older Cisco weaknesses such as the CSRF issues in Cisco IOS 12.4 on the 871 Integrated Services Router.

That July 13, 2026 advisory was aimed mainly at organisations rather than households. The NSA urged network defenders to move to SNMPv3, use strong unique passwords, disable Cisco Smart Install, block TFTP, SMI and SNMP at the firewall, and keep software and firmware images patched. Ars Technica reported that compromised routers are valuable because they can be used as proxy or exit nodes, allowing hostile traffic to pass through apparently legitimate residential or office internet connections. The same report noted that these takedowns have become a recurring problem, with botnets disrupted and then rebuilt.

Consumers were also reading these warnings against the backdrop of a separate GRU-linked case earlier in 2026. A joint FBI, NSA and US Cyber Command advisory said APT28, also known as Fancy Bear and Forest Blizzard, had used compromised Ubiquiti EdgeRouters since at least 2022 to harvest credentials, collect NTLMv2 digests, proxy network traffic and host spear-phishing landing pages. Investigators said the operators uploaded custom Python scripts to some routers to validate stolen webmail credentials and deployed tools such as Impacket ntlmrelayx.py and Responder to support NTLM relay attacks.

That advisory drew the clearest line between a routine restart and real remediation. It stated plainly that “Rebooting a compromised EdgeRouter will not remove the existing malware of concern”. For devices believed to be compromised, the recommended response was a hardware factory reset, installation of the latest firmware, replacement of default credentials and tighter firewall rules on internet-facing interfaces. The distinction matters: a restart may help with temporary instability or clear stale sessions, but it is not a clean-up tool once attackers have established persistence.

For household users, the practical message is straightforward. A monthly restart remains a reasonable habit, and unplugging the router for half a minute is still the simplest way to do it. But the higher-value steps are to keep firmware current, switch on automatic updates where available, turn off remote management unless it is genuinely needed, replace hardware that no longer receives patches, and stop using factory logins. If a router runs hot, drops connections repeatedly or shows settings you did not change, the safer assumption is not that the broadband is merely having a bad day, but that the device may need a deeper reset, replacement or a formal incident report.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.