SDMacTech note: Security advice is most useful when it becomes a habit. If you are unsure whether this applies to your Mac, iPhone, iPad, router, or home office setup, we can help you check it safely. Moreover, we can explain the options in plain English.
Securing your home network might seem uninteresting or unimportant. After all, who would bother to target you? The answer is that criminal hackers are interested in your router for a range of disturbing purposes. These include attacks on your employer if you connect to a corporate network. It’s time to get serious about home network security, especially in light of recent news regarding hacking activities by the Russian military.
In April 2026, the U.S. Department of Justice announced Operation Masquerade, which disrupted a campaign by a hacking unit of Russia’s GRU that compromised thousands of home and small-office routers. The attackers exploited known vulnerabilities in TP-Link routers to hijack DNS settings, redirecting victims to fake web pages that harvested passwords, authentication tokens, emails, and other sensitive information.
The attack was opportunistic: the GRU cast a wide net, compromising routers indiscriminately and then filtering for targets of intelligence value. While your data may not be of interest to Russian intelligence, the same vulnerabilities can be exploited by criminal hackers seeking financial data, credentials for identity theft, or devices to conscript into botnets.
Unlike corporate networks with dedicated IT staff, home routers tend to be installed once and forgotten, sometimes for a decade or more. That old router your AV installer set up with a default password has become a security liability for you, your employer, and the world. Here are actions you can take to fix that, in rough order of importance.
Routers can last many years, but manufacturers eventually stop releasing firmware updates. Once that happens, known vulnerabilities go unpatched, and the router becomes ripe for attack. Check your manufacturer’s end-of-life lists (easily found with a search) to see if your model is still supported. If it’s not receiving security updates, replace it regardless of how well it still works.
When shopping for a replacement, look for routers with automatic firmware updates from a well-known manufacturer with a track record of long-term security support, such as Asus, Eero, Google Nest, Netgear, or Ubiquiti. Avoid bargain-basement devices from unknown manufacturers. Any initial savings aren’t worth the security risk.
Router firmware updates patch security vulnerabilities, and the GRU attack exploited a known vulnerability that had an available fix. Enable automatic firmware updates if your router supports them, many modern routers do. If yours doesn’t support automatic updates, set a monthly reminder to check manually. Because new vulnerabilities are discovered regularly, keeping a router secure is an ongoing process, not a one-time task.
Every router ships with default administrator credentials, often printed on a sticker on the device itself. These defaults are widely known and easily found online. Change the admin password immediately after setup to something strong and unique. Also, store it in your password manager.
Similarly, change the default Wi-Fi network name (SSID) and password. Use WPA3 for wireless traffic encryption if available. Most modern routers support compatibility mode that lets older devices connect, while newer ones benefit from stronger security. Never use WEP or leave your network open.
Many routers offer a remote login option that allows access to the administrative interface from elsewhere on the Internet (rather than within the router’s own network). Unless you specifically need this capability, deactivate it to reduce your exposure to external attacks. This setting is different from the app-based management provided by some modern routers, which use a secure account and an outbound connection initiated by the router to enable remote access. App-based management is safe as long as your account password is strong, unique, and protected with two-factor authentication.
As seen in the recent attacks targeting some TP-Link routers, attackers who gain access often change DNS servers to redirect you to malicious websites without your knowledge. Verify that your router’s DNS settings are either obtained automatically from your ISP or point to a reputable service such as Cloudflare (1.1.1.1), Google (8.8.8.8), or Quad9 (9.9.9.9). Unfamiliar IP addresses in these settings are a red flag that your router may have been compromised.
If you ensure you are using a router that’s still receiving security updates, are installing those updates, and have changed the default admin and Wi-Fi passwords, you’ve achieved an entirely acceptable level of security. With a little more time and effort, you can increase security further:
Home network security isn’t complicated, but it does require some thought at setup and occasional attention. If you’d like help with your network or a pointer to the routers we currently recommend, get in touch with us at SDMacTech. At SDMacTech, we help San Diego Mac, iPhone, and iPad users make technology less frustrating and more reliable.
(Featured image by iStock.com/Igor Nikushin)
You must be logged in to post a comment.