FBI Warned of Compromised Legacy Routers Used in Botnets
Threat actors are hijacking abandoned, unpatched home hardware to mask malicious traffic as legitimate residential activity.
Updated on Oct. 2, 2026 in Cybersecurity

Live Poll
Is now a good time to replace your old home network routers to improve security?
The FBI issued a warning regarding the exploitation of end-of-life routers that no longer receive security patches. Cybercriminals are hijacking this legacy hardware to host residential proxy nodes for illicit activities.
Why it matters
Criminals use compromised residential IP addresses to bypass automated security filters, making malicious traffic appear as if it originates from a standard home connection. This tactic effectively weaponizes consumer infrastructure to facilitate phishing, credential stuffing, and DDoS attacks.
Attackers gain root access by exploiting vulnerable remote management daemons—background software processes that handle router configuration—often left active on devices that have not received a manufacturer firmware patch in five years.
The players
FBI
The domestic intelligence and security service of the United States responsible for investigating cyber threats and issuing public safety advisories.
Linksys
A networking hardware company known for its consumer-grade routers, including legacy models like the E1000, E1200, and E2500.
The details
Threat actors scan for older router models that remain exposed to the internet with default or unpatched remote management features. Once access is established, the router is integrated into a proxy-as-a-service botnet. This allows criminals to tunnel malicious traffic through the home network, effectively anonymizing the source of cyberattacks by hiding them behind a residential IP address.
Timeline
October 2, 2026: FBI issued the official warning concerning compromised routers.
Past five years: Period during which affected legacy devices have not received security patches.
The Tech Race
This development follows the precedent set by the 2016 Mirai botnet attack, which demonstrated how insecure IoT devices could be repurposed for massive network disruption. It marks a persistent shift where residential hardware becomes the frontline for anonymizing global cybercrime.
Homeowners using routers that have not received firmware updates for several years should replace the hardware immediately, as these devices lack the protections against modern exploit vectors. Running legacy equipment poses a risk of having your home connection identified as a source of criminal traffic during investigations.
The takeaway
Legacy hardware is a permanent security liability that attackers will continue to prioritize for its lack of defensive updates. Check your router model's support status and transition to a device that still receives active security patches to avoid becoming a proxy for criminal botnets.
Further reading
For broader context on current network threats, see our Cybersecurity section.
Source note: This article includes information reported by XDA-Developers.
Live Poll
Is now a good time to replace your old home network routers to improve security?









