Has Your Router’s DNS Been Hijacked? How to Check

Key Takeaway:
In April 2026 the FBI warned that Russian military intelligence was breaking into home and small-office routers — mainly older TP-Link models — and quietly changing one setting: the DNS server the router hands to every device on the network. From then on, the attackers could answer “where is this website?” for the whole household and try to sit in the middle of logins. You can check for this yourself in about two minutes: find out which DNS server actually answers your devices, then look up who runs it. Your provider, Google, Cloudflare or your VPN is normal. A hosting company you’ve never heard of is not.


What the FBI Warned About

On 7 April 2026 the FBI’s Internet Crime Complaint Center published an alert about a unit of Russia’s GRU military intelligence, tracked by security companies as APT28 or Fancy Bear. According to the alert, the group exploited vulnerable small-office and home routers and changed their DNS and DHCP settings so that traffic went through servers it controlled.

  • The devices: TP-Link routers vulnerable to CVE-2023-50224, a flaw in the router’s built-in web server that can expose stored credentials to an attacker on the same network. TP-Link’s advisory lists dozens of legacy models, including the TL-WR840N, TL-WR841N, TL-WR940N, Archer C5 and Archer C7, and most of them no longer receive updates.
  • What the attackers did with them: redirected DNS lookups to their own resolvers, which let them attempt man-in-the-middle attacks on the people behind the router.
  • What they got: the FBI says the group harvested passwords, authentication tokens, emails and browsing information.
  • The signs it lists: changed DHCP or DNS settings on the router, and certificate warnings when opening services such as Outlook Web Access.

The alert doesn’t say how many homes were affected. What matters for everyone else is that the technique is simple, and the routers involved are ordinary consumer models that are still plugged in all over the world — many of them past the point where they will ever be patched.


How DNS Hijacking Works

When a phone or laptop joins your Wi-Fi, the router tells it which DNS server to use. Every time you visit a site, the device asks that server for the site’s address. Normally the answer comes from your internet provider or a public service like Google or Cloudflare.

Change that one setting and every device in the house starts asking the attacker instead. The attacker can answer honestly for most sites — so nothing seems broken — and lie only for the ones it wants: your email, your bank, a work login. You type the right address and land on the wrong server.

HTTPS is what usually saves you. A fake server can’t present a valid certificate for your bank’s real name, so the browser shows a full-page warning instead of the site. That’s why the FBI lists certificate warnings as a sign of compromise, and why the single most important habit here is simple: never click past a certificate warning on a site you log in to.


🔍 Step 1: Find Out Which DNS Server Really Answers You

Your device’s settings usually won’t tell you. Most home routers hand out their own address — something like 192.168.1.1 — as the DNS server, then pass your questions on to the real one behind the scenes. So “DNS server: 192.168.1.1” looks normal whether the router is clean or not.

The way around that is to ask a test hostname that replies with the address of whichever server asked it. Run one of these on a device connected to your Wi-Fi, with any VPN switched off:

DeviceCommand
Windows (Command Prompt or PowerShell)nslookup -type=txt o-o.myaddr.l.google.com
macOS or Linux (Terminal)dig +short TXT o-o.myaddr.l.google.com
A second check (any of them)nslookup whoami.akamai.net

The address in quotes (Google’s test) or under “Address” (Akamai’s) is the server that actually did the lookup for you — something like 203.0.113.53 or a long IPv6 address. Write it down. Google’s answer can include a second line marked edns0-client-subnet; that one is a rough version of your address, not the resolver’s, so ignore it.

Want to see what each device is configured with as well? How to check your DNS settings walks through Windows, macOS, iPhone, Android and the router.


Step 2: Look Up Who Runs That Server

Paste the address into the ASN Lookup. It shows which network the address belongs to and which organisation runs it. The Reverse DNS Lookup often adds a giveaway hostname, and the WHOIS Lookup shows who the address block is registered to.

The server belongs to…What it means
Your internet providerNormal — the default for most homes.
Google, Cloudflare, Quad9 or similarNormal if you or whoever set up the router chose it. Some providers also forward to these.
Your VPN providerNormal while the VPN is on — but run the test with it off to check the router itself.
A hosting company you’ve never heard of, often in another countryRed flag. Check the router’s DNS settings straight away (Step 3).

An unfamiliar name isn’t proof on its own — providers sometimes resell or run their DNS under a parent company’s name. What should make you act is a mismatch you can’t explain: a broadband customer in Ohio whose lookups are answered by a small hosting firm overseas. It’s also worth running the address through the IP reputation check to see whether it already appears on abuse blacklists.


Step 3: Check the Router Itself

Log in to the router’s admin page — usually by typing its address, such as 192.168.1.1 or 192.168.0.1, into a browser. The address and the default login are normally printed on a sticker on the router.

  • DNS settings. Look in two places: the internet or WAN settings, and the DHCP or LAN settings. If either lists DNS servers you didn’t set — and they aren’t your provider’s — treat the router as compromised.
  • Remote management. Find “remote management”, “web access from WAN” or similar. It should be off. Both the FBI and TP-Link recommend turning it off.
  • Firmware. Check the version against the manufacturer’s support page. If the model no longer gets updates at all, that is the real problem.
  • The model. If it’s an older TP-Link, compare it with the list in TP-Link’s CVE-2023-50224 advisory. Several listed models will never be patched.

⚠️ If Your Router’s DNS Has Been Changed

  1. Factory-reset the router rather than just correcting the DNS field. Whoever changed it may have changed other things, or still have the password.
  2. Install the latest firmware before reconnecting your devices, if there is one for your model.
  3. Set a new, unique admin password — not the default from the sticker — and turn remote management off.
  4. Replace the router if it’s end-of-life. A model that no longer receives updates will stay vulnerable however carefully you set it up. In February 2026, CISA, the FBI and the UK’s National Cyber Security Centre jointly warned that state-backed hackers target routers, firewalls and VPN gateways that are past their support date, and US federal agencies were given a year to remove theirs.
  5. Change the passwords you used while it was compromised, starting with email, and sign out of other sessions where the service allows it. Stolen login tokens can work without a password, which is why signing out matters.
  6. Run Step 1 again on each device to confirm lookups now go where they should.

The longer checklist for locking down a home network — Wi-Fi encryption, WPS, guest networks and the rest — is in How to secure your home network.


Does DNS over HTTPS or a VPN Protect You?

DNS over HTTPS, partly. If your browser is set to use encrypted DNS with a provider you picked — in Chrome, “Use secure DNS” with a named provider; in Firefox, DNS over HTTPS with a chosen provider — the browser’s own lookups skip the router’s DNS entirely, so a hijacked router can’t redirect them. Other apps on the device still use the router’s setting, and the browser’s “automatic” mode may fall back to whatever the system uses. More in What is DNS over HTTPS.

A VPN, while it’s on. Most VPN apps send DNS through the tunnel to their own servers, so lookups bypass the router. That protects the device while connected; it doesn’t fix the router, and it does nothing for the smart TV or the guest’s phone on the same Wi-Fi. If a VPN’s DNS isn’t going through the tunnel properly, that’s a DNS leak.

Neither replaces the fix. The router is the thing that was broken into.


FAQ

My device says the DNS server is 192.168.1.1. Is that bad?

No — that’s the router itself, and it’s how most home networks work. The router forwards your lookups to the real server, which is why Step 1 asks the test hostnames instead of trusting the device settings.

Is my TP-Link router affected?

Only some older models are named, and TP-Link’s advisory lists them with hardware versions. Check the label for the model and version, then compare. If yours is on the list and no longer supported, replacing it is the safest option.

Will a factory reset remove the problem?

It restores the original settings, including DNS. On its own it doesn’t fix the flaw that let someone in, so update the firmware, change the admin password and turn off remote management straight after — or replace the router if it’s out of support.

Can this happen on mobile data?

Not this attack. It lives in your router, so it only affects devices on that Wi-Fi network. On mobile data your phone uses the carrier’s DNS.

Would I notice anything?

Often not. Most sites keep working because the attacker answers honestly for them. Certificate warnings on familiar sites are the clearest outside sign — which is why checking the DNS server directly is worth the two minutes.


The Short Version

A compromised router can quietly change who answers your DNS lookups for every device in the house. Ask a test hostname which server really answers you, look that server up, and if it belongs to someone you can’t explain, reset the router, update it or replace it, and change your passwords. And whatever else happens, don’t click past certificate warnings.

Sources

Related Reading

Scroll to Top