NSA & FBI Advisory: Reboot your router regularly to disrupt router malware. Automate it ›
Security Briefing

The 2026 NSA Router Reboot Warning, Explained

In April 2026, U.S. agencies revealed that Russian military intelligence had been hijacking ordinary home routers โ€” and issued urgent, plain-English advice for every household. Here's what happened and what to do.

What the NSA and FBI actually said

On April 7, 2026, the U.S. Department of Justice and FBI announced a court-authorized operation that disrupted a network of compromised home and small-office routers. Those routers had been quietly conscripted by a unit of Russia's GRU military intelligence service. In the days that followed, the NSA and FBI urged the public to take a handful of simple steps to secure their own routers โ€” with regular reboots at the top of the list.

The headline advice is deliberately simple because it works for everyone: reboot your router regularly. As the NSA puts it in its long-standing home-network guidance, weekly restarts help "remove implants" โ€” the hidden malicious code attackers try to leave behind.

"At a minimum, you should schedule weekly reboots of your routing device, smartphones, and computers. Regular reboots help to remove implants and ensure security."

โ€” NSA, Best Practices for Securing Your Home Network

Who was behind it

Security researchers track the group as APT28 โ€” also known as Fancy Bear and Forest Blizzard โ€” a unit tied to the GRU. Rather than attacking targets head-on, the group builds a hidden layer of hijacked home and small-office routers and routes its activity through them. That makes malicious traffic look like it's coming from an ordinary residential address, and gives attackers a foothold inside real home networks.

One documented campaign exploited a vulnerability in certain TP-Link routers, tracked as CVE-2023-50224. Devices that were outdated, running default settings, or no longer receiving security updates were the easiest to compromise.

How it unfolded

  • 2023โ€“2025

    Routers quietly compromised

    Attackers exploit unpatched home and small-office routers โ€” including a TP-Link flaw (CVE-2023-50224) โ€” building a botnet of hijacked devices.

  • April 7, 2026

    DOJ & FBI disrupt the network

    A court-authorized operation dismantles the network of compromised routers linked to the GRU.

  • April 2026

    NSA & FBI issue public guidance

    Agencies urge households to reboot routers regularly, update firmware, change default credentials and replace unsupported devices.

  • Ongoing

    The advice still stands

    Disrupting a botnet doesn't patch every router. Regular reboots and basic hygiene remain the recommended everyday defense.

Why a reboot matters so much

It sounds almost too simple, but rebooting is effective for a specific technical reason: a lot of router malware lives in memory, not on permanent storage. When you power-cycle the device, that memory is wiped and the malicious code has to fall away. A restart also drops the temporary connections attackers depend on, forcing them to start over โ€” and buys you time while you apply firmware updates.

Rebooting is not a silver bullet. If your router has an unpatched vulnerability, it can be re-infected. That's why the NSA pairs "reboot regularly" with "update firmware" and "replace unsupported devices." Done together, these steps make your network a far harder target.

The full checklist the NSA recommends

  • Reboot regularly โ€” weekly at a minimum, to clear memory-resident malware.
  • Update firmware โ€” install security updates as soon as they're released.
  • Change default usernames and passwords โ€” never leave the factory login in place.
  • Disable remote management from the internet unless you truly need it.
  • Replace end-of-support routers that no longer receive security updates.

We break each of these down, step by step, in our router protection checklist.

The realistic problem: remembering to do it

"Reboot weekly" is great advice that most people follow for exactly one week. A Keep Connect rebooter runs the schedule for you and also restarts your connection the moment it drops โ€” turning a chore you'll forget into something that just happens in the background.

Sources & further reading

This summary is drawn from public reporting on the 2026 advisory. Read the original coverage:

External links open on third-party sites and are provided for reference. Keep Connect is not affiliated with these publications or with any government agency.

Turn the advice into action

Let Keep Connect handle the reboots

Schedule the weekly reboot the NSA recommends and get back online automatically whenever your connection drops.

Independent resource. This website is an educational resource and online store operated by Keep Connect / Johnson Creative. It is not affiliated with, endorsed by, or associated with the National Security Agency (NSA), the FBI, or any U.S. government agency. Agency guidance is summarized here for public awareness. Details reflect public reporting as of April 2026 and may evolve.