The internet feels slow, and a suspicion surfaces: perhaps a neighbour is piggybacking. The hunch is often right, but often wrong too. There is a way to confirm it before you go to the trouble of changing the password on every device.

What is mistaken for a sign, but is not

Several symptoms commonly blamed on a Wi-Fi piggybacker have more ordinary explanations:

  • Slow at certain hours. Between 7 and 11 pm, the ISP's network in a dense area genuinely is more crowded. That happens at the provider, not in your house.
  • Full signal but slow. Signal strength and speed are two different things. The explanation is in the guide to slow Wi-Fi.
  • The router lights blinking constantly. The activity light blinks for every data packet, including those your own devices send while syncing email or updating apps in the background.

What is more worth suspecting is a sudden change with no obvious cause: fine last month, now stuttering at the same hour, with no new devices or habits in the house.

Checking the device list

The most direct route is opening the router's admin page. Type 192.168.1.1 or 192.168.0.1 into a browser, sign in, then look for a menu called "Attached Devices", "Client List", "DHCP Clients", or "Device Manager".

The list usually holds three columns: device name, local IP address, and MAC address. The device name is often unhelpful, many appear as android-8f2a1c or nothing at all.

A more reliable way to match them up

Instead of guessing from names, do this:

  1. Note every Wi-Fi device in the house: phones, laptops, TVs, consoles, cameras, printers, smart watches, smart plugs.
  2. Switch Wi-Fi off on each of them, one at a time.
  3. Reload the router's list after a few minutes.
  4. Whatever remains is what needs looking into.

Do not be alarmed by the number. A house with four residents easily has fifteen to twenty connected devices. TVs, set-top boxes, speakers, and assorted smart devices are often forgotten in the count.

Reading a MAC address

A MAC address takes the form of six pairs of characters, such as A4:83:E7:1F:0C:22. The first three pairs identify the manufacturer. You can look them up on an OUI search site to learn who made the device.

The method has limits. Modern phones use a randomised MAC address per network for privacy, so the result may point to an unrelated manufacturer. Treat it as an additional clue, not evidence.

Checking without opening the router

If the admin page is locked by the ISP, there are two other routes.

The router manufacturer's app. TP-Link Tether, Asus Router, Deco, and similar show a client list complete with data usage per device. That last part is actually more useful: an unfamiliar device that only connects occasionally may be missed, but one consuming tens of gigabytes stands out immediately.

A network scanner. Apps such as Fing scan every IP address on the local network and report what answers. The result resembles the router's list, with the advantage of running from a phone.

If there really is something unfamiliar

The order goes like this:

1. Change the Wi-Fi password

Use at least 14 characters. A combination of three or four unrelated words is easier to remember and harder to guess than a single word with digits after it. Every device will disconnect and need reconnecting.

2. Change the router admin password

If that person got into the admin page, changing the Wi-Fi password alone is not enough. They could get back in and see the new one.

3. Check the settings that may have been changed

The three most worth looking at:

SettingWhat to look for
DNS serverAn unfamiliar address, not your ISP's or the provider you chose
Port forwardingRules you did not create
Remote managementEnabled even though you do not use it

If in doubt, reset the router to factory settings and configure it again from scratch. That removes every change at once.

4. Separate the smart devices

Switch on the guest network and move the cameras, lights, and smart plugs there. Devices like these are the most common way in, because their firmware is rarely updated.

Making sure it does not recur

A Wi-Fi password almost always leaks from the inside rather than from guessing. A guest who was given the password passes it on, or it is written on a board and readable from outside.

Two habits close most of that gap:

  • Give guests the guest network, not the main one. Its password can be changed at any time without disturbing household devices.
  • Do not write the password anywhere visible. If it needs sharing often, make a QR code for the guest network and keep it on your phone.

For a more thorough review of router settings, see the nine router settings that get overlooked.

A note about the risk

Someone piggybacking on Wi-Fi generally just wants free internet. They cannot automatically read the contents of your communications, because almost every site now uses HTTPS.

The more real risk sits in two places. First, devices on the local network left open without a password, such as a NAS, a printer, or a camera on default settings. Second, legal responsibility: the connection is registered in your name, and whatever is done through it is recorded as such.

Those two reasons are enough to close it off, without imagining anything more dramatic.

Frequently asked questions

Can the "Wi-Fi thief detector" apps on the app store be trusted?

Some work by scanning the local network, and the results resemble the list on the router's admin page. The problem is that many such apps request excessive permissions and show aggressive ads. The router's admin page provides the same data without installing anything.

If there is an unfamiliar device, has my data been stolen?

Not necessarily. Using the connection and reading your data are two different things. Traffic to HTTPS sites remains encrypted even for someone on the same network. What is more worth worrying about is access to local devices such as a NAS or a camera with no password.

Is changing the Wi-Fi password enough?

For most cases, yes, provided the new password is long and not shared again. If you suspect the router's admin page was accessed, change the admin password too and check whether any DNS or port forwarding settings have changed.