There is a wide gap between suspecting a network has been compromised and knowing that it has. This page is for the second case.
If you're still at the suspecting stage, slow internet, an unfamiliar device name, router lights blinking when nobody is online, start with the guide to signs your Wi-Fi has been compromised, because most of those symptoms turn out to have more ordinary causes.
If you're certain, what decides the outcome isn't which steps you take but the order you take them in.
Why the order decides it
The first thing nearly everyone does is change the Wi-Fi password. On its own, that step is usually wasted.
The reason: the Wi-Fi password only governs who may join the network. It does not protect the router's admin pages. If an intruder has reached those pages, and in most real cases they have, because the administrator password is still the factory default, they can open that page, read your new Wi-Fi password, and rejoin within minutes.
So the order runs opposite to instinct: lock the settings door first, then change the network's key.
1. Disconnect first; don't start cleaning yet
Before anything else, reduce what the intruder can still reach.
- Unplug the modem if you suspect something is actively flowing out. Leave the router powered so you can reach its settings over cable.
- Connect your computer by LAN cable rather than Wi-Fi. Every following step is best done over a connection nobody else can observe.
- Switch Wi-Fi off temporarily from the settings, if the router allows it.
What you should not do yet: reset the router. There are a few things worth looking at first.
2. See what was changed before you erase it
A reset destroys the evidence along with the problem. Five minutes of looking first tells you how deep the compromise went, and that determines how far the recovery has to go.
Open the router's settings and note four things:
- DNS settings. The most commonly altered, and the most dangerous. DNS pointed at a foreign server means correct addresses deliver you to fake sites. The guide to DNS explains the mechanism, and the guide to changing DNS shows sensible values.
- Port forwarding and DMZ. Rules you didn't create mean a door was deliberately opened from outside, see the guide to port forwarding.
- Administrator accounts. Some routers allow more than one. A second account you don't recognise is the intruder's spare way back in.
- Remote management. If it's on and you never enabled it, your router's admin page has been exposed to the internet.
If any of the four has changed, the compromise reached the router itself, not merely someone guessing the Wi-Fi password. Go straight to the reset.
3. Factory reset if the settings were touched
If something changed, correcting it item by item isn't a safe option. What you found may not be all there is, and some routers keep changes in places the settings pages never show.
A full reset, using the physical button, not merely a restart, returns everything to its initial state. The method is in the guide to factory resetting a router.
Afterwards, do not restore from a saved settings backup. That file was most likely created after the compromise, and restoring it reinstates exactly what you just removed. Rebuild from scratch with the guide to setting up a new router.
4. Update the firmware before reconnecting anything
A reset restores settings but doesn't close the hole that may have allowed entry. If the way in was a vulnerability in old firmware, a freshly reset router can be compromised the same way again.
Update the firmware first, over cable, before Wi-Fi goes back on. The steps are in the guide to router maintenance.
If the router no longer receives updates from its manufacturer, this is the moment to replace it, see the guide to when a router should be replaced. An unsupported router isn't merely dated; it's open to holes that are publicly known.
5. Change credentials in this order
Now, and only now, the passwords change, in an order that must not be reversed:
- The router's administrator password. First, always. Without it, everything that follows can simply be read back by the intruder.
- The Wi-Fi password, along with its encryption. Use WPA3 where available, or WPA2, see the guide to WPA2 versus WPA3. What makes a strong one is in the guide to strong Wi-Fi passwords.
- The guest network password, if you have one, set differently from the main network.
- Accounts you used from that network: email, banking, social media. This comes after the network is clean, not before; changing important passwords over a still-compromised network simply hands over the new ones.
Switch WPS off if it's enabled. It makes joining easy, and it makes it easy for everyone, the full checklist is in the guide to securing a home router.
6. Check the devices, not just the network
A clean network doesn't mean clean devices. If the way in was one of your devices, cleaning the router alone guarantees the problem returns.
Worth closer attention:
- Cameras and smart devices. The most frequent entry point, since most ship with default passwords and are rarely updated, see the guide to CCTV camera security and the guide to smart home device security.
- The computer you use to open the router's settings. If something there reads what you type, even the new password is already known.
- Devices no longer in use but still connected. The guide to seeing who is using your Wi-Fi shows how to find them.
Afterwards, move smart devices onto the guest network, see the guide to separating guest networks. If one is compromised again later, it will no longer be sharing a room with your computer and your files.
7. Watch for a few days before calling it done
For about a week, check the connected device list once a day. What you're looking for isn't a malfunction but an unfamiliar name reappearing.
If one does, a way in remains open, and the most likely candidate is a device inside the house rather than the router.
If personal data was involved
For a home network, this is usually far enough. For a business network holding customer data there are additional obligations that can't be skipped, including reporting deadlines. The details are in the guide to reporting a personal data breach and the guide to personal data protection law.
The steps matter less than their order. Changing the Wi-Fi password first, the most instinctive move, is exactly what most often renders the whole recovery pointless.
The correct order: disconnect, see what changed, reset if the settings were touched, update the firmware, then change passwords starting with the administrator. After that the devices, not just the network, because that is nearly always where the way in was.
Frequently asked questions
Is changing the Wi-Fi password enough?
No, and this is the most common mistake. The Wi-Fi password only governs who may join. If an intruder has reached the router's admin pages, they can read your new password and rejoin. The router's administrator password has to change first.
Do I need to factory reset the router?
If there's any sign the settings were altered, unfamiliar DNS, port forwarding you didn't create, an extra admin account, a full reset is the surest route. Hidden changes are far harder to find one by one than to start clean.
How do I know the intruder is actually gone?
Once credentials are changed and the router restarted, every device must reconnect. The list of connected devices afterwards should contain only yours. If something you don't recognise reappears, a way in remains open.
Has my data definitely been stolen?
Not necessarily. Most traffic today is encrypted, so its contents stay unreadable even on a compromised network. The more realistic concerns are DNS redirection to fake sites, and other poorly protected devices on the network.