NSA advises regular Wi-Fi router reboots to counter cyberattacks
Translated from Serbian and summarized by DistantNews. Read the original for the full story.
At a glance
- The US National Security Agency (NSA) recommends regularly restarting Wi-Fi routers to disrupt cyberattacks.
- This action can temporarily disconnect hackers from compromised devices by clearing malicious software from the router's memory.
- The advice follows the dismantling of a global network of compromised routers used by Russia's APT28 group.
The U.S. National Security Agency (NSA) is urging internet users to adopt a simple yet effective cybersecurity practice: regularly rebooting their Wi-Fi routers. This seemingly minor action can serve as a crucial defense against certain types of cyberattacks, temporarily severing a hacker's connection to a device.
This recommendation stems from recent actions by U.S. authorities who successfully dismantled a vast global network of compromised home and office routers. This network was reportedly exploited by APT28, a Russian military intelligence group also known as Fancy Bear, for malicious purposes. The hackers targeted not only large corporations but also ordinary home routers, using them to steal passwords, intercept internet traffic, and launch further attacks.
The effectiveness of rebooting lies in how some malware operates. Many malicious programs function only within a device's active memory. When a router is powered off, this memory is cleared, thereby terminating any active malicious processes and cutting off the attacker's access. The NSA suggests unplugging the router for 30 seconds to one minute before plugging it back in.
However, experts caution that this is not a foolproof, permanent solution. If a router remains vulnerable, it can be compromised again. Given that a home router often acts as the gateway to an entire network, a compromised router can potentially expose other devices, personal data, smart home appliances, and even business systems accessed from home. Hackers often operate stealthily, with compromised routers continuing to function normally while secretly redirecting traffic or stealing data.
To bolster security beyond simple reboots, experts advise several other key measures. These include consistently updating router firmware, preferably with automatic security updates enabled; changing default usernames and passwords to strong, unique ones; disabling remote management if not needed; and verifying that the device's manufacturer still provides security support. Older routers that are no longer receiving security patches are particularly vulnerable and should be replaced with newer, supported models.
Originally published by N1 Serbia in Serbian. Translated, summarized, and contextualized automatically by DistantNews, with a note on how the source frames the story. Not individually reviewed before publishing. How this works.