What to do if…
your router settings show remote administration was turned on and you did not enable it
Short answer
Disconnect the router from the internet, then log in locally and turn remote administration off. Change the router admin password, update the firmware, and factory reset or replace the router if the setting will not stay under your control.
Do not do these things
- Don’t leave the router exposed to the internet while you check it.
- Don’t use an email, banking, or work password for the router admin login.
- Don’t assume changing the Wi-Fi password also changes the router admin password.
- Don’t install random “router cleaner” apps or call phone numbers shown in pop-ups.
- Don’t restore an old router backup if you do not trust the settings in it.
- Don’t decide immediately that this was targeted; first contain the access.
What to do now
-
Disconnect the router from the internet.
Unplug the WAN or Internet cable, or power off the modem-router if it is one combined device. This gives you a safer pause while you check settings. -
Take quick photos or screenshots before changing anything major.
Capture the remote administration setting, firmware version, admin users, port forwarding rules, firewall rules, DNS settings, connected-device list, and recent logs if they are easy to see. -
Log in from inside your home network.
Use a wired Ethernet connection if you can. If you use Wi-Fi, make sure it is your own network and not a public or guest network. -
Turn off remote administration.
Disable settings called Remote Administration, Remote Management, Web Access from WAN, Admin from Internet, or similar. If the router offers “local network only” admin access, choose that. Disable unknown or unused cloud-management access unless your ISP clearly requires it for support. -
Change router admin access.
Set a strong, unique router admin password. Change the admin username if the router allows it. If the router supports multi-factor or 2-step verification for admin access, turn it on. Use any “sign out all sessions” option if available. -
Check the settings attackers commonly change.
- DNS: set it back to automatic or to a trusted DNS provider you chose.
- Port forwarding and firewall rules: remove rules you did not create.
- UPnP: turn it off unless you deliberately need it.
- WPS: turn it off.
- Admin accounts: remove or disable any account you do not recognize.
- Unknown devices: note them, but do not panic; some device names are vague.
-
Update firmware using only an official route.
Use the router’s built-in update page, your ISP’s official app, or the router manufacturer’s official support site. Do not use update links from pop-ups, unexpected emails, or search ads. -
Reboot, reconnect the internet, and re-check.
After the update or setting changes, reconnect the internet and confirm remote administration is still off. Check that DNS and port forwarding rules stayed as you set them. -
Factory reset if control still looks unreliable.
Factory reset and rebuild the router settings manually if remote administration turns back on, you cannot change the admin password, unknown admin accounts return, or the router is unsupported and no longer receiving updates. Do not restore an old backup unless you are sure it was made before the suspicious change. -
Contact your ISP if it is ISP equipment or you cannot secure it.
Ask whether remote administration was enabled by them, whether the router is still supported, and whether they can replace it. Use the phone number, website, or app printed on your bill or on the ISP’s official site. -
After the router is stable, change Wi-Fi access.
Set a new WPA3 or WPA2 Wi-Fi password. Reconnect devices one at a time so you can notice anything you do not recognize. -
Protect important accounts if there are signs of wider compromise.
If you saw suspicious account logins, password-reset emails you did not request, or unknown devices using the network, change your email password first, turn on 2-factor authentication, and sign out of other sessions. -
Report only if there is cybercrime, fraud, or identity harm.
You can report cyber-enabled crime to IC3. If your identity or accounts were misused, use IdentityTheft.gov for recovery steps.
What can wait
- You do not have to prove today whether this was a hack, ISP change, bug, or old misconfiguration.
- You do not need to replace every phone, laptop, or smart device before stabilising the router.
- You do not need deep forensics unless settings keep changing, money is lost, accounts are taken over, or a workplace device is involved.
- You can postpone network optimisation, guest networks, device segmentation, and new equipment choices until the immediate access issue is contained.
Important reassurance
This is unsettling, but the first risk reduction is practical: disconnect, turn off remote administration, reset admin access, check DNS and port rules, and update or reset the router. Those steps help whether the change was malicious, accidental, or caused by unsupported equipment.
Scope note
These are first steps for containment and safer decision-making. If you keep losing control of the router, see repeated tampering, or have financial, identity, workplace, or legal impacts, you may need help from your ISP, your employer’s IT team, or a qualified security professional.
Important note
This is general information, not legal, medical, financial, therapeutic, cybersecurity, or other professional advice. Router menus vary by model and ISP; if you are unsure, keep the router disconnected from the internet and use verified support channels from your ISP or manufacturer.
Additional Resources
- Federal Bureau of Investigation — Cybercriminal Proxy Services Exploiting End-of-Life Routers
- Ic3 — Welcome to the Internet Crime Complaint Center
- Consumer Advice — Securing Your Internet-Connected Devices at Home
- Consumer Advice — How To Secure Your Home Wi-Fi Network
- Consumer Advice — Protect Your Personal Information From Hackers and Scammers
- IdentityTheft.gov — Identitytheft
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.