TL;DR: The telltale sign is your DNS server settings in the router's admin panel showing addresses you didn't enter, or websites redirecting to unexpected pages even when the URL you typed was correct. Log into the router admin panel and check the DNS settings under the WAN or Internet section; if they've been changed, reset the router to factory defaults, update the firmware, set a strong unique admin password, and manually set DNS to a trusted provider like your ISP's default or a public option such as 1.1.1.1.

👉 Check my digital footprint — free 30-second check →

The telltale sign is your DNS server settings in the router's admin panel showing addresses you didn't enter, or websites redirecting to unexpected pages even when the URL you typed was correct.

What Usually Causes This

DNS hijacking usually happens when an attacker gains access to the router's admin panel — often through a default or weak password, or a known firmware vulnerability — and changes the DNS servers to ones they control, redirecting traffic through malicious infrastructure.

What to Do About It

Log into the router admin panel and check the DNS settings under the WAN or Internet section; if they've been changed, reset the router to factory defaults, update the firmware, set a strong unique admin password, and manually set DNS to a trusted provider like your ISP's default or a public option such as 1.1.1.1.

If this looks similar to something else you've seen, it's worth reading How to Remove Spyware From an Android Phone.

This pattern shows up elsewhere too — see How to Remove Spyware From an iPhone.

Frequently Asked Questions

What are the real warning signs?

The telltale sign is your DNS server settings in the router's admin panel showing addresses you didn't enter, or websites redirecting to unexpected pages even when the URL you typed was correct.

What usually causes this?

DNS hijacking usually happens when an attacker gains access to the router's admin panel — often through a default or weak password, or a known firmware vulnerability — and changes the DNS servers to ones they control, redirecting traffic through malicious infrastructure.

What should I do about it?

Log into the router admin panel and check the DNS settings under the WAN or Internet section; if they've been changed, reset the router to factory defaults, update the firmware, set a strong unique admin password, and manually set DNS to a trusted provider like your ISP's default or a public option such as 1.1.1.1.

Should I be worried if I only see one sign?

One sign alone (like a slower device) is usually not cause for alarm — most single symptoms have mundane explanations. Multiple signs together, especially unexpected data usage or unfamiliar apps, are worth investigating.

Sources

Related Reading