NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

BeenHacked's avatar
BeenHacked
Follower
Mar 09, 2021

Router Hacked

Several months ago my new router died so I installed my old WGR614. Google Chrome notified me that a couple passwords were hacked. I looked in Chrome security settings and my router was compromised. I had forgotten to change the default PW from admin.  Google said the hacker has had access to my network for 25 days. I tried to log into my router but the hacker had changed the PW so I did a hard reset and changed the PW.

 

Unfotunately I have a lot of sensitive documents on my Mac and Windows computers that are not password protected. I found in the router logs several suspicious access entries -

[LAN access from remote] from 146.88.240.4:42220 to 192.168.1.2:5353

[LAN access from remote] from 184.105.247.207:46211 to 192.168.1.2:5353

[Internet connected] IP address: 98.27.141.75

[LAN access from remote] from 146.88.240.4:42220 to 192.168.1.2:5353

 

My computers have login passwords but I don't know if my hard drives were accessed and what files were accessed/downloaded or if this info is in logs. I have changed my important passwords. I ran antivirus checks on all computers but found nothing.  I turned off DHCP in my router. I froze all of my accounts. Is there a way to know who took what and is there anything else I can do?

2 Replies


  • BeenHacked wrote:

    Google Chrome notified me that a couple passwords were hacked.

     

    I'd want to know more about that before assuming that the router was the cause of the problem and is compromised.

     

    Chrome also manages passwords and may have checked that you weren't using a site that has been known to have been hacked.

     

    What was the exact message that Chrome threw up? It doesn't have access to your router. And, unless you have enabled it, a hacker can't access the router from outside your network.

     

     

     

     

  • I don't think there's an easy way to trace what this hacker has accessed on your PCs and router. The most you can do is factory reset a few times and change password to a strong one. Also disable Remote Access/Management on the router