[SOLVED] Netgear Nighthawk R7000 hacked, reset all PCs /devices switched to ISP router. Don't know if i'm safe yet ?

Aug 27, 2021
1
0
10
Hi, sorry long post - could someone help me. On friday the 20th I think my network was hacked. I was using a Netgear Nighthawk R7000 router and Netgear DM200 modem.

I use Nord VPN and on my desktop I get this message:
We couldn't validate the TLS certificate and ensure a secure connection required for NordVPN to run, it looks like your internet traffic may be intercepted.

I disconnect and try connecting without nord to a site and firefox blocks it telling me it can't be trusted.
My mum is also trying to visit a site and she also gets the firefox message, on her PC she gets a router logon prompt.
I get an incoming WIFI call on my mobile from a number I don't recognise.

I reset the router with a paperclip and try and set it up but It tells me there is already another router/gateway on the network.

Someone I speak to earlier tells me that they think one of the devices on the network has been configured as a router and is rerouting traffic outside (?) the network so it can be examined for passwords etc and says I should reset all devices connected to the network.
So I do this and connect the new unused ISP router.

Later on a reset machine, I try the netgear router again with internet - Bitdefender total security blocks loads of suspicious connections.
I also try it with no internet, the same happens.
Resetting with a paperclip doesn't do anything.
Bitdefender also flagged my ISP router telling me that the page is relying on an untrusted certificate, so I don't know if I'm safe i'm very suspicious. I don't know if someone is still targeting me.

I reset the laptop once last time and reset the ISP router again.
I have changed all the default passwords for the wifi and admin, I have powerline and I do the same for those and the firmware is up to date.

Please help
 
Solution
Hi, sorry long post - could someone help me. On friday the 20th I think my network was hacked. I was using a Netgear Nighthawk R7000 router and Netgear DM200 modem.

I use Nord VPN and on my desktop I get this message:
We couldn't validate the TLS certificate and ensure a secure connection required for NordVPN to run, it looks like your internet traffic may be intercepted.

I disconnect and try connecting without nord to a site and firefox blocks it telling me it can't be trusted.
My mum is also trying to visit a site and she also gets the firefox message, on her PC she gets a router logon prompt.
I get an incoming WIFI call on my mobile from a number I don't recognise.

I reset the router with a paperclip and try and set it up but...
Hi, sorry long post - could someone help me. On friday the 20th I think my network was hacked. I was using a Netgear Nighthawk R7000 router and Netgear DM200 modem.

I use Nord VPN and on my desktop I get this message:
We couldn't validate the TLS certificate and ensure a secure connection required for NordVPN to run, it looks like your internet traffic may be intercepted.

I disconnect and try connecting without nord to a site and firefox blocks it telling me it can't be trusted.
My mum is also trying to visit a site and she also gets the firefox message, on her PC she gets a router logon prompt.
I get an incoming WIFI call on my mobile from a number I don't recognise.

I reset the router with a paperclip and try and set it up but It tells me there is already another router/gateway on the network.

Someone I speak to earlier tells me that they think one of the devices on the network has been configured as a router and is rerouting traffic outside (?) the network so it can be examined for passwords etc and says I should reset all devices connected to the network.
So I do this and connect the new unused ISP router.

Later on a reset machine, I try the netgear router again with internet - Bitdefender total security blocks loads of suspicious connections.
I also try it with no internet, the same happens.
Resetting with a paperclip doesn't do anything.
Bitdefender also flagged my ISP router telling me that the page is relying on an untrusted certificate, so I don't know if I'm safe i'm very suspicious. I don't know if someone is still targeting me.

I reset the laptop once last time and reset the ISP router again.
I have changed all the default passwords for the wifi and admin, I have powerline and I do the same for those and the firmware is up to date.

Please help
You need to do some root cause analysis as to HOW you got compromised (if you did).
Did you have insecure settings on the router? Default passwords? Open ports? WPS enabled on WIFI? UpNP enabled?
By default, commercial home routers are pretty secure if they are kept updated.

You also need to look at WHY you got compromised (if you did).
Are you wealthy? Do you do annoying things online? Risky online behavior, like visiting sketchy websites?
99.9% of people won't be attacked because they are uninteresting and there is no benefit to the attackers.
 
Solution