← Threat BriefingsThreat Briefing

The routers inside millions of networks are now a national-security risk

Why the FCC moved to bar foreign-made consumer and business routers — and what it means for the hardware you already own

In March 2026, the U.S. Federal Communications Commission added foreign-manufactured consumer and small-business routers to its Covered List — the federal government's register of equipment that poses unacceptable risks to national security. The determination found that these devices introduce a supply-chain vulnerability that could disrupt the U.S. economy, critical infrastructure, and national defense. It was formal recognition of what the security community had warned about for years: the device that connects you to the internet can be the thing that betrays you.

Why routers, specifically

Routers sit at the network edge, reachable from the internet and trusted by everything behind them. A single compromised unit can jeopardize an entire network — and the market that supplies them is concentrated in ways that turn an ordinary purchasing decision into a national-security exposure. One foreign manufacturer grew from roughly ten percent to more than sixty percent of the U.S. retail router market in a few years, a position that former NSA cybersecurity chief Rob Joyce told Congress appeared to have been achieved by selling below cost. Under PRC law, companies can be compelled to assist the state's intelligence services. The concern is not the engineering quality of any single unit; it is structural — when a majority of the hardware routing American traffic is built by companies answerable to a foreign government, the risk is systemic.

The threat is documented

This is not theoretical. The campaigns tracked as Volt Typhoon, Flax Typhoon, and Salt Typhoon — documented by CISA, the FBI, and the NSA — used exactly this class of hardware. Attackers pre-positioned inside U.S. critical infrastructure, assembled botnets from hundreds of thousands of compromised routers and cameras, and penetrated major telecom carriers. Our companion briefing, China's cyber explosives are in place, covers those campaigns in detail.

This was the opening move, not the endgame

When the router action landed, we said plainly that routers were the opening move, not the endgame — the vulnerability was never confined to the box that routes your traffic, and the Covered List would have to widen over time. It has. In July 2026, the FCC extended the same logic to networked smart machines and connected power inverters — hardware that now acts on the physical world, not just your data. The list is doing exactly what we described: expanding category by category as the policy world catches up to a documented threat. That is the tide turning in the right direction. (See the new briefing: the FCC flags robots and inverters.)

What it means for you

Read the fine print. The FCC action addresses new equipment authorizations only. It does nothing about the hundreds of millions of routers and connected devices already deployed and already trusted the moment they were switched on — and the FCC, acting alone, cannot reach them. Nothing you own today is removed, recalled, or made safe by this action.

That matters most where the stakes are highest and the resources thinnest. The greatest exposure is not in the living room; it is in the clinic, on the factory floor, at the grid substation — operational-technology and IoT devices that cannot be easily patched or replaced, connected to the internet through routers the federal government has now formally classified as a national-security threat. Those organizations rarely have a security team, and until now have had no affordable option that addresses the hardware layer.

What you can do now

You cannot rip out and replace your way out of this — and you do not have to. Faction's Cyber-Assured Pods and Portals sit behind your existing infrastructure and place your critical devices inside an owner-controlled network that is invisible and unreachable from the public internet, with every packet encrypted under keys only you hold. A compromised router or device can no longer reach, observe, or exfiltrate the traffic that matters. No rip-and-replace, no specialist IT team — or Factionize your existing infrastructure end to end.

Own your trust. Keep your peace of mind.

The new threat environment calls for a new Zero Trust model. We'd welcome the chance to show you how Faction puts you in control and secures your critical systems and assets rapidly with low cost and IT overhead.