I changed the default password, and all is well now....but I am still confused how they were
using it to connect to websites with it.
On the S3's it has a beagle bone black as a controller board. If you ssh into it then you have access to a lot of commands that would not be there via gui. Most likely someone was ssh'ed into it I would guess from reading. But since they did not change pool's I have a feeling they did not know what they had access to.
But default passwords especially on routers are a bad idea in general. Glad it stopped now.