One thing to check is if they changed the SSID, this is often an indication that someone edited the router configuration.
If they didnt you can easily trace back the the ISP, check for their password configuration.
In certain cases ive found those to be extremely poor for example an 8 digit random generated string, which is viable to bruteforce.
Other cases use defaults of 10 char lower/upper/digits, basically your screwed unless you have some very very powerfull GPU setup.
One thing that you might wanna do is learn how people contruct passwords.
Ive encountered many passwords and for example routers with ; 12345678
My lucky day
Often people do something like this ; banana
Than the router says; "minimum of 8", the person thinks "shit".
Adds a "12" so it becomes banana12.