A series of distributed denial-of-service attacks against DNS provider Dyn disrupted access to major websites across the US and parts of Europe. The attacks were largely powered by the Mirai botnet, built from compromised internet-connected devices.
What happened
- The attacks came in waves on 21 October 2016 and affected services including Twitter, Netflix, Spotify, Reddit, and Amazon.
- Mirai infected cameras, digital video recorders, and routers by logging in with factory-default usernames and passwords.
- The Mirai source code had been published online weeks earlier, allowing others to build their own botnets.
- Three young men later pleaded guilty in the US to creating Mirai, although the Dyn attack itself was not formally attributed to them.
Why it mattered
The attack showed how insecure consumer devices could be turned into a weapon against core internet infrastructure, and it spurred work on IoT security standards, including the UK’s later product security rules.
Lessons for organisations
Change default passwords, keep devices updated, and include IoT equipment in asset inventories. Organisations should also consider resilience in critical suppliers such as DNS providers, for example by using more than one.
Source: Forbes
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.