Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • IoT Bots Cause Massive Internet Outage October 21st, 2016 current page
Link copied

IoT Bots Cause Massive Internet Outage October 21st, 2016

Oct 24, 2016
Author:
Morey Haber Headshot 2024
Morey J. Haber
Chief Security Advisor
Blog banner default
IoT Bots Cause Massive Internet Outage October 21st, 2016
Morey Haber Headshot 2024
Morey J. Haber
Chief Security Advisor
IoT Bots


The real perpetrator of the widespread Internet outage on Friday, October 21, 2016 is still not known but the weapon of choice was definitely IoT devices compromised with Mirai malware. The Distributed Denial of Service (DDoS) attack that started on the East coast of the United States targeted DNS provider Dyn, and appears to have comprised 10% of IoT assets participating in the botnet.

Scale of Attack Could Have Been Larger

The command and control structure of a botnet allows for the remote strategic and anonymous command and control of compromised assets (bots) to conduct an attack. According Dale Drew, the CISO of Level 3 Communications, the Mirai botnet has about 550,000 active nodes. Considering that it was estimated that 55,000 nodes (10%) where used in the attack and caused this much distribution, what would 50%, or 90% participation look like in terms of Internet usability? The outage could be potentially devastating and the financial losses easily escalate into the hundreds of millions of dollars since it affects so many businesses and so much of our modern daily electronic lives.

Precursor to a Larger Attack?

The events of October 21, 2016 have proven that compromised IoT devices, botnets, and a targeted DDOS attack can be effective on a large scale and can disrupt major companies that rely on the Internet. It also raises the question as to whether this attack was a precursor to a larger attack, a test similar to DDOS attacks three weeks ago in France, or if the owners of the botnet have a more devastating plan in place awaiting activation. This was just another test mission.

Everyone from the board room to government entities should take notice. This could be potentially our last real warning before a sustained attack.

The Real Problem is how We got to This Point

Sure, thieves, criminals, and malicious entities will always exist, but IoT devices are the dumbest and simplest devices to be connected to the Internet. They have basic security, can have hard coded passwords, and no methods for patching vulnerabilities or controlling privileges. Trivial hacking techniques linked with publicly available source code designed to compromise these devices has led to underground networks that control these botnets and literally sell time for usage on a “rent to use” basis for conducting malicious activity.

Stopping the Next Attack Means Improving IoT Security

While we cannot stop the criminal mind, we can stop manufacturers from making devices with poor security and require any device that accesses the Internet to have basic security capabilities. This is no different than the laws requiring automotive safety standards that appeared in the 1960’s and continue to evolve today.

Some of my peers, however, have voiced a clear opposition to this legislation. Arguments against basic security adoption via legislation range from “attacks can occur from anywhere,” to “all nations would need to adopt them,” in order to be effective. Considering how the entire planet is becoming dependent on these technologies, viability for international legislation actually sounds reasonable considering the risks to every nation. In addition, claims that a defensive posture is the most successful mitigation since these devices are already present is also a topic for debate. Filtering MAC traffic for IoT devices as an example only limits capabilities and does nothing to stop bots, traffic, and potentially other targets from being acquired and consuming resources.

The botnet’s command and control services are the key to stopping these threats and can essentially leave the army of bots headless without a commander-in-chief to instruct the next mission. We can no longer be reactionary to the problem and need to stop the poor construction, design, import, and implementation of these devices in the first place, and prevent the next botnet zombie outage apocalypse.

Start with Minimum IoT Safety Standards

As we continue to monitor the facts about last Friday’s attacks, we need to remember history. Attacks like SQL Slammer, Code Red, and even Melissa have demonstrated weaknesses in our technology and highlighted the success of social engineering. This attack is no different. We need to change things in order to prevent them from happening again. In my opinion, we need minimum safety standards for Internet devices. Otherwise, we are just going to continue to introduce devices that bring unnecessary risks to the Internet. We would never put them ‘as is’ in our business, so why would we trust them publicly?

My advice: Patch your systems, cycle your passwords and restrict privileges as much as possible.

Top IoT Security Risks and Vulnerabilities and How to Mitigate Them

Blog

Top IoT Security Risks and Vulnerabilities and How to Mitigate Them

How to Prevent DDoS Attacks: Learn Key Protections

Blog

How to Prevent DDoS Attacks: Learn Key Protections

2022 Cybersecurity Survival Guide

Resources

2022 Cybersecurity Survival Guide

Latest Posts
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
  • How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    May 21, 2026 How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    Blog
    5m
  • Cybersecurity as a Boardroom Priority for Major African TelCos
    May 12, 2026 Cybersecurity as a Boardroom Priority for Major African TelCos
    Blog
    8m
Related
  • Securing Operational Technology (OT) with Privileged Remote Access and Network Tunnels
    Sep 13, 2024 Securing Operational Technology (OT) with Privileged Remote Access and Network Tunnels
    Blog
    9m
  • Birmingham Women's & Children’s NHS Foundation Trust Maintains Secure Access at All Times with Bomgar
    Jul 26, 2018 Birmingham Women's & Children’s NHS Foundation Trust Maintains Secure Access at All Times with Bomgar
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.