Articles & Research

Briefing

The day cameras and DVRs broke the internet: Mirai, Dyn and the IoT reckoning

The October 2016 Dyn attack, powered by a botnet of ordinary home devices, exposed how little accountability existed for connected-device security.

Priya Nakamura

Cyber Policy Correspondent, American Computer Society

October 2016 · 7 min read

Analysts monitoring threat dashboards in a security operations centre
Analysts monitoring threat dashboards in a security operations centre

On 21 October 2016 a botnet built from hijacked routers, cameras and DVRs knocked major internet services offline for hours by attacking a single DNS provider. The Society examines why the incident remains a benchmark for IoT accountability.

An attack on the internet's address book

On Friday 21 October 2016, DNS provider Dyn suffered a sustained distributed denial-of-service attack that disrupted access to more than 1,200 domains, including Twitter, Netflix, Reddit, PayPal and Spotify, for users across the United States and Europe. Dyn later confirmed the attack traffic came primarily from the Mirai botnet.

Mirai worked by scanning the internet for IoT devices — home routers, IP cameras and digital video recorders — still using factory-default or hard-coded credentials, then enlisting them as attack nodes. Its source code had been published publicly in late September 2016, which allowed the botnet to be replicated and scaled rapidly by others.

The attack directed malicious traffic at port 53, used for DNS resolution, effectively drowning out legitimate lookups and making dependent services unreachable even though those services themselves were never directly attacked.

“Mirai needed no clever exploit — only millions of cameras and routers that no one had bothered to secure.”

A vulnerability with no clear owner

What made Mirai distinctive was not technical sophistication but scale enabled by neglect: millions of consumer devices had shipped with weak or unchangeable default passwords, with no update mechanism, and with no single accountable party responsible for patching them once vulnerabilities were known. Manufacturers, retailers, ISPs and consumers each held a partial responsibility that in practice none exercised.

US authorities pursued the case, and three men pleaded guilty in December 2017 to federal charges connected to creating and operating the Mirai botnet. Derivative Mirai variants continued to target IoT devices for years afterward.

Consequences for how devices get built

The Dyn incident became a reference point in the policy debate that led to laws such as California's IoT security law, effective January 2020, and the UK's product security regime, both of which banned universal default passwords on connected consumer devices. It also pushed major cloud and DNS providers to invest more heavily in redundant, geographically distributed resolution infrastructure.

What the Society advises

The Society holds that engineers designing connected devices bear a professional obligation that does not end at shipment. Mirai is a case study used in the Society's cyber security CPD modules for exactly this reason.

  • Never ship consumer or industrial devices with universal default or hard-coded credentials.
  • Build in a secure, verifiable mechanism for firmware updates before a device reaches market.
  • Treat published vulnerability disclosures as an obligation to patch, not a public relations matter.
  • Advocate for and comply with minimum security standards for connected devices in your jurisdiction.
CybersecurityPublic policy

Join the professional body behind this work

ACS members receive our research first, free CPD and ethics modules every year, and a route to professional registration assessed by their peers.

Become a member