Someone's refrigerator just took part in a malicious cyberattack
Between December 23 and January 6, more than 100,000 internet-connected smart “things,” including media players, smart televisions and at least one refrigerator, were part of a network of computers used to send 750,000 spam emails.
Context & Ripple Effects
Days before this story broke, Ars Technica flagged connected appliances as a security disaster waiting to happen — the warning was framed around what could go wrong with fridges, TVs and washing machines on open networks. This report supplies the first concrete instance: between December 23 and January 6, more than 100,000 smart things including media players, smart televisions and at least one refrigerator were conscripted into a botnet that fired off 750,000 spam emails.
The pickup was broad for a single research finding — ReadWrite, Gizmodo and security-focused accounts like @thecyberwire all ran it the same day — which says less about new events than about how ready the tech press was for proof that the 'smart home' threat was no longer hypothetical.
First-order effects
- Owners of those 100,000-plus devices had their broadband connections and device identities used to send bulk spam without their knowledge, putting their IPs at risk of blacklisting.
- The vendors of the compromised smart TVs, media players and the refrigerator now face questions about why consumer appliances shipped without any mechanism for patching or isolating them.
Second-order effects
- Email providers and anti-spam vendors have to treat residential and appliance-grade IP ranges with more suspicion, raising filtering costs for legitimate mail sent from home networks.
- Appliance and TV manufacturers competing on connectivity now have an incentive to differentiate on updateability and default hardening, or risk the 'insecure fridge' label attaching to their category rather than their competitor's product.
Third-order effects
- If cheap connected hardware keeps shipping with no patch path, consumer devices become a standing pool of attack infrastructure that their owners neither control nor monitor — pushing the industry toward security baselines or regulation for anything sold with a network stack.
The trend: Consumer IoT is crossing from novelty products to unmanaged infrastructure on the public internet, with each compromised appliance class adding pressure for mandatory update mechanisms and network hygiene standards.