Mirai-based botnet tried to hijack Deutsche Telekom, UK's TalkTalk and Post Office customer routers, disrupting internet access for over 1M customers
The Mirai worm also hit the broadband, internet and TV networks of 900,000 Deutsche Telekom customers — Around 100,000 Post Office …
Context & Ripple Effects
Two months after a Hackforums user publicly released Mirai's source code, the worm has moved from DDoS weapon to mass router hijacker: a Mirai-based strain attempted to take over customer routers at Deutsche Telekom, TalkTalk and Post Office, knocking roughly 900,000 Deutsche Telekom and around 100,000 Post Office customers offline.
The shift matters because it targets the ISP-controlled home gateway rather than third-party IoT devices — and the corpus shows the codebase kept mutating afterward, from a DDoS campaign against WannaCry's hardcoded kill-switch domain to a 2019 Palo Alto Networks-reported variant targeting signage TVs and presentation systems.
First-order effects
- Over 1 million Deutsche Telekom, Post Office and TalkTalk broadband customers lose internet access until their infected routers are rebooted, patched or replaced by the ISPs.
Second-order effects
- European telcos absorb the support and hardware-replacement costs of insecure consumer routers, strengthening their argument that they carry risks and costs others profit from — the same grievance behind Deutsche Telekom, BT and Telefónica later asking the EU to make Big Tech pay for network use.
Third-order effects
- With Mirai's source public, every variant lowers the bar further: botnet capability becomes a commodity that keeps resurfacing years later across device classes, pushing regulators toward mandatory security baselines for consumer routers and IoT gear sold through ISPs.
The trend: Open-sourced malware is turning consumer routers and IoT devices into a persistent, self-updating attack platform that ISPs are left to defend and pay for.