/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers calculate that Mirai botnet DDoS attack on KrebsOnSecurity, which lasted 77 hours and used 24,000 unsecured IoT devices, cost device owners ~$324K

The attack levied against the domain using insecure IoT devices cost their owners dearly in power and bandwidth.

ZDNet Charlie Osborne

Context & Ripple Effects

The public release of Mirai's source code in late 2016 turned a single researcher's weapon into a commodity anyone could compile, and this new accounting puts a price tag on who actually pays when it fires. The same botnet family later knocked major DNS infrastructure offline in the DynDNS outage powered by DVRs and cameras with XiongMai components, and was even aimed at WannaCry's kill-switch domain to keep the ransomware alive.

What makes the $324K figure analytically important is its direction: the target, Brian Krebs' site, absorbed the headline damage, but the bill for power and bandwidth landed on 24,000 device owners who never consented to participating. It is one of the first attempts to quantify the externality that insecure IoT devices impose on their own buyers.

First-order effects

  • The direct financial burden of the 77-hour attack falls on the owners of the 24,000 conscripted devices, not on KrebsOnSecurity or the attacker — an estimated $324K in electricity and bandwidth costs shifted onto households and small businesses.

Second-order effects

  • Device makers whose products were harvested into Mirai — the XiongMai-component DVRs and cameras implicated in the DynDNS attack — face mounting reputational and potential liability exposure as each new study attaches dollar figures to their unpatched defaults.
  • ISPs and bandwidth providers absorb degraded network performance and support load from hijacked customer devices, giving them a commercial stake in filtering or quarantining botnet traffic.

Third-order effects

  • If the true cost of insecure devices keeps being measured and attributed, the economics argue for shifting responsibility upstream — toward mandatory security baselines, default-credential bans, and vendor liability rather than consumer vigilance.
  • Open-sourced malware like Mirai lowers the marginal cost of attack to near zero while victims' costs stay high, structurally favoring attackers until defense spending or regulation closes the gap.

The trend: IoT botnets are externalizing real monetary costs onto device owners and networks, building the case for holding device manufacturers financially accountable for insecure defaults.