Researchers calculate that Mirai botnet DDoS attack on KrebsOnSecurity, which lasted 77 hours and used 24,000 unsecured IoT devices, cost device owners ~$324K
The attack levied against the domain using insecure IoT devices cost their owners dearly in power and bandwidth.
Context & Ripple Effects
The public release of Mirai's source code in late 2016 turned a single researcher's weapon into a commodity anyone could compile, and this new accounting puts a price tag on who actually pays when it fires. The same botnet family later knocked major DNS infrastructure offline in the DynDNS outage powered by DVRs and cameras with XiongMai components, and was even aimed at WannaCry's kill-switch domain to keep the ransomware alive.
What makes the $324K figure analytically important is its direction: the target, Brian Krebs' site, absorbed the headline damage, but the bill for power and bandwidth landed on 24,000 device owners who never consented to participating. It is one of the first attempts to quantify the externality that insecure IoT devices impose on their own buyers.
First-order effects
- The direct financial burden of the 77-hour attack falls on the owners of the 24,000 conscripted devices, not on KrebsOnSecurity or the attacker — an estimated $324K in electricity and bandwidth costs shifted onto households and small businesses.
Second-order effects
- Device makers whose products were harvested into Mirai — the XiongMai-component DVRs and cameras implicated in the DynDNS attack — face mounting reputational and potential liability exposure as each new study attaches dollar figures to their unpatched defaults.
- ISPs and bandwidth providers absorb degraded network performance and support load from hijacked customer devices, giving them a commercial stake in filtering or quarantining botnet traffic.
Third-order effects
- If the true cost of insecure devices keeps being measured and attributed, the economics argue for shifting responsibility upstream — toward mandatory security baselines, default-credential bans, and vendor liability rather than consumer vigilance.
- Open-sourced malware like Mirai lowers the marginal cost of attack to near zero while victims' costs stay high, structurally favoring attackers until defense spending or regulation closes the gap.
The trend: IoT botnets are externalizing real monetary costs onto device owners and networks, building the case for holding device manufacturers financially accountable for insecure defaults.