RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The incident desk · 100 retrospective records ↗

The incident desk / Incident

Incident / From the archive · September 2016 event · prepared 16 September 2026

Default passwords on IoT devices built a record-setting botnet

A CISA alert and an academic measurement study traced Mirai's spread to just 62 factory-default username and password combinations.

Visual for this record: Default passwords on IoT devices built a record-setting botnet
Visual published by api.moneyoval.com, shown for identification of the record. Credit: api.moneyoval.com · source page ↗ Rights: owner-review-pending.

What happened

In September 2016, a botnet built from compromised routers, security cameras and digital video recorders began launching some of the largest distributed denial-of-service attacks recorded to that point, including floods directed at a security researcher's website and a French hosting provider. A US government alert issued on 14 October 2016 described the malware, later known as Mirai, as continuously scanning the internet for vulnerable internet-of-things devices and attempting to log in using a list of just 62 common factory-default username and password combinations, with more than 380,000 devices reportedly compromised across the campaigns the alert describes. An independent seven-month measurement study presented at the USENIX Security Symposium tracked the botnet to a peak of roughly 600,000 infections and found it spread almost entirely through embedded and IoT devices rather than conventional computers.

Confidence and limits

The government alert is a defensive advisory built from observed attack traffic and reported credential lists, and it is specific about the scanning method and device types affected. The USENIX study is an independent academic measurement based on the researchers' own network telemetry over a seven-month tracking window, giving the two documents different but overlapping vantage points on the botnet's scale. Neither document reviewed for this article addresses any individual's identity, prosecution or legal outcome.

Why it mattered

Mirai demonstrated that a botnet did not need to compromise sophisticated targets to cause internet-scale disruption; it needed only enough low-cost, rarely updated consumer and embedded devices left on factory-default credentials. The USENIX study's description of the attack as relying on novice malicious techniques against low-end devices to threaten even some of the best-defended targets captured why the case became a reference point for arguing that the security of the least-defended devices on a network can determine the resilience of the internet as a whole, not just of the device owner.

Defensive takeaway

Change every default credential on internet-connected embedded devices before they are deployed, disable remote administration features you do not use, and keep device firmware current, since these devices are rarely monitored the way servers are.

  • Do you have a complete inventory of internet-connected cameras, routers, recorders and other embedded devices on your network?
  • Have factory-default administrative credentials been changed on every one of those devices, not just the ones you remember installing?
  • Would unusual outbound scanning traffic from an embedded device be detected by your monitoring, or only traffic from servers and workstations?

The defensive lesson from both documents is narrower and more durable than any single attack they describe: a very large share of internet disruption capacity can come from devices nobody thinks of as computers, and default credentials left unchanged at the factory remain, years later, one of the most reliably exploitable weaknesses an organization can control.

Defensive takeaway

Inventory every internet-connected camera, router, recorder or other embedded device on your network, and confirm none of them are still reachable using a manufacturer default password.

A US government alert and an independent seven-month academic measurement study both confirm the botnet's scale and its reliance on default device credentials; no court or Department of Justice document was reviewed for this draft, so it makes no claim about who created or operated the botnet or about any legal outcome.

Sources & reading trail

Heightened DDoS Threat Posed by Mirai and Other Botnets ↗

US government alert describing Mirai's default-credential scanning method, affected device types, and scale of compromise in the Krebs and OVH attacks.

government-primary · Source published: 14 October 2016 · Retrieved: 16 September 2026

Understanding the Mirai Botnet ↗

Independent seven-month academic measurement study of the botnet's peak infection count and its reliance on embedded and IoT devices.

project-primary · Source published: Not established · Retrieved: 16 September 2026

Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.