Case file · MIRAI 2016

How the Mirai botnet knocked Twitter and Netflix offline with factory passwords

Published 2026-09-29 · 5 min read · Missing control: Mandatory default password change

The devices that knocked Twitter, Netflix and Reddit offline on October 21, 2016 were not cracked by clever code. Mostly they were cameras, video recorders and routers still using the passwords they shipped with.[4][6] This case file covers how the Mirai botnet was built and spread, how its three young authors ended up working with the FBI, and the one control that would have starved it.

What happened

In the summer and fall of 2016, three men in their early 20s, Paras Jha, Josiah White and Dalton Norman, built a piece of malware they called Mirai. It searched the internet for small connected gadgets such as security cameras, video recorders and home routers, took them over, and pooled them into a botnet, a network of hijacked machines that obey one controller. At its peak it held hundreds of thousands of devices.[1][2]

The group used the botnet to flood targets with junk traffic, an attack called distributed denial of service, or DDoS, and to earn money from advertising click fraud.[1] One of the first known victims was a well-known security journalist's website, hit with about 620 gigabits per second of traffic.[1][4]

That same fall, Jha posted Mirai's source code on a hacker forum under the name "Anna-senpai," letting anyone run their own copy.[2][3][4] Prosecutors later called the release one of the most damaging things the group did, because the copies outlived the originals.[2]

On Friday, October 21, 2016, Mirai-infected devices hit Dyn, a company that ran the internet's address lookup service for many large websites. Dyn engineers began fighting the flood around 7:10 a.m. Eastern time, and a second wave followed later in the day. Twitter, Netflix, Reddit, Spotify, Amazon and others were hard to reach for parts of the day, with major services back by late afternoon.[5][6]

How it worked

Many cheap internet-connected devices came from the factory with a built-in administrator login that was the same on every unit and easy to guess. Owners rarely changed it, and some devices made that hard to do. Mirai carried a short list of these factory logins and simply tried them on any device it could reach from the internet. When one worked, the device joined the botnet.[4][6][7]

Nothing on the hijacked device looked broken. The camera still recorded and the router still routed. The owner usually had no idea the device was also firing traffic at strangers.

The Dyn attack showed why a single weak point in the internet's plumbing matters. Dyn's servers translate a website name into the numeric address a browser needs. When Dyn was swamped, the sites themselves were fine, but browsers could not find them. Dyn later said about 100,000 malicious endpoints, mostly running Mirai, took part, and that normal computers retrying failed lookups pushed traffic to 10 to 20 times normal volume, making the attack look far bigger than it was.[5]

How it was caught

In January 2017 a security journalist publicly identified Jha and White as the likely authors.[1] In December 2017 all three pleaded guilty in federal court in Alaska to conspiracy to violate the Computer Fraud and Abuse Act for operating Mirai. Jha also pleaded guilty separately to a string of attacks on the network of Rutgers University.[1][3] The Justice Department's case covered running the botnet, not the Dyn attack, which was carried out using a copy of the leaked code.

What it cost

In September 2018 each of the three was sentenced to 5 years of probation and 2,500 hours of community service, and together they were ordered to pay $127,000 in restitution.[2][3] The unusually light sentences reflected what court papers called extraordinary cooperation: the men had been helping the FBI with other cybercrime cases, and continuing that work was part of the deal.[2][3] In the separate Rutgers case, Jha was ordered to pay $8.6 million in restitution and serve a term of home confinement.[8]

The bill for everyone else was harder to total. Hangzhou Xiongmai, a Chinese maker whose circuit boards sat inside many brands of webcam and recorder, recalled cameras using its parts and said that owners who never changed default passwords were part of the problem.[7] Mirai copies kept circulating for years afterward.[2]

The missing control

The missing control: forcing default passwords to be changed. The devices shipped with a shared factory login, and nothing required anyone to replace it before the device went online.

Mirai did not break encryption or find some rare software flaw. It walked in through doors that were never locked. If each device had come with a unique password, or refused to connect until the owner set one, the list of factory logins would have opened almost nothing, and the botnet would have been a fraction of its size. The same fix works at the other end: a business that changes every default login the day a device arrives is not part of anyone's botnet.

What to do in your business

Watch the case
The botnet that knocked Twitter and Netflix offlineDrops 2026-10-05
How webcams knocked Twitter and Netflix offlineDrops 2026-10-25
The botnet its creator gave away for freeDrops 2026-10-26
The Dyn attack wasn't really about DynDrops 2026-10-27
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More identity and access cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. TechTarget: Mirai creators and operators plead guilty to federal charges
  2. Alaska's News Source: Mirai botmasters sentenced in District of Alaska federal court
  3. Security Affairs: Mirai authors avoid jail by helping US authorities in other investigations
  4. TechCrunch: Hackers release source code for a powerful DDoS app called Mirai
  5. Help Net Security: Dyn DDoS attack post-mortem
  6. Forbes: Hacked cameras behind the Dyn attack that hit Twitter and Netflix
  7. TechCrunch: Webcams involved in the Dyn DDoS attack recalled
  8. BankInfoSecurity: Mirai co-author gets house arrest, $8.6 million fine