skip to content
NSCA — Network Security Cloud AnalyticsNSCAintelligence at every scale
All posts
Network··9 min read

How hacked cameras took down the internet — DDoS attacks explained

In 2016, a botnet of hijacked security cameras and home routers knocked Twitter, Netflix, and Reddit offline across two continents. The weapon was built by a few college-age men. Here is how a DDoS attack actually works.

On October 21, 2016, large parts of the internet went dark for people across the United States and Europe. Twitter, Netflix, Reddit, Spotify, PayPal, Airbnb — all unreachable, on and off, all day. There was no break-in and no stolen data. The attackers simply aimed a firehose of junk traffic at a company most people had never heard of, called Dyn, and the famous websites that quietly depended on it toppled like dominoes. The firehose came from roughly 150,000 hijacked devices: home routers, video recorders, and internet-connected security cameras. The program running them, called Mirai, had been written by a handful of young men — in part to get an edge in the world of Minecraft.

What a DDoS attack actually is

DDoS stands for Distributed Denial of Service. Take it one word at a time.

Denial of Service means making something unavailable — knocking a website or app offline so real users cannot reach it. The simplest way to do that is to overwhelm it: send so many requests that the system buckles under the load and stops responding to anyone.

Distributed is the part that makes it hard to stop. The flood does not come from one place you can simply block. It comes from thousands or millions of sources at once, from all over the world. Picture a shop. A burglar picks the lock — that is a normal hack. A DDoS is different: it is a crowd of ten thousand fake customers jamming the doorway so no real customer can get in. Nothing is stolen. The shop just cannot do business. For a company that lives online, that downtime is its own kind of theft — lost sales, lost trust, and sometimes a ransom demand to make it stop.

What a botnet is

An attacker cannot generate that much traffic alone. They need an army, and that army is a botnet.

A botnet is a collection of devices that have been quietly infected with malware and can be controlled remotely by one operator — usually without the owners ever knowing. Each infected device is a "bot." On command, all of them point their traffic at the same target at the same moment.

The unsettling detail: a device in a botnet often works completely normally. Your security camera still shows the front porch. Your router still serves Netflix. Meanwhile, at three in the morning, that same hardware is helping flood a bank on the other side of the world, and you have no idea.

Why hacked cameras? The internet-of-things problem

Mirai's genius was not sophistication. It was laziness — ours, not the attackers'.

The program roamed the internet looking for cheap connected gadgets — cameras, video recorders, routers — that were still using the username and password they shipped with from the factory. Things like "admin" and "admin," or "root" and "12345." When it found one, it simply logged in. No clever exploit, no software flaw. Just passwords that nobody ever changed.

There are billions of these inexpensive internet-connected devices in homes and offices. Most are rarely updated. Many are never reconfigured after the box is opened. That makes them a nearly inexhaustible supply of recruits — an army hiding in plain sight, in living rooms and store ceilings everywhere.

The Dyn attack: hitting the phone book of the internet

The clever part of October 2016 was the target. The attackers did not flood Twitter and Netflix directly. They flooded a company called Dyn, which provided DNS for them.

DNS is the internet's phone book. When you type netflix.com, your device does not actually know where that is — it asks a DNS service to translate the name into the numeric address computers use to connect. Dyn ran that lookup service for a huge number of major websites.

Knock out the phone book and you do not have to attack each business individually. Everyone trying to look up a number is suddenly stranded, even though the businesses themselves are fine. That is why one attack on one company most people had never heard of made dozens of household-name sites unreachable at once. At its peak the flood reached around 1.2 terabits per second — among the largest attacks ever seen at the time.

The part that should worry you: amateurs built it

This was not a nation-state weapon. Mirai was created by a few young men, later identified as Paras Jha, Josiah White, and Dalton Norman. According to investigators, their motivations were ordinary internet-era ones: making money by renting out attacks, and gaining an advantage in the cut-throat business of hosting Minecraft servers, where knocking a rival offline was a competitive strategy.

Then they did the thing that turned a crime into an epidemic: they published Mirai's source code online. Once the blueprint was public, anyone could build their own version. Copycat botnets multiplied immediately and are still active today. The original trio pleaded guilty in 2017 — but the tool they let loose never went away. It just kept spreading.

Why this still matters in 2026

Everything that made 2016 possible is bigger now. There are far more connected devices, and many are just as poorly secured as those first cameras. DDoS-for-hire services — marketed with friendly names like "stressers" — let almost anyone rent a flood for the price of a meal. The attacks themselves keep breaking size records.

Any organization that depends on being online can be a target. Sometimes it is extortion: pay up or we keep you down. Sometimes it is a distraction, flooding the front door while a quieter break-in happens elsewhere. Sometimes it is just spite or rivalry. The point is that availability — simply staying reachable — is now something every business has to defend, not just a problem for tech giants.

What actually defends against it

At home: change the default password on every connected device the day you set it up, keep their software updated, and if your router allows it, put cameras and smart gadgets on a separate guest network so a compromise of one cannot spread. You will not feel the difference — but you will have stopped donating your devices to the next botnet.

For businesses: use a DDoS-mitigation or content-delivery service that can absorb and filter a flood before it reaches you — these networks are built to soak up traffic far larger than any single company could. Use more than one DNS provider, the lesson Dyn's customers learned the hard way. Build in spare capacity and rate limits, and have a written plan for the day you are being flooded, including who to call. One honest caveat: you cannot make a DDoS impossible. The realistic goal is to be able to absorb one and stay standing.

The lesson

The 2016 attack is remembered as a story about hacked cameras, but its real lesson is about dependencies. The internet's weakest points turned out to be the cheapest, most forgotten devices — and a shared service that dozens of major companies quietly relied on without thinking about it.

Security is not only about protecting your data from being stolen. It is also about protecting your ability to keep working, and about knowing what you depend on that you cannot see. The camera in the corner and the DNS provider you never chose are both part of your security now. The first step is simply realizing they exist.