← All incidents
Incident dossier · Rank #10

Dyn Managed DNS Outage — Mirai IoT Botnet DDoS (October 21, 2016)

Dyn 2016-10-21 11h 0m core impact NetworkSoftware

On Friday 21 October 2016, Dyn's managed (authoritative) DNS platform was hit by a large-scale distributed denial-of-service attack in which a Mirai-malware IoT botnet directed a flood of DNS lookup requests at the service. The attack arrived in three windows across the day (UTC 11:10-13:20, 15:50-17:00, 20:00-22:10). Because so many major properties delegated their NS records to Dyn, the attack cascaded into user-visible outages for several dozen named services — including Twitter, Reddit, Spotify, Netflix, GitHub and PayPal — across the United States and Europe for much of the day. Dyn reported receiving malicious requests from tens of millions of IP addresses; the compromised endpoints were consumer devices such as printers, IP cameras, residential gateways and baby monitors, not spoofed traffic.

Failure cascade

Failure cascade: trigger → fault → downstream impactTriggerPrimary faultDownstream impactTrigger — Network (2016-10-21)Trigger · Network2016-10-212016-10-21Primary fault at Dyn — Dyn Managed DNS Platform (authoritative DNS service)Dyn (Oracle)Dyn Managed DNS Platform (authoritative DNS service)Dyn Managed DNS PlatformDownstream service degraded by the fault: TwitterTwitterDownstream service degraded by the fault: RedditRedditDownstream service degraded by the fault: SpotifySpotifyDownstream service degraded by the fault: NetflixNetflix+22 more downstream services

Trigger → primary fault → downstream blast radius, derived from the sourced root cause and affected-services record.

Facility & location

Operator
Dyn
Data center
Dyn Managed DNS Platform (authoritative DNS service)
Location
Manchester, USA, New Hampshire
Date
2016-10-21

Impact & scale

Users affected
Not published in primary sources — no end-user count exists; several dozen named consumer/enterprise services (~66-67 commonly cited; Wikipedia's roster length varies by revision) were disrupted across the US and Europe, implying a very large but unquantified user population.
Financial
No fetchable source gives a confirmed dollar figure. Attributed-but-unverified leads: BitSight reportedly found Dyn lost ~8% of its domains (~14,500) in the following days; some analyst pieces cite a ~$110M aggregate business-impact estimate. Neither confirmed.
Scope
Tier-1 / Sev-1 — internet-scale, cross-sector, cross-provider outage originating from a single managed-DNS provider
Services / systems down
  • Twitter
  • Reddit
  • Spotify
  • Netflix
  • GitHub
  • PayPal
  • Amazon.com
  • Airbnb
  • HBO
  • Slack
  • SoundCloud
  • PlayStation Network
  • Xbox Live
  • Visa
  • CNN
  • The New York Times
  • The Guardian
  • BBC
  • Shopify
  • Etsy
  • Pinterest
  • Tumblr
  • Quora
  • Wired
  • Swedish Government
  • Swedish Civil Contingencies Agency

Impact data & metrics

Attack source IP addresses (retry-inflated)Tens of millions of IP addresses
True malicious endpoints (bots)Up to ~100,000 (Dyn) — attributed, NOT quote-verified in this pass
Mirai-infected device census~493,000 infected devices (Level 3) — attributed, NOT quote-verified
Named disrupted servicesSeveral dozen named services (~66-67 commonly cited; roster length varies by Wikipedia revision, fetch this pass indicated 80+)
Attack waves3 UTC windows (11:10-13:20, 15:50-17:00, 20:00-22:10); some secondary sources describe 2 major + residual (unverified)
Per-wave durationsWave 1 ~2h10m; Wave 2 ~1h10m; Wave 3 ~2h10m (derived from UTC windows)
Total outage durationNo single authoritative figure; event window spans ~11h (11:10-22:10 UTC)
Compromised device classesConsumer IoT: printers, IP cameras, residential gateways, baby monitors
End-user countNot published — absent from primary sources
Confirmed economic costNone fetch-confirmed; attributed leads: ~14,500 domains lost (~8%, BitSight), ~$110M aggregate estimate

Magnitude profile

Magnitude sub-scores (0–10)Magnitude sub-scores (0–10)Users 9Users affected (0–10) — breadth of the user/customer population impacted. — scored 9/10.Financial 7Financial impact (0–10) — direct + consequential cost. — scored 7/10.Duration 7Outage duration (0–10) — how long service was degraded/down. — scored 7/10.Blast 10Blast radius (0–10) — how wide the fault propagated across systems/regions. — scored 10/10.
Magnitude 8.6 = blast 10×0.35 + users 9×0.25 + financial 7×0.20 + duration 7×0.20 (sub-scores 0–10 · weighted composite)

Blast radius is the defining dimension (10): one DNS provider's outage silenced several dozen named services (~66-67 commonly cited) across commerce, media, gaming, dev-infrastructure, payments and two Swedish government bodies, on both sides of the Atlantic. Users score is high (9) by inference from the roster (Twitter/Netflix/Spotify/PayPal scale) even though no end-user count is published. Duration (7) reflects an event spanning ~11 hours of intermittent disruption across three UTC windows rather than a single continuous outage. Financial (7) is an inferred estimate — no confirmed dollar figure exists in fetchable sources. Magnitude of the attack traffic itself was extreme: Dyn cited malicious requests from tens of millions of IP addresses (retry-inflated source count).

Sequence of events (SOE)

Phased sequence of eventsSept–Oct 2016 (pre-event) · TRIGGER — Mirai source code publicly released by 'Anna_Senpai'; per Krebs the action 'quickly spawned dozens of copycat Mirai botnets' — one of which was assembled and staged for the Dyn attack. The Dyn operation was never publicly attributed to the original authors (aggregate reporting; Krebs documents the copycat proliferation, not Dyn attribution).TRIGGERSept–Oct 2016 (p~07:10 ET (11:10 UTC), 21 Oct 2016 · TRIGGER — The assault began against Dyn's US-East-coast authoritative DNS infrastructure — 'Dyn received a global distributed denial of service (DDoS) attack on its DNS infrastructure on the east coast starting at around 7:10 a.m. ET' — a flood to port 53 ('DNS water-torture'-style query storm).TRIGGER~07:10 E~07:10–07:30 ET · DETECTION — DDoS-monitoring analogue of fire-detection: Dyn's NOC/DDoS telemetry detected anomalous port-53 traffic against East-coast DNS at attack onset (no smoke/heat detector — anomaly sensing).DETECTION~07:10–07:30 EMorning, 21 Oct 2016 · DETECTION — External attribution ('sensing the mechanism'): 'Flashpoint is now reporting that they have seen indications that a Mirai-based botnet is indeed involved in the attack on Dyn today.'DETECTIONMorning, 21 Oct Morning, 21 Oct 2016 · DETECTION — Scale quantified: Level 3's Dale Drew stated the Mirai population was 'at about 550,000 nodes' and that 'approximately 10 percent were involved in the attack on Dyn.'DETECTIONMorning, 21 Oct Morning, 21 Oct 2016 · MITIGATION — Suppression-system analogue activated: Dyn deployed traffic-shaping of inbound port-53 traffic, anycast routing-policy rebalancing, internal filtering and scrubbing services; analysis credited to Flashpoint and Akamai (disclosed-offline Dyn source).MITIGATIONMorning, 21 Oct Morning, 21 Oct 2016 · IMPACT — Collateral (evacuation analogue — no personnel at risk): downstream customers using Dyn as authoritative DNS lost resolution — Krebs names Twitter, Spotify, Reddit and SoundCloud; wider aggregate reporting adds GitHub, Netflix, PayPal, Airbnb, Amazon and HBO.IMPACTMorning, 21 Oct ~09:36 ET, 21 Oct 2016 · RECOVERY — First wave contained: 'the first wave ended at 9:36 a.m.' after initial mitigation and anycast rebalancing.RECOVERY~09:36 E~11:52 ET, 21 Oct 2016 · CASCADE — Second wave ramped up: '...before ramping up again at 11:52 a.m.' — 'This attack was distributed in a more global fashion,' according to Dyn.CASCADE~11:52 EMidday, 21 Oct 2016 · CASCADE — Regional defenses undercut: the global bot distribution defeated region-biased anycast re-steering, because shifting load off the US-East footprint did not help when sources spanned every region; the outage spread more broadly.CASCADEMidday, 21 Oct 2Midday–afternoon, 21 Oct 2016 · MITIGATION — Isolation/de-energisation analogue (no electrical de-energisation): routing/traffic isolation — anycast re-steering, scrubbing-center diversion and filtering of port-53 flood traffic — applied against the second wave (disclosed-offline Dyn source).MITIGATIONMidday–afternoonAfternoon, 21 Oct 2016 · RECOVERY — Second wave mitigated and service progressively restored across regions after sustained scrubbing and filtering (containment analogue; disclosed-offline Dyn source).RECOVERYAfternoon, 21 OcLater, 21 Oct 2016 · RECOVERY — Dyn reported a third attack wave was mitigated without customer impact (disclosed-offline Dyn source).RECOVERYLater, 21 Oct 20Evening, 21 Oct 2016 (exact end time not in surviving primary record) · RESTORED — Normal DNS resolution restored for Dyn customers after the third wave was neutralised. Precise all-clear timestamp is uncertain — the primary Hilton statement is now offline (dyn.com 301 → Oracle post-acquisition; Oracle URL returns 403).RESTOREDEvening, 21 Oct Dec 2017 → Sept 2018 · RESTORED — Law-enforcement analogue (no fire/EMS): FBI/DOJ prosecuted Mirai authors Paras Jha, Josiah White and Dalton Norman — guilty pleas Dec 2017, sentenced Sept 2018 to 'five years probation, 2,500 hours of community service, and ordered to pay $127,000 in restitution.' These prosecutions did not encompass the Dyn attack, which is widely attributed to a separate copycat operator.RESTOREDDec 2017 → Sept

Root cause

SPECIFIC "IGNITION SOURCE" (attack weapon): The outage was caused by a sustained, multi-wave volumetric-plus-application-layer DDoS from a Mirai-based Internet-of-Things botnet directed at Dyn's Managed DNS authoritative nameservers. There was NO physical ignition, fuel, or fire — the fire-forensic analogues below are explicitly mapped to the DDoS mechanism, as the crawl note requires. SPECIFIC "EQUIPMENT" (compromised hardware) AND ITS "CHEMISTRY" (failure mechanism): The weapon was assembled from "poorly secured Internet-based security cameras, digital video recorders (DVRs) and Internet routers" (Krebs). The single most-cited hardware root cause is DVRs/cameras built on XiongMai Technologies components that shipped with the hardcoded, effectively unchangeable administrative credential pair root:xc3511, devices that "share the same username-password combination root:xc3511" making telnet enrollment trivial (Threatpost). Mirai's loader continuously scanned the IPv4 Internet over Telnet and brute-forced logins — "the initial version of Mirai relied exclusively on a fixed set of 64 well-known default login/password combinations commonly used by IoT devices" (Cloudflare) — enrolling any device that accepted a default pair. The weaponised output against Dyn was a DNS flood aimed at UDP/TCP port 53 (a "DNS water-torture"-style query storm), drawing on an attack module that "implements most of the ... DDoS techniques such as HTTP flooding, UDP flooding, and all TCP flooding options" (Cloudflare). EXACT FAILURE MECHANISM AT THE TARGET: Legitimate recursive-resolver retries are indistinguishable from malicious DNS queries, so Dyn's authoritative resolvers were forced to process both. This inflated the apparent source-IP count to "tens of millions" while Dyn assessed the true malicious-endpoint population at approximately 100,000 (Dyn/Hilton statement, now offline and surviving only via secondary reproduction). Dyn cited a claimed peak of 1.2 Tbps that it said it could not verify (same disclosed-offline source). LATENT ROOT — DESIGN, REDUNDANCY, AND "MAINTENANCE" LAPSE: The latent root is a two-sided systemic hygiene failure, not a plant defect. (1) On the supply side, IoT manufacturers shipped devices with default/hardcoded credentials and an exposed Telnet service, with no forced credential change and little or no firmware patching — a device-lifecycle "maintenance" and secure-design lapse that let a static list of 64 credential pairs conscript hundreds of thousands of devices (Threatpost, Cloudflare). (2) On the target side, the amplifying architectural exposure was that many major web properties used Dyn as their SOLE authoritative DNS provider, so degradation of one managed-DNS operator cascaded into a broad Internet outage — a redundancy / single-supplier lapse. The Dyn event is widely attributed to a "copycat" Mirai botnet assembled after the original authors publicly leaked the source code, which "quickly spawned dozens of copycat Mirai botnets" (Krebs 2018); the Dyn attacker was never publicly identified and the three original authors were not charged in connection with the Dyn attack (widely reported — note that the cited Krebs 2018 piece documents the copycat proliferation but does not itself adjudicate Dyn attribution).

Contributing factors

Correction of errors (COE)

Lessons learnt

Improvements & remediation

Comprehensive analysis

Fire-forensic mapping (no physical fire)

This was a cyber incident with zero physical ignition, fuel, or combustion. Applying the fire-forensic template as required: the 'ignition source' is the Mirai DDoS weapon; the 'equipment/chemistry' is default-credentialled XiongMai DVRs/cameras (root:xc3511) enrolled via Telnet brute-force; 'detection' is DDoS telemetry and Flashpoint attribution rather than smoke/heat sensing; the 'suppression system' is Dyn's traffic-shaping, anycast rebalancing, filtering and third-party scrubbing; 'evacuation' has no human analogue (only downstream customers losing resolution); 'de-energisation' maps to routing/traffic isolation; and 'emergency response/investigation' maps to the FBI/DOJ prosecution of the Mirai authors. Every analogue is explicitly tied to the DDoS mechanism, per the crawl note.

Why the outage cascaded so widely

The blast radius was governed by DNS dependency, not by attack cleverness. Properties using Dyn as their sole authoritative DNS provider became unreachable the instant resolution failed, while multi-provider properties degraded far less. Krebs verbatim confirms Twitter, Spotify, Reddit and SoundCloud; the broader marquee list (GitHub, Netflix, PayPal, Airbnb, Amazon, HBO) is aggregate contemporaneous reporting. The single-supplier architecture — a redundancy lapse on the customer side — is the amplifier that turned an attack on one vendor into a headline 'internet outage.'

The defender's dilemma: indistinguishable traffic

Authoritative resolvers cannot tell a malicious pseudo-random-subdomain query from a legitimate one, and stub/recursive resolvers retry on timeout — so the flood induced a self-amplifying storm of genuine retry traffic. Dyn assessed ~100,000 truly malicious endpoints while apparent sources ballooned to 'tens of millions' of IPs. This is why blunt source-based filtering was hazardous: dropping 'suspicious' port-53 traffic risked dropping paying customers' real lookups. It also explains why the second, globally distributed wave defeated region-biased anycast re-steering.

Attribution, copycats, and the source-code leak

The original Mirai authors (Jha, White, Norman) pleaded guilty in Dec 2017 and were sentenced in Sept 2018 to five years probation, 2,500 hours community service and $127,000 restitution — but those prosecutions did not encompass the Dyn attack. After the authors leaked Mirai's source, the code 'quickly spawned dozens of copycat Mirai botnets' (Krebs), and the Dyn operation is widely attributed to one such untraceable copycat whose operator was never publicly identified. The leak is the durable systemic hazard: it permanently lowered the barrier to entry.

Source-integrity and disclosed gaps

The authoritative primary — Dyn's own 'Dyn Analysis Summary of Friday October 21 Attack' by Scott Hilton — is now offline (dyn.com 301-redirects to Oracle post-acquisition; the Oracle URL returns HTTP 403; web.archive.org is blocked in this environment). The 100,000-endpoint, 'tens of millions', 1.2-Tbps-'could not verify', Flashpoint/Akamai-credit, and third-wave facts therefore survive only via secondary reproduction and are flagged as a disclosed gap rather than re-verified verbatim. All other headline facts were re-fetched and confirmed against Krebs (2016 & 2018), Threatpost, and Cloudflare in this review.

Technical deep-dive

Mirai operated as a self-propagating worm plus command-and-control (C2) DDoS platform. Its loader performed stateless, high-rate TCP SYN scanning of pseudo-random IPv4 space on Telnet ports (23/2323), and on an open banner attempted authentication from a hardcoded dictionary of 64 default credential pairs (Cloudflare). Successful logins were reported to a loader/report server, which then pushed the architecture-appropriate Mirai binary; the bot wiped competing malware, hid its process, and connected to C2 to await attack commands. XiongMai-based DVRs/cameras with root:xc3511 were a canonical conscription target (Threatpost). Independent measurement placed the Mirai population near 550,000 nodes at the time of the Dyn attack (Level 3 via Threatpost), with ~24% node overlap with the earlier Bashlite/gafgyt IoT botnet (Threatpost); the USENIX Antonakakis et al. study later documented an even larger peak population, and Krebs has reported the original authors' own build reached hundreds of thousands of devices (secondary/soft-sourced, retained with that caveat). Against Dyn, the copycat operator used the attack module's DNS-flood capability. Two mechanisms compounded: (a) a raw volumetric flood of UDP/TCP packets to port 53, and (b) a "DNS water-torture" query flood in which bots requested pseudo-random subdomains of victim zones, forcing authoritative resolvers to do real work per query and defeating simple caching. Because a legitimate stub/recursive resolver that times out will retry — often several times — the flood induced a self-amplifying storm of genuine retry traffic layered on top of the attack, inflating apparent sources to "tens of millions" of IPs even though Dyn assessed ~100,000 truly malicious endpoints (Dyn/Hilton statement, disclosed offline). This is why naive source-based filtering was dangerous: dropping "suspicious" port-53 traffic risked dropping paying customers' real lookups. Dyn's mitigation ("suppression system" analogue) combined traffic-shaping of inbound port-53 traffic, manipulation of anycast routing policy to rebalance load across scrubbing-capable POPs, internal filtering, and third-party scrubbing, with attack analysis credited to Flashpoint and Akamai (Dyn/Hilton statement, disclosed offline; Flashpoint's Mirai attribution independently confirmed by Krebs). The first wave was contained and ended at 9:36 a.m. ET, but a second wave that ramped at 11:52 a.m. ET was "distributed in a more global fashion" (Dyn via Threatpost), which specifically undercut region-biased anycast re-steering: shifting load away from the US-East footprint did not help when bots were sourcing traffic from every region simultaneously. Dyn reported a third wave was mitigated without customer impact (disclosed-offline source). The blast radius was determined entirely by DNS dependency: any property using Dyn as sole authoritative DNS lost resolution, while multi-provider properties degraded far less. Krebs verbatim names Twitter, Spotify, Reddit and SoundCloud among affected customers; the wider list commonly cited (GitHub, Netflix, PayPal, Airbnb, Amazon, HBO) reflects aggregate contemporaneous reporting rather than a single primary source.

References & provenance

Sourced from public post-incident reports. Quotes are short attributed excerpts for provenance only; the analysis above is original and substantially shorter than its sources. Last verified 2026-07-31.

Root access required

The DC Incidents dossier is a root-only module. Sign in with an authorized account to continue.

Back to Home