Dyn and the Mirai Botnet (Oct 2016): When DNS Took Down Half the Internet
Retrospective: this article looks back at events from October 2016, written in 2026 with the benefit of hindsight.
On October 21, 2016, a large share of the US internet seemed to stop working. Twitter, Netflix, Reddit, GitHub, Spotify and dozens of other services became unreachable for hours. None of those companies had been breached. Their shared DNS provider, Dyn, had been knocked offline.
What happened
Dyn was hit by waves of distributed denial-of-service traffic from the Mirai botnet. Mirai was built from compromised IoT devices: IP cameras, DVRs and home routers that still used factory-default passwords. The malware scanned the internet for those devices, logged in with a short list of default credentials and enlisted them into a botnet that could generate enormous traffic volumes.
Because DNS translates names into addresses, taking down an authoritative DNS provider takes down every site that depends on it — even if the sites themselves are perfectly healthy.
Why it mattered for cloud teams
Most organizations had treated DNS as plumbing. Dyn showed it was a single point of failure sitting outside every firewall, every load balancer and every cloud region. Companies that ran a secondary DNS provider recovered quickly; companies that relied on one provider waited.
Lessons in hindsight
- Map your external dependencies. DNS, CDN, identity provider and certificate authority are all critical infrastructure you do not run.
- Use more than one authoritative DNS provider for customer-facing domains, or at least have a tested plan to add one quickly.
- Insecure devices anywhere are a risk to everyone. Mirai's source code was published shortly before the attack, and copycat botnets followed for years.
- Availability is part of security. Business leaders feel an outage as acutely as a breach.
A decade later, managed DNS services such as Azure DNS and Amazon Route 53 run on globally distributed anycast networks, and DDoS protection is built into the major clouds. The core lesson has not changed: know which outside services can take you offline, and have a plan for each one.