Desk live·
ForensicPost
Nation-state/Infrastructure/File 26-0110

Billions of Consumer Routers and Cameras Receive No Updates After a Few Years

Consumer routers, cameras and recorders number in the billions, receive no updates after a few years, and are owned by people with no ability to secure them. Every botnet in this database is built from them.

Constructed geometry · not a chart of case data
TargetConsumer connected devices
ActorMultiple
S. Rosler11 min readConfidence: medium2 sources reviewed

The device population behind the botnets filed at 26-0302, 26-0325 and 26-0528 is the same one in every case: consumer routers, IP cameras and digital video recorders, connected continuously, running firmware that stopped receiving updates years ago.

Three Properties, Each Individually Reasonable

These devices are cheap, because consumers buy on price. They are long-lived, because a router that works is not replaced. And they are unmanaged, because the owner is not a systems administrator and was never told they had become one.

Each property is a rational outcome of how the market works. Together they produce a permanent, growing population of internet-connected computers that nobody patches, nobody monitors and nobody is responsible for.

Enterprise Security Has No Equivalent Problem

It is worth noticing how strange this is. In a corporate environment, a device with no owner, no update path and no monitoring would be a finding. At national scale it is the default condition for the majority of connected hardware.

The mismatch matters because the consequences are not confined to consumers. The record DDoS filed at 26-0302 targeted telecommunications companies. The proxy traffic in 26-0320 lands on enterprise login pages. The estate is consumer-owned and the harm is systemic.

The Interventions That Would Work Are Not Security Products

Mandated minimum support periods with disclosure at point of sale. Automatic updates that continue past commercial end-of-life. Provider-level detection and notification when customer equipment is compromised. Liability that attaches to shipping a device that will be abandoned.

All four are regulatory and commercial choices. None of them can be bought by a security team, which is why this problem has persisted through every takedown this desk has filed.

How we reported this

This is an analysis file built on published research, listed below, read against the botnet files previously published by this desk. The policy conclusions are ours and labelled as such. Corrections: corrections@forensicpost.com.

Sources
  1. IoT attack statistics 2026: botnets and OT risksStingrai
  2. IoT botnets in 2026: 3 million devices seized, millions more waitingFlowtriq
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary