In March 2026 law enforcement action targeted four botnets — Aisuru, KimWolf, JackSkid and Mossad — which had collectively compromised more than three million devices, principally consumer routers, digital video recorders and IP cameras. The largest attack attributed to the infrastructure peaked at 31.4 terabits per second and 200 million requests per second against telecommunications targets.
The Victims Are Not The Targets
Three million compromised devices means three million households and small businesses whose equipment was participating in attacks. Almost none of them noticed, and almost none will be told.
A compromised router does not behave badly enough to prompt a call. It routes traffic, the internet works, and the additional load is invisible against a modern connection. The owner has no console, no logs and no reason to look.
Nobody In The Chain Has An Incentive To Fix It
The manufacturer sold the device years ago at thin margin and has moved on; support ended, and firmware updates with it. The internet provider supplied it as part of a package and does not want the support calls that a forced replacement would generate. The owner does not know there is a problem.
That is why this device population persists across every takedown. It is not a hard technical problem — it is an ownership problem with no owner, and the cost of remediation falls on parties who bear none of the consequence.
What The Record Number Actually Measures
A 31.4 Tbps peak is a statement about aggregate consumer bandwidth, not about attacker sophistication. Domestic connections got faster; the same number of compromised devices now produces a larger number every year without the operators doing anything differently.
Which means DDoS records will keep falling regardless of enforcement, for as long as the underlying device estate stays reachable.
Compiled from published law-enforcement reporting and research, listed below. Device counts and attack peaks are as reported by the agencies and researchers involved. Corrections: corrections@forensicpost.com.