Desk live·
ForensicPost
Ransomware/Enforcement/File 26-0302

Three Million Routers, and a Record Set at 31.4 Terabits

US authorities disrupted four IoT botnets built from consumer routers, recorders and cameras, behind a DDoS attack that peaked at 31.4 Tbps. The devices belonged to people who will never know.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetConsumer IoT device estate
ActorMultiple
S. Rosler12 min readConfidence: high3 sources reviewed

In March 2026 law enforcement action targeted four botnets — Aisuru, KimWolf, JackSkid and Mossad — which had collectively compromised more than three million devices, principally consumer routers, digital video recorders and IP cameras. The largest attack attributed to the infrastructure peaked at 31.4 terabits per second and 200 million requests per second against telecommunications targets.

The Victims Are Not The Targets

Three million compromised devices means three million households and small businesses whose equipment was participating in attacks. Almost none of them noticed, and almost none will be told.

A compromised router does not behave badly enough to prompt a call. It routes traffic, the internet works, and the additional load is invisible against a modern connection. The owner has no console, no logs and no reason to look.

Nobody In The Chain Has An Incentive To Fix It

The manufacturer sold the device years ago at thin margin and has moved on; support ended, and firmware updates with it. The internet provider supplied it as part of a package and does not want the support calls that a forced replacement would generate. The owner does not know there is a problem.

That is why this device population persists across every takedown. It is not a hard technical problem — it is an ownership problem with no owner, and the cost of remediation falls on parties who bear none of the consequence.

What The Record Number Actually Measures

A 31.4 Tbps peak is a statement about aggregate consumer bandwidth, not about attacker sophistication. Domestic connections got faster; the same number of compromised devices now produces a larger number every year without the operators doing anything differently.

Which means DDoS records will keep falling regardless of enforcement, for as long as the underlying device estate stays reachable.

How we reported this

Compiled from published law-enforcement reporting and research, listed below. Device counts and attack peaks are as reported by the agencies and researchers involved. Corrections: corrections@forensicpost.com.

Sources
  1. DoJ disrupts 3 million-device IoT botnets behind record 31.4 Tbps global DDoS attacksThe Hacker News
  2. IoT botnets in 2026: 3 million devices seized, millions more waitingFlowtriq
  3. Four major DDoS botnets dismantled in global law enforcement operationSafeState
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary