Dutch authorities disrupt botnet with 17 million infected devices
Dutch authorities have disrupted a large botnet consisting of at least 17 million infected devices. The operation followed a report from a security researcher to the Dutch National Cyber Security Centre, which then worked with police to investigate the infrastructure. Authorities identified around 200 servers in the Netherlands used to control infected devices and support cyberattacks. Several servers were seized from a hosting provider, while the provider took the wider network offline because it was being used for criminal purposes.
What this means for your organisation
Botnets of this size are largely built on devices whose owners do not know they are infected, typically routers, cameras and other equipment left connected without updates or ownership. For organisations the point cuts both ways: your own equipment may be part of such a network unnoticed, and the capacity built is used against others. A takedown removes infrastructure, but not the infections on the devices.
Berigo recommends
- Build an inventory of all network-connected equipment, including devices without a clear internal owner.
- Remove or segment equipment that no longer receives security updates.
- Monitor outbound traffic for patterns suggesting communication with command servers.
- Set update and lifecycle requirements for network equipment in procurement and supplier agreements.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch