Everipedia Logo
Everipedia is now IQ.wiki - Join the IQ Brainlist and our Discord for early access to editing on the new platform and to participate in the beta testing.
October 2016 Dyn cyberattack

October 2016 Dyn cyberattack

The 2016 Dyn cyberattack was a series of distributed denial-of-service attacks (DDoS attacks) on October 21, 2016, targeting systems operated by Domain Name System (DNS) provider Dyn. The attack caused major Internet platforms and services to be unavailable to large swathes of users in Europe and North America.[2][3] The groups Anonymous and New World Hackers claimed responsibility for the attack, but scant evidence was provided.[4]

As a DNS provider, Dyn provides to end-users the service of mapping an Internet domain name—when, for instance, entered into a web browser—to its corresponding IP address. The distributed denial-of-service (DDoS) attack was accomplished through numerous DNS lookup requests from tens of millions of IP addresses.[5] The activities are believed to have been executed through a botnet consisting of many Internet-connected devices—such as printers, IP cameras, residential gateways and baby monitors—that had been infected with the Mirai malware.

Dyn cyberattack
DateOctober 21, 2016 (2016-10-21)
Time12:10 – 14:20 UTC
16:50 – 18:11 UTC
21:00 – 23:11 UTC
LocationEurope and North America, especially the Eastern United States
TypeDistributed denial-of-service
ParticipantsUnknown
SuspectsNew World Hackers, Anonymous
(self-claimed)
img

Timeline and impact

According to Dyn, a distributed denial-of-service (DDoS) attack began at 7:00 a.m. (EDT) and was resolved by 9:20 a.m. A second attack was reported at 11:52 a.m. and Internet users began reporting difficulties accessing websites.[6][7] A third attack began in the afternoon, after 4:00 p.m.[5][8] At 6:11 p.m., Dyn reported that they had resolved the issue.[9][10]

Dyn Chief Strategy Officer and spokesperson Kyle York led the communication response with customers, partners and the market.

Affected services

Services affected by the attack included:

Investigation

White House spokesperson Josh Earnest responds on October 21, 2016, the day of the attack

White House spokesperson Josh Earnest responds on October 21, 2016, the day of the attack

The US Department of Homeland Security started an investigation into the attacks, according to a White House source.[2][33][34] No group of hackers claimed responsibility during or in the immediate aftermath of the attack.[35] Dyn's chief strategist said in an interview that the assaults on the company's servers were very complex and unlike everyday DDoS attacks.[7] Barbara Simons, a member of the advisory board of the United States Election Assistance Commission, said such attacks could affect electronic voting for overseas military or civilians.[7]

Dyn disclosed that, according to business risk intelligence firm FlashPoint and Akamai Technologies, the attack was a botnet coordinated through numerous Internet of Things-enabled (IoT) devices, including cameras, residential gateways, and baby monitors, that had been infected with Mirai malware. The attribution of the attack to the Mirai botnet had been previously reported by BackConnect Inc. another security firm.[36] Dyn stated that they were receiving malicious requests from tens of millions of IP addresses.[5][37] Mirai is designed to brute-force the security on an IoT device, allowing it to be controlled remotely.

Cybersecurity investigator Brian Krebs noted that the source code for Mirai had been released onto the Internet in an open-source manner some weeks prior, which will make the investigation of the perpetrator more difficult.[38]

On 25 October 2016, US President Obama stated that the investigators still had no idea who carried out the cyberattack.[39]

On 13 December 2017, the Justice Department announced that three men (Paras Jha, 21, Josiah White, 20, and Dalton Norman, 21) had entered guilty pleas in cybercrime cases relating to the Mirai and clickfraud botnets.[40]

Perpetrators

In correspondence with the website Politico, hacktivist groups SpainSquad, Anonymous, and New World Hackers claimed responsibility for the attack in retaliation for Ecuador's rescinding Internet access to WikiLeaks founder Julian Assange, at their embassy in London, where he had been granted asylum.[4] This claim has yet to be confirmed.[4] WikiLeaks alluded to the attack on Twitter, tweeting "Mr. Assange is still alive and WikiLeaks is still publishing. We ask supporters to stop taking down the US internet. You proved your point."[41] New World Hackers has claimed responsibility in the past for similar attacks targeting sites like BBC and ESPN.com.[42]

On October 26, FlashPoint stated that the attack was most likely done by script kiddies.[43]

A November 17, 2016 Forbes article reported that the attack was likely carried out by "an angry gamer".[44]

See also

  • WannaCry ransomware attack

  • Mirai (malware)

  • Vulnerability (computing)

  • Dyn (DynDNS) DDoS Attack [46]

References

[1]
Citation Linkdowndetector.com"Level3 outage? Current problems and outages". downdetector.com. Retrieved 23 October 2016.
Sep 29, 2019, 4:02 AM
[2]
Citation Linktechcrunch.comEtherington, Darrell; Conger, Kate. "Many sites including Twitter, Shopify and Spotify suffering outage". TechCrunch. Retrieved 2016-10-21.
Sep 29, 2019, 4:02 AM
[3]
Citation Linkwww.bloomberg.com"The Possible Vendetta Behind the East Coast Web Slowdown". Bloomberg.com. Retrieved 2016-10-21.
Sep 29, 2019, 4:02 AM
[4]
Citation Linkwww.politico.comRomm, Tony; Geller, Eric (21 October 2016). "WikiLeaks supporters claim credit for massive U.S. cyberattack, but researchers skeptical". POLITICO. Retrieved 22 October 2016.
Sep 29, 2019, 4:02 AM
[5]
Citation Linkwww.wired.comNewman, Lily Hay. "What We Know About Friday's Massive East Coast Internet Outage". WIRED. Retrieved 2016-10-21.
Sep 29, 2019, 4:02 AM
[6]
Citation Linkmashable.com"Sites across the internet suffer outage after cyberattack". mashable.com. Mashable. Retrieved October 21, 2016.
Sep 29, 2019, 4:02 AM
[7]
Citation Linkportal.issn.orgPerlroth, Nicole; Mccann, Erin (2016-10-21). "No, It's Not Just You. The Internet Is (Still) Having Problems". The New York Times. ISSN 0362-4331. Retrieved 2016-10-21.
Sep 29, 2019, 4:02 AM
[8]
Citation Linkwww.cnbc.comLovelace Jr., Berkeley (21 October 2016). "After cyberassault KOs Amazon, Twitter, Spotify, third attack reported". CNBC. Retrieved 21 October 2016.
Sep 29, 2019, 4:02 AM
[9]
Citation Linkwww.dynstatus.com"Dyn, Inc. Status - Update Regarding DDoS Event Against Dyn Managed DNS on October 21, 2016". dynstatus.com. Retrieved 21 October 2016.
Sep 29, 2019, 4:02 AM
[10]
Citation Linkredstagfulfillment.com"Red Stag Fulfillment - Can Hackers Shut Down Your Ecommerce Business?". redstagfulfillment.com. Retrieved 21 October 2016.
Sep 29, 2019, 4:02 AM
[11]
Citation Linkwww.adweek.comHeine, Christopher. "A Major Cyber Attack Is Hurting Twitter, Spotify, Pinterest, Etsy and Other Sites". AdWeek. Retrieved 21 October 2016.
Sep 29, 2019, 4:02 AM
[12]
Citation Linkgizmodo.comTurton, William. "This Is Probably Why Half the Internet Shut Down Today [Update: It's Happening Again]". Gizmodo. Retrieved 2016-10-21.
Sep 29, 2019, 4:02 AM
[13]
Citation Linkfusion.netChiel, Ethan. "Here Are the Sites You Can't Access Because Someone Took the Internet Down". Fusion. Retrieved 21 October 2016.
Sep 29, 2019, 4:02 AM
[14]
Citation Linkwww.avclub.comChavez, Danette (21 October 2016). "Here's why half the internet went down today". The A.V. Club. Retrieved 21 October 2016.
Sep 29, 2019, 4:02 AM
[15]
Citation Linkwww.ibtimes.co.ukMurdock, Jason (21 October 2016). "Twitter, Spotify, Reddit among top websites knocked offline by major DDoS attack". International Business Times UK. Retrieved 21 October 2016.
Sep 29, 2019, 4:02 AM
[16]
Citation Linkwww.theatlantic.comMeyer, Robinson; LaFrance, Adrienne. "What's Going On With the Internet Today?". The Atlantic. Retrieved 2016-10-21.
Sep 29, 2019, 4:02 AM
[17]
Citation Linktwitter.com@TESOnline (21 October 2016). "We are still investigating intermittent login issues some players are experiencing across all megaservers" (Tweet) – via Twitter.
Sep 29, 2019, 4:02 AM
[18]
Citation Linkwww.bbc.com"Massive web attacks briefly knock out top sites". BBC News. 21 October 2016.
Sep 29, 2019, 4:02 AM
[19]
Citation Linkwww.theguardian.comThielman, Sam; Johnston, Chris (21 October 2016). "Major cyber attack disrupts internet service across Europe and US". The Guardian. Retrieved 21 October 2016.
Sep 29, 2019, 4:02 AM
[20]
Citation Linkwww.csmonitor.comHinckley, Story (21 October 2016). "Did the East Coast just suffer a massive cyberattack?". Christian Science Monitor. Retrieved 21 October 2016.
Sep 29, 2019, 4:02 AM