Dyn ran the address book. From a converted mill in Manchester, New Hampshire, the company answered the domain-name queries that turn a name like twitter.com into a number, on behalf of some of the largest sites on the internet. A little after seven on the morning of Friday 21 October 2016, Eastern time, those answers stopped coming. Nothing had been hacked; the sites were running, and nobody could find them. Twitter, Reddit, Spotify, GitHub, Netflix, PayPal and dozens of other services went dark across the East Coast of the United States. Dyn cleared the first wave in about two hours. A second, shortly before noon, reached users across Europe and North America; a third, in the late afternoon, was one the company said it mitigated.
The flood came from Mirai, a botnet made of things nobody called computers. The malware scanned the internet for devices that still answered to a factory username and password — a list of about sixty pairs was enough — and researchers at Flashpoint traced much of Friday's traffic to video recorders and cameras running firmware from Hangzhou Xiongmai Technology, whose password was fixed beyond an owner's reach. The same code had knocked KrebsOnSecurity offline in September with a 620-gigabit flood on the 20th, and its source was posted to a hacking forum on 30 September. Dyn spoke at first of tens of millions of attacking addresses; the analysis its product chief, Scott Hilton, published five days later put the number at up to 100,000 endpoints, the larger figure a false indicator thrown up by a storm of retries. The 1.2-terabit peak reported that weekend was never a number Dyn confirmed.
Claims arrived faster than facts. A group calling itself New World Hackers claimed the attack as a test; WikiLeaks asked supporters to stop taking down the American internet, implying a motive it never substantiated. None of it was confirmed, and the FBI and Homeland Security said only that they were investigating. On 24 October Xiongmai announced a recall — fewer than 10,000 units, all sold in the United States, against the half-million-odd devices researchers estimated ran its vulnerable firmware — said equipment shipped since 2015 had Telnet closed, and threatened to sue those it accused of defaming it. What made the month hard to answer was that nothing was broken. The cameras kept recording. Their owners noticed nothing, and could not know their devices had spent a Friday attacking New Hampshire.
The ending came within fourteen months, and did not include whoever fired at Dyn. In December 2017 three young men — Paras Jha, a Rutgers student who had posted the code under the name Anna-senpai, Josiah White and Dalton Norman — pleaded guilty in Alaska to building and running Mirai, never charged over Dyn, which other hands had attacked with their code; in September 2018 all three received probation, community service and restitution. In December 2020 the Justice Department said a participant in the Dyn attack, a minor at the time and therefore unnamed, had pleaded guilty. Dyn agreed in November 2016 to be bought by Oracle for a reported $600 million; its DNS service was wound down by 2023. The code outlived them all.
One hour on a Friday afternoon
At about half past three on 7 October, Homeland Security and the Director of National Intelligence jointly stated that the intelligence community was confident the Russian government had directed the theft of emails from American political organisations, that the DCLeaks and WikiLeaks postings fitted that effort, and that "only Russia's senior-most officials could have authorized these activities." It was the first formal attribution of the year's intrusions, and a careful one — it blamed Moscow for the email thefts, not for the scanning of state election systems. It held the news for perhaps half an hour. The Washington Post then published the Access Hollywood recording of Donald Trump, and half an hour after that WikiLeaks posted the first tranche from the Gmail account of John Podesta, Hillary Clinton's campaign chairman — the mailbox surrendered to a fake Google security alert on 19 March. Instalments followed almost daily until the election. The campaign declined to authenticate them; no forgeries were ever shown. Moscow denied all of it, as it had all year. Hindsight is specific: in July 2018 a federal grand jury named twelve GRU officers and described the phishing in detail; none has been arrested.
Fifty terabytes in a garden shed
On 5 October the Justice Department unsealed a complaint: FBI agents had arrested Harold T. Martin III, a 51-year-old Booz Allen Hamilton contractor at the NSA, at his Maryland home on 27 August, and found classified material in the house, the car and a shed. Prosecutors would describe some 50 terabytes accumulated over two decades, and called it the largest theft of government secrets in American history. The timing did the accusing: the Shadow Brokers had begun selling NSA tools in August, and Martin looked like the source. He was never charged as one; prosecutors never alleged he passed anything on, and his lawyers called him a hoarder. Only in January 2019 did it emerge that the tip came from Kaspersky Lab, whose researchers had received odd Twitter messages from an account linked to Martin just before the Brokers' first post. He pleaded guilty in March 2019 to one count of wilful retention and drew nine years that July. The Brokers marked Halloween with a post styled as a trick or treat: hundreds of addresses they claimed the NSA had used as staging servers — a claim, never a verified list.
Three million cards, five months late
It reached customers as text messages: change your PIN now — and then, from 19 October, word that the card itself was being blocked and replaced. The State Bank of India alone recalled about 600,000 cards; by the 20th the industry count stood at some 3.2 million, roughly 600,000 of them RuPay and the rest on Visa and Mastercard, the largest replacement Indian banking had seen. The trail ran back through withdrawals in China and the United States, made on cards whose owners were in India, to malware in the systems of Hitachi Payment Services, which ran YES Bank's ATM network. The fraudulent transactions had surfaced only in September, and SBI chose reissue over advice because too few customers were changing their PINs.
The verified losses were smaller than the alarm. The National Payments Corporation of India put the complaints at 641 customers and about ₹1.3 crore — its count, and a floor, since the worry was what remained unused; the alarm, NPCI said, had begun with banks reporting Indian cards used in China. Hitachi said that month that an interim assessment had found no evidence of a breach. The record keeps the sequence: compromise between 21 May and 11 July, detection in September, disclosure in October, and confirmation only in February 2017, when Hitachi's final audit accepted that malware had been injected and that the volume taken could not be established, because the malware had erased its tracks. Five months separated compromise from public. India had no rule requiring faster, and would not until the six-hour rule of 2022.
Twenty-Three Recommendations and a Promise
On 12 October the White House published Preparing for the Future of Artificial Intelligence, the first White House report on the subject, with twenty-three recommendations and, the same day, a national research plan. Industry moved faster than policy. At its 4 October event Google put the Assistant into a phone, the Pixel, and a speaker, Home, its answer to Amazon's Echo; the Assistant is now being retired in favour of Gemini. On 19 October Tesla said every car leaving its factory carried the hardware for full self-driving — eight cameras, twelve ultrasonic sensors, a radar — and that software would supply the rest, at a safety level it called substantially greater than a human driver's. The computer was superseded within three years, and in April 2026 Tesla conceded that its successor could not manage unsupervised driving either. On 18 October Microsoft claimed human parity in conversational speech recognition, a 5.9 per cent word error rate on the Switchboard test, equal to professional transcribers; IBM re-measured the transcribers in March 2017 and put them at 5.1, which Microsoft reached that August.
Two Hundred Million Installations Change Hands
On 19 October Malwarebytes bought AdwCleaner, a free adware remover written in 2011 by three seventeen-year-old French students and installed, by Malwarebytes' count, some 200 million times; two founders joined, terms were not disclosed, and it is still free ten years on. The market was consolidating: Avast, having closed its $1.3 billion tender for AVG on 30 September, ran the two as one company from 3 October, some 400 million users under Vince Steckler, a company sold to NortonLifeLock in 2022 and now Gen Digital. Trend Micro answered the next-generation vendors on 18 October with XGen, adding what it called high-fidelity machine learning to its older techniques and claiming to be first to blend them. The month's research was ESET's En Route with Sednit, three instalments on 20, 25 and 27 October dissecting the group linked to the DNC breach: at least 1,888 email addresses targeted between March and September 2015, six zero-days that year, and a downloader, Downdelph, seen only seven times. For the cameras on the cover the vendors had mostly advice: change the factory password.
⏳ Time capsule — October 2016
- Samsung halted sales of the Galaxy Note 7 worldwide on 10 October and ended production the next day, after replacement handsets issued to cure the original battery fires caught fire too; aviation regulators soon banned the phone from aircraft altogether.
- On 13 October the Swedish Academy gave the Nobel Prize in Literature to Bob Dylan, for new poetic expressions within the American song tradition; the same day Thailand announced the death of King Bhumibol Adulyadej, on the throne for seventy years.
- On 22 October the Chicago Cubs beat the Los Angeles Dodgers 5–0 at Wrigley Field to win their first National League pennant since 1945; on 2 November they won the World Series, their first in 108 years.
- Ae Dil Hai Mushkil opened on 28 October, the Diwali weekend, against Ajay Devgn's Shivaay, after weeks of threats from the Maharashtra Navnirman Sena over its Pakistani co-star Fawad Khan in the aftermath of the Uri attack; it went on to earn about ₹240 crore worldwide.
The default password
Ten years on, October 2016 is when the industry stopped treating the internet of things as a figure of speech. The fixes were slow and legal: California banned shared default passwords on connected devices from 2020, Britain followed in 2024, and the European Union wrote security duties for every connected product into law the same year. The botnets did not wait. Mirai's code, published for anyone to copy, became a lineage; its descendants, on routers and cameras with far fatter connections, set the records this archive tracks in its October and December 2025 editions, at 15.72 and then 29.7 terabits per second. Dyn's name is gone, absorbed into Oracle and retired; what it demonstrated, that a hundred thousand unattended devices can switch off the visible internet, is a permanent condition.
The other threads ended in court and in code. The hour of 7 October led to the July 2018 indictment, twelve names never served; Harold Martin drew nine years. Dirty COW, a copy-on-write race that had sat in the Linux kernel since 2007 and was found in the wreckage of a hacked server rather than in a lab, was patched by Linus Torvalds on 18 October, eleven years after his first attempt at the same bug. The Australian Red Cross Blood Service's 1.28 million donation records, covering some 550,000 donors, left on a public web server by a contractor and found by a stranger on 25 October, were disclosed on the 28th — Australia's largest known leak at the time. In India, the recall became the case study for a country with a payments revolution coming and no rule for saying when it broke, a gap closed by CERT-In in 2022 and the Data Protection Act of 2023.