In recent days you may have heard about the terrifying botnet consisting of 3 million electric toothbrushes that were infected with malware. While you absent-mindedly attended to your oral hygiene, little did you know that your toothbrush and millions of others were being controlled remotely by nefarious criminals.
Alas, fiction is sometimes stranger than truth. There weren’t really 3 million Internet-connected toothbrushes accessing the website of a Swiss company in a DDoS attack that did millions of dollars of damage. The toothbrush botnet was just a hypothetical example that some journalists wrongly interpreted as having actually happened.
It apparently started with a January 30 story by the Swiss German-language daily newspaper Aargauer Zeitung. Tom’s Hardware helped spread the tale in English on Tuesday this week in an article titled, “Three million malware-infected smart toothbrushes used in Swiss DDoS attacks.”
Tom’s Hardware wrote:
According to a recent report published by the Aargauer Zeitung, around three million smart toothbrushes have been infected by hackers and enslaved into botnets. The source report says this sizable army of connected dental cleansing tools was used in a DDoS attack on a Swiss company’s website. The firm’s site collapsed under the strain of the attack, reportedly resulting in the loss of millions of Euros of business.
In this particular case, the toothbrush botnet was thought to have been vulnerable due to its Java-based OS. No particular toothbrush brand was mentioned in the source report. Normally, the toothbrushes would have used their connectivity for tracking and improving user oral hygiene habits, but after a malware infection, these toothbrushes were press-ganged into a botnet.
Does that even make sense?
Security experts poked holes in the story, saying that the botnet description appeared to be a hypothetical and didn’t really make sense anyway. Security researcher Matthew Remacle called it nonsense on Tuesday, pointing out that smart toothbrushes just pair with phones via Bluetooth instead of connecting to the Internet directly.

Loading comments...