The US, Canada and Germany dismantled them but the next wave is already forming, leveraging unprotected connected consumer devices and, the UK aside, regulation isn’t fast enough
Even now, we are nowhere near the most famous – and as it turned out wildly inaccurate IoT prediction from circa 2010 – that there would be 50 billion connected devices by 2020. The timeline for the 50 billion has been pushed out to 2035, according to IoT Analytics in October 2025, which expects the 2030 total to be 39 billion, with a CAGR of 13.2% between the end of 2025 and then.
IoT Analytics counts connected IoT devices as active nodes/devices or gateways that concentrate the end-sensors, not every end node (sensor/actuator). Wi-Fi is the largest sector, accounting for 32% of all IoT connections and its role is expanding, driven by three trends, according to the analyst house:
• Rise of low-power Wi-Fi for IoT devices – adoption of low-power Wi-Fi is increasing as devices use Wi-Fi 6 features such as Target Wake Time and extended sleep modes to reduce energy consumption, enabling battery-powered sensors, locks and appliances.
• Enterprise tech upgrades – upgrades to enterprise, customer-premises equipment and edge are accelerating as Wi-Fi 6E and Wi-Fi 7 (a report this week on trials to that demo’d a ‘step-change’ in Wi-Fi 7’s reliability makes interesting reading) replace older networks, improving throughput, latency, and reliability while broadband and fixed wireless access (FWA) gateway refreshes add momentum.
• Long-distance, broad application connectivity – Wi-Fi HaLow (802.11ah) is gaining traction below 1GHz, providing long-range, low-power links for industrial and outdoor IoT applications, such as video sensors, AMI 2.0, and precision agriculture. This broadens Wi-Fi’s addressable market and supports new shipment growth from 2026 onward.
Leveraging Wi-Fi to create IoT botnets
Given how fast IoT is expanding and the growing role of Wi-Fi in IoT, IoT For All‘s article published last week makes frightening reading. First the good news. US law enforcement, working with authorities in Canada and Germany, dismantled the command-and-control infrastructure behind four major botnets, as reported in Wired. Collectively they had hijacked more than 3 million devices worldwide. IoT For All described as “one of the most significant botnet takedowns on record”.
The four networks – known as Aisuru, KimWolf, JackSkid and Mossad – were responsible for hundreds of thousands of distributed denial-of-service attacks, including strikes against US Department of Defense systems.
Now for bad news – the conditions that allowed the botnets to flourish remain. By infecting consumer Wi-Fi-connected devices, hackers created a “residential proxy” network so malicious traffic appeared originate from legitimate households, making the attacks difficult to trace and allowing them to bypass security filters.
Proxy networks for malicious traffic
The article explains, “The four botnets spread almost exclusively through internet-connected consumer devices — routers, webcams, digital video recorders, smart TVs, set-top boxes — the kind of hardware that gets plugged in once and forgotten. These devices are routinely shipped with weak default credentials, rarely receive firmware updates, and are almost never monitored by their owners.
“That combination makes them ideal raw material for botnet operators, who can quietly conscript millions of them into attack infrastructure without the owners ever noticing anything is wrong. The scale that results is staggering: together the four networks were capable of generating attack traffic exceeding 30 terabits per second, with one combined Aisuru-Kimwolf attack last November peaking at roughly 31.4 Tbps — nearly three times the size of any previously recorded attack.“
The botnets were stopped by authorities’ seizing the domains and backend servers that direct traffic from the compromised devices, which remain compromised. Hence, “Hundreds of millions of poorly secured IoT devices remain online, running outdated firmware or factory-default passwords, permanently available for conscription [without their owners even knowing]. Until device manufacturers are held to higher security standards — or consumers demand them — the recruitment pool for the next Aisuru is already out there, plugged into the wall and waiting,” IoT for All adds.
Further, it seems the botnet business model was a big success: the perpetrators ran a cybercrime-as-a-service operation, renting out access to the hijacked infrastructure to other criminal actors.
Ignorance is bliss?
And if you want an illustration of the ignorance surrounding this threat, bang on cue, Fierce Network quoted Claus Hetting, CEO and Chair of Wi-Fi Now, saying, “If somebody would want to attack US infrastructure, do you think they would go house to house and try to get in the back door of these $20 routers?”
Well, yes – see above – but they didn’t have to go house-to-house, Claus. Hetting was responding to questions about the US’ telecoms regulator’s surprise announcement last week. The Federal Communications Commission’s (FCC) decreed that all consumer-grade routers produced in foreign countries will be banned from sale in the US unless the supplier applies for and receives Conditional Approval from the Department of War (DoW) or the Department of Homeland Security (DHS).
To be clear, in situ Wi-Fi routers and those that have already been approved by the FCC can continue to operate and still be sold: the mandate applies to new devices.
Caught by surprise
The FCC’s edict caught by the industry by surprise, as the definition of routers produced in foreign countries includes those assembled overseas for American brands, but also those with a supply chain involving countries like China, Taiwan and Vietnam, which in short means almost every household router. Presumably the plan is to force US router makers all to move all elements of manufacturing to the US.
Why consumer-grade routers are more of an issue than those designed for enterprises was not explained, but the FCC did say its decision was in response to the Executive Branch determining that foreign-produced routers introduce a “supply chain vulnerability that could disrupt the US economy, critical infrastructure and national defense” and pose a severe cybersecurity risk.
The Executive Branch’s thinking is not specifically aligned with the IoT threat, but this could be a golden opportunity to address it. Currently, the US relies on a voluntary Cyber Trust Mark program for IoT devices, along with industry-specific regulations, such as NIST frameworks), and sector-level mandates which tend to urge collaboration rather than impose strict regulation.
However, the EU and US agreed to develop the EU-US Joint Cyber Safe Products Action Plan in 2023 to align their approaches and prepare for potential mutual recognition of standards (see below regarding the European Union’s approach).
What about this side of the Pond?
The UK Government introduced what is described as “the world’s first legislation on the cyber security of consumer connectable products: the Product Security and Telecommunications Infrastructure (PSTI) Act 2022 and the PSTI Regulations 2023.” It came into force on 29 April 2024. Although it was designed to protect consumers, it will help to foil botnets because of various conditions it imposes, such as a ban on Default Passwords – manufacturers must not provide universal, hardcoded or easy to guess default passwords, like “admin”, “12345”.
Manufacturers must provide a public point of contact for security researchers to report vulnerabilities, allowing them to be patched before exploitation can take place. Device makers must also state the minimum time period for which security updates will be provided, which is intended to help consumers make safer purchasing decisions.
Finally, non-compliance can result in fines up to £10 million or 4% of qualifying worldwide revenue.
The UK legislation was built on the developments outlined in the box below – more information here. Japan and Singapore are following the UK’s lead and working to harmonise their approaches, as explained in Parliament in November 2025, reported by Hansard.

Action in Europe
The European Union’s (EU) Cyber Resilience Act (CRA) builds on the 2020 EU Cybersecurity Strategy and EU Security Union Strategy. It complements other relevant legislation, specifically the NIS2 Directive which covers the securing network and information systems.
The CRA is designed to protect consumers from cyber threats via smart devices. It imposes mandatory cybersecurity requirements on manufacturers of consumer devices – from baby-monitors to smart watches – covering the planning, design, development and maintenance of such products to protect users. The obligations are mandatory at every stage of the value chain.
The CRA also states manufacturers must address vulnerabilities during the lifecycle of their products. Some products of particular relevance to cybersecurity may be obliged to undergo third-party assessment by a notified body before they are sold on the EU market.
Products will bear the CE marking to indicate that they comply with the CRA requirements and national market surveillance authorities will ensure enforcement of the rules.
The CRA entered into force on 10 December 2024 BUT the main obligations will not apply until 11 December 2027, with reporting obligations to apply as of 11 September 2026. This content, produced by global lawyers Hogan Lovells, sets out what vendors need to do during 2026 to be compliant by the time the law comes into force.
The only trouble is the threat is huge and now, and with events moving as fast as they are, that December 2027 deadline seems like a very long way off.
Warning: Bluetooth and other WPAN tech
Finally, note that Wi-Fi isn’t the only surface for attacking IoT. “Bluetooth and IoT technologies have quietly become one of the most overlooked attack surfaces in modern cybersecurity,” according to an article in Medium last December. Like consumer devices that use Wi-Fi, attacks via Bluetooth and IoT devices are often missed by perimeter defences.
“Many IoT ecosystems rely on wireless protocols such as Bluetooth, Zigbee, Z-Wave, or proprietary radio-frequency implementations. These protocols often assume a trusted environment and lack robust authentication, encryption, or replay protection,” the article states, adding, “They operate for years the same firmware and credentials.”
Also, “Once compromised, IoT devices are rarely cleaned or reinstalled. They persist quietly, acting as long-term footholds inside networks. In many real-world cases, attackers use these devices to pivot laterally, exfiltrate data, or maintain persistence without touching traditional endpoints.


