The three million toothbrush botnet story isn’t true.

Here’s the original source of the story: https://archive.is/2024.01.30-203406/https://www.luzernerzeitung.ch/wirtschaft/kriminalitaet-die-zahnbuersten-greifen-an-das-sind-die-aktuellen-cybergefahren-und-so-koennen-sie-sich-schuetzen-ld.2569480

It’s simply a made up example. It doesn’t exist. It starts talking about NoName Ddosia, too, which also isn’t toothbrushes.

The toothbrush thing has gone viral despite it being total bollocks.

Now NoName have picked up the fake toothbrush story as propaganda for their members.

Good job, Fortigate.

Fortigate haven’t replied to my PR question about it. Given this is several times the size of the world’s biggest botnet, you’d think they’d have any evidence.. at all.

Kudos to @BleepingComputer for doing actual journalism.

Fortinet also declined to comment to me.

It's a completely made up story, which is now being circulated as Russian propaganda.
https://www.bleepingcomputer.com/news/security/the-unlikely-3-million-electric-toothbrush-ddos-attack/

The unlikely 3 million electric toothbrush DDoS attack

A widely reported story that 3 million electric toothbrushes were hacked with malware to conduct distributed denial of service (DDoS) attacks is likely a hypothetical scenario instead of an actual attack.

BleepingComputer
Fortigate have issued me a statement. The toothbrush DDoS story is completely made up.
I’d like to thank all the Mastodon reply guys in the thread who decided the story was real, btw, based on vibes.
Probably the best reply on one of the stories so far.
It’s now made it to YouTubers 🤣 who are doing better journalism and threat intel than.. journalists and threat intel. https://youtu.be/sVpe0ZEZ1Ho
Did a Massive Toothbrush DDOS Just Happen?

YouTube

The newspaper that had the first article about the Fortigate toothbrush botnet have updated the story and doubled down:

“The article originally said that the case "really happened like that."
This information came from the company Fortinet, which had described the case as real in the interview and proofread the article before publication. Fortinet is now correcting this statement and calling it a "hypothetical scenario". https://www.luzernerzeitung.ch/wirtschaft/kriminalitaet-die-zahnbuersten-greifen-an-das-sind-die-aktuellen-cybergefahren-und-so-koennen-sie-sich-schuetzen-ld.2569480

Cybergefahren: So schützen Sie sich

Die Zahl der Angriffe erreicht unvorstellbare Höhen, wie neue Daten der Cybersicherheitsfirma Fortinet zeigen. Welche Entwicklungen Sorgen bereiten und warum es trotzdem Anlass zur Zuversicht gibt.

Luzerner Zeitung
Zahnbürsten-Cyberangriff: Hintergründe zu einer ungewöhnlichen Geschichte

Ein Artikel in dieser Zeitung über elektrische Zahnbürsten, die in einen Cyberangriff verwickelt gewesen sein sollen, ist viral gegangen. In Expertenkreisen löste er Skepsis aus. Die Hintergründe.

Luzerner Zeitung

During the whole toothbrush botnet thing, people said ‘yes, the story is fake but it COULD happen’.

Almost every smart toothbrush uses Bluetooth so no, it could not.

Somebody pointed me towards one on Amazon which says it uses wi-fi, so I ordered it and investigated.

The toothbrush only has Bluetooth. The charger uses wi-fi - but has no open TCP or UDP ports. Traffic is outbound only, TLS 1.3.

So no, it was just total nonsense.

@GossiTheDog What does the charger do with WiFi?
@GossiTheDog Switch the toothbrushes to Tuya devices and then maybe we can have one million smart bulbs dos something
@GossiTheDog @SwiftOnSecurity but IT COULD HAPPEN as soon as someone makes a toothbrush with a 2lbs battery in it! It COULD!
@GossiTheDog, why are you letting facts get in the way of a good story?
atc1441 (@atc1441) on X

WIFI Toothbrush completely OTA under full control, no need of pressing buttons🥳 "Exploit" ESP32 Opens WIFI Network: evowera 12345678 (default set in Toothbrush🤪) and answers all the right requests to make the custom firmware update Demo video here🎬: https://t.co/2rPXHyO6ft

X (formerly Twitter)

@GossiTheDog

I wonder where the toothbrush gets the time and date from, to validate the TLS certificate chain.

...and how it alerts the user to an invalid server TLS 1.3 certificate.

BTW, how does TCP work with outbound traffic only? UDP maybe but TCP?

Without inbound traffic, it surely has to have an Ethernet cable connection or a WPS button.
Given that you can't tell it about the Wireless network to use.

Questions upon questions. Even without asking the obvious question of...why?

@GossiTheDog could there be a ddos botnet that incorporated something that talked to toothbrushes? Sure, but the toothbrushes themselves would just be an amusing side note to a pathetically tiny botnet.

@GossiTheDog

Supply chain toothbrush charger attack

Boom. Gottem

@GossiTheDog I have my toothbrush set to flight mode...

@GossiTheDog Still a reasonable chance it accepts any cert or is vulnerable to downgrade attacks or something.

Remember, the S in IOT stands for security.

@GossiTheDog

Now, why does a toothbrush **charger** connect to anything?

@GossiTheDog The whole (bogus) story about a toothbrush botnet made me think. What exactly could "smart" enablement add to a toothbrush that would justify the development cost and the e-waste? What's next? Smart toilet paper? As you wipe your bum, it gives you directions and congratulates you at the end for doing a good job?

But hey. I probably got to that age where I just go "back in my day...", as younger folks roll their eyes

@GossiTheDog a.k.a. Kevin explores how far he can push the training expenses on his next tax returns.
@GossiTheDog @SwiftOnSecurity Just as expected. But it sure was a clockbaity “exciting” story. For people who have no understanding about technology.
@GossiTheDog So, finally, journalists were doing their job :)

@GossiTheDog This one is nice, too:

Das globale Management von Fortinet hat nun zurückgerudert mit seinem Statement, das an verschiedene internationale Medien gesendet wurde. Dieses auch an CH Media zu schicken, hat die Firma unterlassen. Auch sonst liegt uns bisher kein weiteres Statement von Fortinet vor.

"Fortinet's global management has now backtracked with its statement that was sent to various international media outlets. The company neglected to also send this to CH Media. We have not yet received any further statements from Fortinet."

@GossiTheDog also, the security press only covers fiery car crashes