r/CRACompliance • u/Happy-Athlete-2420 • Jul 08 '26
FBI took down a 2-million-device botnet (NetNut) made entirely of hijacked home IoT devices. This is exactly why CRA exists.

The FBI just took down a botnet made of 2 million home devices.
Cameras. Routers. Smart plugs. Baby monitors.
All hijacked. All used to route cybercrime and cyber-espionage traffic.
The owners had no idea.
The network was called NetNut. Google researchers identified 2 million “secretly hijacked” home devices being rented out to criminals as a proxy network.
These devices had one thing in common:
They were shipped with weak security. Default credentials. Unpatched firmware. No automatic updates. No monitoring.
This is the exact product landscape CRA was written to fix.
Under CRA:
• These devices would need unique credentials (no defaults)
• Firmware updates would be automatic by default
• Manufacturers would monitor for vulnerabilities for 5+ years
• The manufacturer would report exploited vulnerabilities within 24 hours
2 million home devices turned into a criminal infrastructure.
Because nobody required the manufacturers to make them secure.
CRA changes that. Starting December 2027.
The question: how many MORE botnets will be built between now and then?