3 million smart toothbrushes reportedly hacked in massive DDoS attack — how to protect yourself

A smart toothbrush next to a phone showing its app
(Image credit: Shutterstock)

Editor's Note: As we look into this story further, it may or may not have actually occurred as there's no official record of this attack taking place. However, the smart toothbrush brand as well as the company that was attacked may be keeping all of the details close to the chest as they work to patch any vulnerabilities. Regardless of whether or not millions of smart toothbrushes were actually used in a large-scale DDoS attack, this story still highlights the dangers posed by smart home devices.

It seems like every day there’s a story about PCs falling victim to malware or malicious apps infecting smartphones. However, the best smart home devices are just as vulnerable to attacks and maybe even more so.

As many smart devices don’t have the same level of protection built into computers and phones, hackers can exploit any vulnerabilities they may have and then use them to launch cyberattacks. Just this week for instance, it was discovered that 3 million smart toothbrushes were compromised and then used to launch a distributed denial of service or DDoS attack against a company in Switzerland.

According to a report from the Swiss-German newspaper Aargauer Zeitung (h/t Tom’s Hardware), the smart toothbrushes used in this attack were first infected with malware which allowed them to be integrated into a botnet that was used to carry out DDoS attacks on a number of prominent websites. 

With 3 million smart toothbrushes forming a botnet that could be controlled remotely, the hackers behind this campaign then had them all try to access the website of a Swiss company at the same time. This led the site to crash and it wasn’t able to be brought back online for several hours afterwards. During the time the site was down though, it led to millions in damages and lost business for the unnamed Swiss company. While larger organizations may be able to weather such a storm, an attack like this could ruin a small business which is why DDoS attacks carried out by botnets are so dangerous.

Besides stealing credit card information, passwords and other sensitive data, hackers often use malware to infect vulnerable PCs with the aim of adding them to a botnet. Once this is done, they can then launch large-scale attacks without having to provide their own resources to do so. In this case though, infecting these smart toothbrushes proved much easier than doing the same thing with computers or phones.

How to protect your smart devices from hackers

Smart Home products

(Image credit: Shutterstock)

Unlike with your PC where you can install the best antivirus software to stay safe from malware infections and cyberattacks, unfortunately you can’t do the same thing with your smart home devices. Instead it’s up to the vendors that make them to release new firmware to patch vulnerabilities that can be exploited by hackers.

For this reason, you want to update your smart home devices immediately when an update becomes available. Some vendors update their devices more frequently than others while some don’t send out updates at all. This is why you want to carefully research any smart device you plan on purchasing before you bring it into your home. 

At the same time, you want to stick with more well-known and established brands when shopping for smart home gear. It may be tempting to purchase an inexpensive security camera or motion sensor on Amazon but if that device comes from a company that doesn’t routinely push out firmware updates, you may end up spending more in the long run, especially if it becomes infected with malware.

Likewise, if you have one of the best Wi-Fi routers, you may want to consider setting up a guest network and keeping all of your smart home devices separate from everything else on your network. By quarantining your smart home devices, you can keep your laptop, smartphone and other devices that contain a lot of sensitive data safe from any potential threats that may be incurred by your smart home.

As for smart toothbrushes, you should ask yourself whether or not a device you use really needs smart functionality. Every device that’s connected to your home network is a potential target for hackers, so by limiting the number of smart devices you own, you're making the attack surface much smaller for hackers. 

More from Tom's Guide

Anthony Spadafora
Managing Editor Security and Home Office

Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches to password managers and the best way to cover your whole home or business with Wi-Fi. He also reviews standing desks, office chairs and other home office accessories with a penchant for building desk setups. Before joining the team, Anthony wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
A Wi-Fi router next to a phone with a lock symbol on the screen
Massive MikroTik router botnet has been spreading malware – here’s how to stay safe
and image of the Google Chrome logo on a laptop
Popular Chrome extensions hijacked by hackers in widespread cyberattack — 3.2 million at risk
A hacker typing quickly on a keyboard
Thousands of WordPress sites hijacked to spread Windows and Mac malware - how to stay safe
Green skull on smartphone screen.
Over 1 million Android devices infected with password-stealing, pre-installed botnet malware — how to stay safe
An Android bot next to an Android TV remote
Millions of Android TVs hijacked in massive botnet — how to see if yours is at risk
Eight Sleep Pod 4 Ultra with head raised in beige bedroom
Eight Sleep smart beds reportedly have a secret backdoor that can be accessed remotely — everything you need to know
Latest in Smart Home
Kidde Ring Smart Smoke Alarm
I'm a firefighter's daughter and this $55 smart smoke detector is the one I want for my own home
Ring Battery Doorbell next to door
Hate it when your Ring doorbell alerts you all the time? Here's how to schedule motion detection
Amazon Echo (4th-gen)
Amazon is removing this privacy feature from its Echo smart speakers on March 28 — what you need to know
HomePod with display concept render
Apple HomePod with display now rumored for late 2025 launch
Schneider Electric Pulse home energy panels.
The Smart Home Upgrade You’ve Been Missing
An Echo Show 10 with the Alexa Plus logo displayed on screen
Alexa+ — I have 4 big questions about Amazon's new AI assistant
Latest in News
Bill Gates in 2019
Bill Gates just predicted the death of every job thanks to AI — except for these three
NYTimes Connections
NYT Connections today hints and answers — Wednesday, March 26 (#654)
Gemini screenshot image
Google unveils Gemini 2.5 — claims AI breakthrough with enhanced reasoning and multimodal power
Samsung Galaxy Z Flip 6 review.
Samsung Galaxy Z Flip 7 design just teased in new cases leak — and the outer display is huge
Google Chrome
Chrome failed to install on Windows PCs, but Google has issued a fix — here's what happened
nyc spring day AI image
OpenAI just unveiled enhanced image generator within ChatGPT-4o — here's what you can do now