What are botnets and how are they used in cyberattacks

What are botnets and how are they used in cyber attacks?


A botnet is a network of infected devices, secretly controlled by attackers to launch large-scale cyberattacks. If you have an internet-connected business, there’s a real chance your devices have already been targeted.

  1. 🖥️ A botnet can include thousands or millions of devices – computers, phones, surveillance cameras, routers – all infected without the owners’ knowledge.
  2. DDoS attacks launched by botnets can cost a company approximately $22,000 per minute of downtime – a real financial risk, not a theoretical one.
  3. 🎯 Botnets don’t just attack tech giants – over half of cyberattacks target small and medium-sized companies, which have more limited resources to defend themselves.
  4. 🔒 A device is often infected through a simple email or fake update – without any visible interaction from the user.
  5. 📋 Cyber ​​insurance covers direct financial losses caused by a botnet attack – including recovery costs, business interruption, and customer liability.

🤖 What is a botnet?

🔗 Simple, jargon-free definition

The word “botnet” comes from combining the terms “robot” and “network.” Specifically, a botnet is a collection of internet-connected devices – computers, laptops, phones, routers, IP cameras – that have been infected with malicious software and are remotely controlled by an attacker.

The owners of these devices are usually unaware that they are part of such a network. The device operates normally, but in the background it executes commands received from the attacker. The first documented botnet appeared in 2001, and since then, networks of this type have grown exponentially in size and sophistication (Wikipedia, 2024).

🧠 How an infected device ends up in a botnet

Infection occurs, most commonly, through one of these three mechanisms:

  • Phishing email with a malicious attachment or link – the user opens the file and the malware is automatically installed.
  • Fake software or driver updates – web pages that imitate legitimate sites and offer “updates” that contain malicious code.
  • Uncovered vulnerabilities in operating systems or applications – the attacker exploits a security breach without any interaction from the user.

Once infected, the device receives instructions through a command and control (C&C) channel. The attacker can enable or disable devices on the network at any time, depending on the objective of the attack.

📡 Who controls a botnet and why

The person who controls a botnet is called a “bot herder.” This can be an organized crime group, a state actor, or an individual who has purchased access to the botnet on the black market. “DDoS-for-hire” services – attacks on demand – can cost as little as $38 per hour, creating a massive imbalance: the attacker spends little, the victim loses hugely.

💥 How botnets are used in cyberattacks

🌊 DDoS attacks – paralyzing a business in minutes

The most common type of attack launched through botnets is the DDoS (Distributed Denial of Service) attack. Thousands or millions of infected devices simultaneously send requests to a company’s servers, overloading the infrastructure to the point of complete blockage.

The result: the website becomes inaccessible, transactions stop, customers cannot access services. In 2025, the number of DDoS attacks globally increased by 236% compared to 2023, reaching 47.1 million recorded attacks.

📧 Spam and phishing on an industrial scale

Botnets are also used to send millions of spam or phishing emails simultaneously, using the IP addresses of infected devices. This way, the attacker remains anonymous, and the security filters of the targeted companies are harder to activate – the traffic appears to come from legitimate sources.

Phishing campaigns launched through botnets often target company employees, with the aim of obtaining access credentials to internal systems or sensitive financial data.

🔐 Data theft and unauthorized access

An infected device can transmit everything typed on it to the attacker – passwords, card details, confidential information. Botnets are, in essence, a distributed espionage network. The impact of ransomware launched through botnets was mainly financial (38% of cases), followed by exposure of sensitive data (35%) and operational disruption (20%), according to the ENISA Threat Landscape Finance Sector report (ENISA, 2024).

Type of attack Mechanism Main impact
DDoS Overloading servers with fake traffic Inactivity, direct financial losses
Spam / Phishing Massive sending of malicious emails Credential theft, unauthorized access
Data theft Keylogging, traffic interception Customer data exposure, fines GDPR
Ransomware Encryption of company data Blocking of activity, payment of ransom
Cryptomining Using victim’s hardware resources Performance degradation, energy costs

🏢 Why companies are priority targets

📊 Numbers that matter to an entrepreneur

There is a common perception that botnets and cyberattacks only target large corporations. The reality is different. Over half of global cyberattacks are directed against small and medium-sized companies, which have smaller security budgets and less up-to-date systems.

Recovering from a cyberattack can involve significant costs for a company, from restoring systems and recovering data to business interruption and expenses associated with investigations and security measures. In the case of ransomware attacks, many organizations choose to pay the ransom in the hope of regaining access to their data, although this decision offers no guarantee that files will be fully restored or that the attackers will not demand further payments.

⚠️ Signs that a device in your company may be infected

  • Unexplained slow performance of computers or servers.
  • Unusually high network traffic, especially at night.
  • Emails sent from company accounts without employees’ knowledge.
  • Applications that crash or behave strangely for no apparent reason.
  • Higher than usual internet or energy bills.

🌍 Real experiences from the community

The owner of a small online store described on Reddit how, in a single day, his servers received almost 400,000 fake visits generated by a botnet, completely blocking access to real customers. “I had no idea what was going on. I thought it was a hosting issue. By the time I realized it was a DDoS attack, I had lost a whole day of sales,” the user reported. (r/cybersecurity, 2025 )

On the same forum, an IT security specialist stressed that the most convincing argument for a skeptical business owner remains the financial one: “60% of small businesses affected by a major cyberattack close within six months. Show them that and ask them if they want to be in that statistic.” (u/Odd_Presentation_578, r/cybersecurity, 2023 )

The cyberattack on retail chain M&S in 2025 showed that even large companies are not immune. Customers reported being unable to make payments, personal data was compromised, and the brand’s reputation suffered in the long term. “It can take weeks to understand the scale of a cyberattack,” commented one user on Mumsnet. (Mumsnet, 2025 )

🛡️ How to protect yourself as an entrepreneur or manager

🔧 Basic technical measures

Protecting against botnets does not require a dedicated IT department. A few basic measures significantly reduce the risk of infection:

  • Regular updates of operating systems and applications — most infections exploit known vulnerabilities, for which patches are already available.
  • Antivirus/EDR solution on all company devices, including those of employees working from home.
  • Email filtering to block malicious attachments and links before they reach employees.
  • Network segmentation — if one device is infected, the attacker should not automatically have access to the entire infrastructure.

📋 Why technical measures are not enough

Even companies with solid security systems can be affected. Attackers are constantly evolving, and a single employee opening the wrong email can compromise the entire network. The European financial sector reported that 58% of major cyber incidents resulted in operational disruption, despite investments in security (ENISA, 2024).
This is where cyber insurance comes into play – not as a substitute for technical measures, but as a financial safety net when they are not sufficient. A well-configured policy covers recovery costs, business interruption, notification of affected customers and legal liability.

💼 What does IT insurance cover for companies in the field

For companies that provide IT or software services, the risk is twofold: they can be victims of an attack, but they can also be held liable if an attack launched from their infrastructure affects customers. A IT professional liability insurance covers precisely these scenarios – errors, omissions and cyber incidents that can harm your clients’ business.

Botnets are not an abstract threat reserved for large corporations. They are an operational reality for any company connected to the internet, regardless of size or field. Technical measures reduce the risk, but do not eliminate it completely.

If you want to know specifically what financial coverage you have in the event of a cyber attack, the best next step is a consultation with a cyber insurance specialist.

Sources and references

  • Wikipedia. Botnet. 2024. https://ro.wikipedia.org/wiki/Botnet
  • ENISA. Threat Landscape: Finance Sector, January 2023 – June 2024. European Union Agency for Cybersecurity, 2024. https://www.enisa.europa.eu/sites/default/files/2025-02/Finance%20TL%202024_Final.pdf
  • Rahmonbek, A. Revealing the realities of cybercrime in small and medium enterprises. Computers & Security, 2024. https://www.sciencedirect.com/science/article/pii/S0167404824001275
  • FS-ISAC & Akamai. From Nuisance to Strategic Threat: DDoS Attacks Against the Financial Sector. 2025. https://www.fsisac.com/newsroom/ddos-attackers-increase-targeting-of-global-financial-sector-according-to-fsisac-and-akamai-report

Community Experiences

  • Anonymous user, r/cybersecurity, 2025 – Online store owner who suffered a DDoS attack with 400,000 fake visits in 24 hours, with complete loss of business for a day. https://www.reddit.com/r/cybersecurity/comments/1ibz708/ddos_attack_on_my_very_small_business/
  • u/Odd_Presentation_578, r/cybersecurity, 2023 – IT specialist who argues that 60% of small businesses affected by a major cyber attack close within six months and recommends cyber insurance as a complementary solution. https://www.reddit.com/r/cybersecurity/comments/16fmbzk/how_to_convince_the_owner_of_a_small_business/
  • Anonymous user, Mumsnet, 2025 – Comment on the M&S cyber attack and the impact on customers and brand reputation. https://www.mumsnet.com/talk/_chat/5322574-ms-cyber-incident
The information in this article is for informational and educational purposes only. It is not a substitute for professional cybersecurity or insurance advice.