Law enforcement officials in Canada arrested a 23-year-old Ottawa resident on Wednesday on charges related to the creation and management of the Kimwolf botnet. This malicious network targeted Internet-of-Things (IoT) devices, successfully enslaving millions of endpoints over the past six months. These compromised devices were reportedly utilized to facilitate a series of significant distributed denial-of-service (DDoS) attacks against various targets.
The suspect, known online by the handle Dort, was publicly identified in early 2026 following a series of aggressive cyber activities. These included DDoS attacks, doxing, and swatting campaigns directed at a cybersecurity researcher and a prominent security journalist. The coordination between international law enforcement agencies has resulted in the suspect facing criminal hacking charges in both the United States and Canada.
Investigations into the Kimwolf botnet revealed its ability to spread rapidly throughout the global IoT landscape. The infrastructure behind the botnet allowed for the mobilization of millions of hijacked devices to overwhelm network resources. The legal proceedings in both jurisdictions aim to address the scale of the disruption caused by these sustained campaigns across North America.
For CIOs and operations leaders, this development highlights the ongoing risks presented by unsecured IoT devices integrated into enterprise environments. The case underscores the capacity for botnet operators to leverage poorly secured endpoints to launch large-scale DDoS attacks that can disrupt service availability. Monitoring for unusual traffic patterns remains a critical component of maintaining organizational network resilience.
