IoT as a Cyber Attack Platform: Lessons from Real-World and Proof-of-Concept Incidents
The rapid proliferation of Internet of Things (IoT) devices has transformed everyday environments, connecting homes, enterprises, and industrial systems in unprecedented ways. While these devices offer significant convenience and functionality, their widespread deployment coupled with common weak security mechanisms, make them an attractive target for cyberattacks. In this paper, we examine IoT as a cyber attack platform, analysing both real-world incidents and proof-of-concept attacks to understand how compromised devices are leveraged to target other systems. We identify the IoT device vulnerabilities most frequently exploited, classified according to the OWASP Top 10 IoT vulnerabilities, and evaluate the resulting impact on the confidentiality, integrity, and availability (CIA) of targeted systems. Our review highlights the evolving strategies attackers use to harness IoT devices for distributed attacks, from botnets to lateral movement within networks. Based on these insights, we discuss the lessons learned and underscore the critical role of robust security mechanisms in enabling the next generation of secure IoT devices and services.