Global Threat Map

What hackers do all day.

We run a honeypot — a decoy server with no real data — on the open internet, then watch who attacks it. Every credential-stuffing bot, exploit scanner, and brute-force campaign that finds it gets logged. The result is an unfiltered picture of automated attack traffic hitting anything with a public IP. Including yours.

22,625,506 attacks observed since Jan 16, 2025

Source regions of inbound attacks. Points are coarse origin cells sized by volume — no target shown.

Attacks
22.6M
Unique sources
87K
Countries
192
Geo-located
22.6M

Top source countries

Attack count by source country

  • United StatesUS2,509,645
  • ChinaCN2,093,198
  • The NetherlandsNL1,588,648
  • RomaniaRO1,457,409
  • IndiaIN1,369,091
  • BrazilBR1,233,852
  • SingaporeSG878,260
  • FranceFR865,205
  • IndonesiaID779,970
  • LebanonLB764,537
  • GermanyDE607,863
  • TaiwanTW530,443

Most-targeted ports

Service ports under attack

  • Port 22SSH4,316,800
  • Port 23Telnet748,634
  • Port 8443HTTPS-alt16,306
  • Port 5900VNC7,893
  • Port 443HTTPS7,041
  • Port 80HTTP4,174
  • Port 64297other2,764
  • Port 587SMTP2,104
  • Port 21027other605
  • Port 5902VNC533

Attack type mix

By honeypot sensor that logged it

  • Cowrie22,298,592
  • P0f249,403
  • Suricata72,052
  • Ciscoasa2,338
  • Honeytrap1,896
  • Fatt1,014
  • Dionaea49
  • Tanner44

Source reputation

Threat-intel classification of source IPs

  • known attacker274,835
  • mass scanner893
  • bot, crawler75

Attacks over time

Daily attack volume across the observation window

Apr 17, 2026Jul 15, 2026

Methodology

Data is aggregated from a self-operated T-Pot honeypot deployment. Source locations are geolocated to whole-degree cells and stripped of any target or sensor identity before publication. Counts reflect logged connection and exploit attempts, not confirmed breaches.

This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com