Global Threat Map
What hackers do all day.
We run a honeypot — a decoy server with no real data — on the open internet, then watch who attacks it. Every credential-stuffing bot, exploit scanner, and brute-force campaign that finds it gets logged. The result is an unfiltered picture of automated attack traffic hitting anything with a public IP. Including yours.
22,625,506 attacks observed since Jan 16, 2025
Source regions of inbound attacks. Points are coarse origin cells sized by volume — no target shown.
- Attacks
- 22.6M
- Unique sources
- 87K
- Countries
- 192
- Geo-located
- 22.6M
Top source countries
Attack count by source country
- United StatesUS2,509,645
- ChinaCN2,093,198
- The NetherlandsNL1,588,648
- RomaniaRO1,457,409
- IndiaIN1,369,091
- BrazilBR1,233,852
- SingaporeSG878,260
- FranceFR865,205
- IndonesiaID779,970
- LebanonLB764,537
- GermanyDE607,863
- TaiwanTW530,443
Most-targeted ports
Service ports under attack
- Port 22SSH4,316,800
- Port 23Telnet748,634
- Port 8443HTTPS-alt16,306
- Port 5900VNC7,893
- Port 443HTTPS7,041
- Port 80HTTP4,174
- Port 64297other2,764
- Port 587SMTP2,104
- Port 21027other605
- Port 5902VNC533
Attack type mix
By honeypot sensor that logged it
- Cowrie22,298,592
- P0f249,403
- Suricata72,052
- Ciscoasa2,338
- Honeytrap1,896
- Fatt1,014
- Dionaea49
- Tanner44
Source reputation
Threat-intel classification of source IPs
- known attacker274,835
- mass scanner893
- bot, crawler75
Attacks over time
Daily attack volume across the observation window
Methodology
Data is aggregated from a self-operated T-Pot honeypot deployment. Source locations are geolocated to whole-degree cells and stripped of any target or sensor identity before publication. Counts reflect logged connection and exploit attempts, not confirmed breaches.
This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com