All news
cybersecurityregulation

Honeypot Data: 1.5M SSH Attacks Hit Servers in 30 Days

08 Aug 2026

A distributed honeypot network spanning six continents has quantified just how relentless automated SSH scanning has become — and the numbers offer a useful reality check for any startup running exposed infrastructure.

What happened

Over a 30-day collection window in July 2026, a network of 15 decoy servers (using 15 IPv4 addresses across 5 VPS providers) recorded 1,531,053 total SSH login attempts from 6,790 unique attacking IP addresses. The attacks originated from 129 countries and 1,334 distinct ASNs, underscoring the global, automated nature of credential-stuffing traffic aimed at internet-facing servers.

The project logged 131,922 unique credential pairs, drawn from 12,238 unique usernames and 97,621 unique passwords — evidence of large, systematic credential lists being cycled through by bots rather than targeted human attackers.

Where the traffic came from

Regional breakdowns show some notable asymmetries:

  • Asia accounted for 60.1% of unique attacking IPs (4,084 IPs), making it the top source of distinct attacker infrastructure.
  • Europe accounted for 60.2% of total login attempts (921,439), despite the honeypot network itself being 60% Europe-based — a concentration that may reflect both attacker activity and honeypot placement.
  • China produced the most unique attacking IPs of any single country (1,653), followed by the United States (721).
  • The Netherlands generated the most total login attempts of any country (686,449) — a volume far exceeding its share of unique IPs, suggesting a small number of Dutch-associated IPs are firing at very high frequency.

The report flags that this Netherlands/China concentration may reflect compromised infrastructure or proxy/VPN relays rather than the true geographic origin of attackers — a caveat worth keeping in mind when interpreting country-level attack data generally.

The credentials attackers are still trying

Despite years of security awareness campaigns, weak default credentials remain the dominant attack vector in this dataset:

  • The top credential pair was root:123456, attempted 3,861 times.
  • The username "root" alone appeared in 648,133 login attempts — roughly 42% of all attempts in the dataset.

This pattern suggests that a large share of internet-wide SSH scanning is still betting on operators leaving root login enabled with weak or default passwords.

Why founders should care

For early-stage teams running any cloud infrastructure, this data points to a few probable takeaways:

  • Any publicly exposed SSH endpoint is likely facing near-constant automated probing, regardless of a startup's size or profile — obscurity is not a meaningful defense.
  • Because root-username attempts made up a substantial share of traffic, teams that disable password-based root SSH login by default and enforce key-based authentication may meaningfully reduce their exposed attack surface.
  • The regional concentration of traffic (particularly from Asia and Europe-linked IPs) suggests there could be value in geo-based rate-limiting or anomaly-detection features for infrastructure security tooling — a signal worth watching for security-focused product teams.
  • Given the prevalence of common weak credentials in the dataset, automated credential-hygiene practices — password managers, forced key-based auth, disabling password login entirely — may plausibly eliminate a large share of this class of attack with relatively low engineering effort.

Caveats and open questions

The report is explicit that several methodological details remain unclear: how the honeypot deduplicated "unique attacking IPs" (and whether scanners or researchers were excluded), what honeypot software/configuration was used, and whether attack volumes correlate with known botnet campaigns. The project's author also describes the network as a work in progress, with planned future improvements — meaning current figures should be treated as a snapshot rather than a definitive baseline, and methodology may shift in future reporting periods.

Bottom line

The headline number — 1.5 million SSH login attempts in 30 days across 129 countries — is a concrete illustration of the baseline noise level facing any exposed server today. For founders provisioning their first production infrastructure, the practical implication is straightforward: treat default SSH configurations as a known, high-probability attack surface, and harden accordingly before scaling.

Sources