Germany (DE) Threat Intelligence

DE

Germany has 170,199 malicious IP addresses with 4,936,502 abuse reports. Top threat categories include suspicious activity, severe abuse, professional threat, moderate threat, ssh bruteforce. Top attacking networks: DigitalOcean, LLC (25,995 IPs), Deutsche Telekom AG (15,410 IPs), Hetzner Online GmbH (9,991 IPs). Data collected since 2022-10-13, last activity 2026-07-13.

Threat Assessment: Germany is one of the most significant sources of cyber threats globally, with an exceptionally high volume of malicious IP addresses. The dominant attack types are suspicious activity, severe abuse, professional threat. The majority of threats originate from networks operated by DigitalOcean, LLC and Deutsche Telekom AG.

Total Reports
4,936,502
Unique IPs
170,199
First Seen
2022-10-13
Last Activity
2026-07-13

Top Threat Categories

Suspicious Activity 126,767
Severe Abuse 51,325
Professional Threat 20,407
Moderate Threat 7,932
Ssh Bruteforce 6,454

Top Attacking Networks

AS14061 DigitalOcean, LLC
25,995 IPs
AS3320 Deutsche Telekom AG
15,410 IPs
AS24940 Hetzner Online GmbH
9,991 IPs

Most Reported IPs in Germany

139.19.117.129 533 reports
207.154.230.149 460 reports
95.90.13.168 459 reports
94.26.106.201 457 reports
62.54.176.203 457 reports

Access this data via API

Get Germany threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/DE

View full API documentation

See how we classify and verify threats →

Check any IP from Germany

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS14061 Intelligence AS3320 Intelligence AS24940 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...