Germany (DE) Threat Intelligence

DE

Germany has 186,805 malicious IP addresses with 5,891,049 abuse reports. Top threat categories include suspicious activity, severe abuse, professional threat, moderate threat, ssh bruteforce. Top attacking networks: DigitalOcean, LLC (28,768 IPs), Deutsche Telekom AG (17,638 IPs), Hetzner Online GmbH (10,943 IPs). Data collected since 2022-10-13, last activity 2026-08-21.

Threat Assessment: Germany is one of the most significant sources of cyber threats globally, with an exceptionally high volume of malicious IP addresses. The dominant attack types are suspicious activity, severe abuse, professional threat. The majority of threats originate from networks operated by DigitalOcean, LLC and Deutsche Telekom AG.

Total Reports
5,891,049
Unique IPs
186,805
First Seen
2022-10-13
Last Activity
2026-08-21

Top Threat Categories

Suspicious Activity 126,767
Severe Abuse 51,325
Professional Threat 20,407
Moderate Threat 7,932
Ssh Bruteforce 7,663

Top Attacking Networks

AS14061 DigitalOcean, LLC
28,768 IPs
AS3320 Deutsche Telekom AG
17,638 IPs
AS24940 Hetzner Online GmbH
10,943 IPs

Most Reported IPs in Germany

139.19.117.129 833 reports
95.90.13.168 720 reports
207.154.230.149 717 reports
109.91.4.177 695 reports
178.27.90.142 690 reports

Access this data via API

Get Germany threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/DE

View full API documentation

See how we classify and verify threats →

Check any IP from Germany

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS14061 Intelligence AS3320 Intelligence AS24940 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...