India (IN) Threat Intelligence

IN

India has 315,797 malicious IP addresses with 5,484,044 abuse reports. Top threat categories include suspicious activity, severe abuse, ssh bruteforce, moderate threat, high threat. Top attacking networks: Bharti Airtel Ltd., Telemedia Services (54,483 IPs), Reliance Jio Infocomm Limited (47,615 IPs), National Internet Backbone (22,476 IPs). Data collected since 2022-09-05, last activity 2026-07-13.

Threat Assessment: India is one of the most significant sources of cyber threats globally, with an exceptionally high volume of malicious IP addresses. The dominant attack types are suspicious activity, severe abuse, ssh bruteforce. The majority of threats originate from networks operated by Bharti Airtel Ltd., Telemedia Services and Reliance Jio Infocomm Limited.

Total Reports
5,484,044
Unique IPs
315,797
First Seen
2022-09-05
Last Activity
2026-07-13

Top Threat Categories

Suspicious Activity 130,099
Severe Abuse 34,016
Ssh Bruteforce 8,742
Moderate Threat 8,222
High Threat 4,889

Top Attacking Networks

AS24560 Bharti Airtel Ltd., Telemedia Services
54,483 IPs
AS55836 Reliance Jio Infocomm Limited
47,615 IPs
AS9829 National Internet Backbone
22,476 IPs

Most Reported IPs in India

185.100.212.141 462 reports
103.158.40.65 460 reports
183.82.111.224 459 reports
125.20.210.182 458 reports
103.84.236.222 458 reports

Access this data via API

Get India threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/IN

View full API documentation

See how we classify and verify threats →

Check any IP from India

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS24560 Intelligence AS55836 Intelligence AS9829 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...