Netherlands (NL) Threat Intelligence

NL

Netherlands has 95,587 malicious IP addresses with 4,015,156 abuse reports. Top threat categories include suspicious activity, severe abuse, ssh bruteforce, moderate threat, high threat. Top attacking networks: DigitalOcean, LLC (34,838 IPs), DIGITALOCEAN-ASN (15,837 IPs), 1337 Services GmbH (3,586 IPs). Data collected since 2022-12-05, last activity 2026-04-05.

Threat Assessment: Netherlands shows substantial cyber threat activity, ranking among the top threat source countries worldwide. The dominant attack types are suspicious activity, severe abuse, ssh bruteforce. The majority of threats originate from networks operated by DigitalOcean, LLC and DIGITALOCEAN-ASN.

Total Reports
4,015,156
Unique IPs
95,587
First Seen
2022-12-05
Last Activity
2026-04-05

Top Threat Categories

Suspicious Activity 55,837
Severe Abuse 41,578
Ssh Bruteforce 25,499
Moderate Threat 4,856
High Threat 3,686

Top Attacking Networks

AS14061 DigitalOcean, LLC
34,838 IPs
AS14061 DIGITALOCEAN-ASN
15,837 IPs
AS210558 1337 Services GmbH
3,586 IPs

Most Reported IPs in Netherlands

45.148.10.240 2,125 reports
178.16.54.200 1,456 reports
45.148.10.121 1,030 reports
45.148.10.157 745 reports
45.148.10.151 711 reports

Access this data via API

Get Netherlands threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/NL

View full API documentation

See how we classify and verify threats →

Check any IP from Netherlands

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS14061 Intelligence AS14061 Intelligence AS210558 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...