Threat landscape 2026.
IPv4 threat metrics from the OneFirewall Alliance feed: 2025 compared with 2026, plus the live picture as of 5 October 2026.
More addresses, and more of them are returning.
9.31 million IPv4 addresses were reported in 2026 so far, up 26.6% on the same period of 2025. Returning addresses grew faster than new ones (+38.7% against +22.2%), so a growing share of the feed is infrastructure that was already known.
Monthly values count addresses last reported in each month. October covers 1 to 5 October in both years.
More addresses are reaching the enforcement threshold.
Addresses with a stored score of 150 or more, the TAXII threshold, rose 68%, from 47,326 to 79,496. The median score rose from 13 to 16, while the 95th percentile eased slightly, from 93 to 88. More addresses are crossing the line; the most extreme scores have not grown.
| Metric | 2025 | 2026 | Change |
|---|---|---|---|
| Addresses with stored score at or above 150 | 47,326 | 79,496 | +68.0% |
| Median stored score | 13 | 16 | +23.1% |
| 95th percentile stored score | 93 | 88 | −5.4% |
Scores are compared on the stored value, so older rows are not understated by score decay.
Port scanning and SSH brute force lead the tagged activity.
The most common tags in 2026 are port scans (124,644 rows), SSH brute force (106,562) and web application attacks (104,015). SSH brute force rose from 5,323 to 106,562 tagged rows, and port scanning from 1,998 to 22,053.
| Attack-type tag | 2025 | 2026 | Change |
|---|
A row can carry several tags. Many 2026 tags were absent from the 2025 export, so their change reflects tagging coverage, not attacks alone.
Brute-force activity grew fastest of the techniques with a 2025 baseline.
Brute-force techniques (T1110) went from 6,557 rows in 2025 to 562,826 in 2026. Phishing (T1566) doubled to 2.1 million rows. T1566 also counts spam sources, so it is a broad measure.
| Technique | 2025 | 2026 | Change |
|---|
Origins are shifting towards the US and cloud networks.
China (15.3% of 2026 rows) and the United States (13.0%) are the largest countries of origin. US rows rose 77.4%, while India fell 44.4% and Iran fell 82.2%. Cloud and hosting networks grew strongly: DigitalOcean rose from 232,913 to 392,451 rows, and Google from 88,881 to 150,220.
| Country | 2025 | 2026 | Change |
|---|
Geography uses IPinfo lite. Addresses with no autonomous system entry are shown as Unknown.
Cloud-hosted sources now make up almost half of the feed.
Rows reported by cloud providers rose from 116,522 to 4,199,580, which is 45.1% of 2026 rows. This is the largest change in the dataset, and it partly reflects which sources were tagged in each year, so read it as a shift in who reports, not in attacks alone.
Indicators are consolidating: fewer objects, more unique ones.
STIX 2 objects fell 28.0%, from 3.92 million to 2.82 million, while distinct indicators rose 8.5%, from 615,234 to 667,727. Command-and-control is still the leading phase, while persistence rose from 156,386 to 371,324 objects and credential access appeared at scale.
The live feed as of 5 October 2026.
2,032,103 addresses are active in the live feed. 840,527 of them (41.4%) are reported by three or more members. 52,605 have a displayed score of at least 150, and 1,038 score 500 or more.
How these numbers were produced
- Source: exports of OneFirewall IPv4 rules and STIX 2 indicators, 5 October 2026.
- Periods: 1 January to 5 October, UTC, in 2025 and 2026. Change is the percentage change from 2025 to 2026.
- Tag-based metrics depend on which reporting sources and tags existed in each year. Many 2026 tags have no 2025 baseline.
- Scores are compared on the stored value. The displayed score decays with time, so it is used only for the live snapshot.
- Every IPv4 address is masked, with the last octet removed. No member, user or token data is included.
