Germany (DE) Threat Intelligence

DE

Germany has 89,865 malicious IP addresses with 2,724,979 abuse reports. Top threat categories include ssh bruteforce, malware c2, web attack, generic bruteforce, mail bruteforce. Top attacking networks: DigitalOcean, LLC (15,267 IPs), Deutsche Telekom AG (7,091 IPs), Hetzner Online GmbH (5,676 IPs). Data collected since 2022-10-13, last activity 2026-04-16.

Threat Assessment: Germany shows substantial cyber threat activity, ranking among the top threat source countries worldwide. The dominant attack types are ssh bruteforce, malware c2, web attack. The majority of threats originate from networks operated by DigitalOcean, LLC and Deutsche Telekom AG.

Total Reports
2,724,979
Unique IPs
89,865
First Seen
2022-10-13
Last Activity
2026-04-16

Top Threat Categories

Ssh Bruteforce 3,963
Malware C2 1,190
Web Attack 1,010
Generic Bruteforce 322
Mail Bruteforce 241

Top Attacking Networks

AS14061 DigitalOcean, LLC
15,267 IPs
AS3320 Deutsche Telekom AG
7,091 IPs
AS24940 Hetzner Online GmbH
5,676 IPs

Most Reported IPs in Germany

140.82.121.3 2,018 reports
140.82.121.4 1,835 reports
139.19.117.129 435 reports
213.209.143.62 319 reports
158.94.208.162 313 reports

Access this data via API

Get Germany threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/DE

View full API documentation

See how we classify and verify threats →

Check any IP from Germany

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS14061 Intelligence AS3320 Intelligence AS24940 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...