Poland (PL) Threat Intelligence

PL

Poland has 16,165 malicious IP addresses with 619,956 abuse reports. Top threat categories include ssh bruteforce, web attack, generic bruteforce, mail bruteforce, web scanner. Top attacking networks: Orange Polska Spolka Akcyjna (1,435 IPs), 1337 Services GmbH (1,286 IPs), MEVSPACE sp. z o.o. (1,161 IPs). Data collected since 2023-05-26, last activity 2026-04-16.

Threat Assessment: Poland shows substantial cyber threat activity, ranking among the top threat source countries worldwide. The dominant attack types are ssh bruteforce, web attack, generic bruteforce. The majority of threats originate from networks operated by Orange Polska Spolka Akcyjna and 1337 Services GmbH.

Total Reports
619,956
Unique IPs
16,165
First Seen
2023-05-26
Last Activity
2026-04-16

Top Threat Categories

Ssh Bruteforce 537
Web Attack 130
Generic Bruteforce 51
Mail Bruteforce 10
Web Scanner 8

Top Attacking Networks

AS5617 Orange Polska Spolka Akcyjna
1,435 IPs
AS210558 1337 Services GmbH
1,286 IPs
AS201814 MEVSPACE sp. z o.o.
1,161 IPs

Most Reported IPs in Poland

54.38.52.18 266 reports
31.6.212.12 255 reports
193.106.245.20 245 reports
45.138.16.231 242 reports
45.138.16.240 240 reports

Access this data via API

Get Poland threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/PL

View full API documentation

See how we classify and verify threats →

Check any IP from Poland

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS5617 Intelligence AS210558 Intelligence AS201814 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...