Real numbers from the servers that run KIPBan: how many attacking IPs were banned, where they come from, which networks host them and how many come back. The data comes from the shared ban list, is aggregated, and refreshes automatically. No individual IP addresses or customer details are published.
New attacking IPs per day
What attackers go after
Share of banned IPs by the service that caught them. One IP can hit several services, so the shares can add up to more than 100%.
Where the attacks come from
Countries with the most banned IPs, by geolocation of the address. Attack sources are often hijacked machines, so this shows where the machines are, not who is behind them.
Networks that host the attackers
Autonomous systems (ASNs) with the most banned IPs.
When attacks are detected
Bans by hour of the day, UTC. Bots do not sleep, which is the point.
How many come back
Banned IPs by offence number. An address that returns after its ban expires moves up the ban ladder (3 days, 30 days, then forever by default). The third step is only reached after a 30-day ban expires, so it fills up as the data period grows.
How to read these numbers
- Source. The shared KIPBan ban list: IPs reported by agents on Windows and Linux servers of the people running the service, including our own fleet.
- Period. Up to the last 30 full days (UTC) plus the current day. The service began collecting this data on 27 September 2026, so the period grows daily until it reaches 30 days. The one-off import of old bans on 26 September is excluded.
- Unique IPs. Addresses that entered the shared ban list during the period, each counted once. “New IPs per day” counts addresses seen in the shared list for the first time on that day.
- Bans. How many times an address was banned by any organization. If three organizations catch the same address, that is three bans; several servers of one organization count as one. A repeat catch after a ban expires counts again.
- Came back. Each address is placed on the highest ban step reported for it during the period; the share is addresses on the 2nd step or higher.
- Countries and networks. IPv4 addresses only, matched with the public-domain iptoasn.com database. Only groups of at least 5 addresses are listed.
- Aggregates only. We publish totals, shares and top lists. We do not publish single IP addresses, server names or anything that identifies a customer.
- Cleaned data. Demo and test accounts, whitelisted addresses and CDN ranges are excluded.
- Refresh. The page reads attack-stats.json, which is updated automatically. The time of the last update is shown at the top.
- Limits. The sample is the servers that run KIPBan, not the whole internet. Treat it as a view of what exposed RDP, SSH, mail and web services see, not as a global census.
Questions about the statistics
Can I quote or reuse these numbers?
Yes. Please link to this page and mention KIPBan as the source. The raw aggregate data is in attack-stats.json.
Do you publish the attacking IP addresses?
Not on this page. Customers can get the addresses as a block list for their router, firewall or nginx.
Why do the numbers differ from my own logs?
This is the combined view of every connected server, with each IP counted once, while your logs show only the traffic that reached your own machines.