Harvesting SSH Credentials: Insights from My Honeypot Network

A security researcher shares findings from a 30-day honeypot network project designed to track SSH credential harvesting attempts. The data highlights global attack patterns, revealing that while the majority of unique attacking IPs originate from Asia, the highest volume of login attempts comes from Europe.
Why it matters
Understanding the geographic distribution and volume of automated credential harvesting provides critical insights for network administrators to harden SSH configurations against global brute-force threats.
I’ve been working on this honeypot network for the past couple of months, and I’d now like to share some information from the first 30 days.
The project is still work-in-progress and I plan to improve it over time. The presentation is still a little bit rough, but this will do for now.
References for this article: - Timeframe = July 2026 - 15 servers (only dedicated for this purpose) - 15 IPs, IPv4 - all over the world (see above) - 5 VPS Providers - SSH Honeypot, Port 22/TCP The Data # Some things to consider before we start:
Presentation is still rough, but will improve with next versions.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in