Significant Threat
IP 207.90.244.21 is a high-risk address operated by Cogent Communications (AS174) that has generated 11,803 abuse reports across automated honeypot sensors between September 2025 and June 2026, indicating sustained and widespread malicious activity originating from this United States-based IP. The address carries a threat level of 8/10 and an 84% confidence score, making it a reliable indicator of genuine risk.
The overwhelming majority of recent reports—19 out of 20 recent classifications—categorize activity from this IP as general hacking intrusion attempts, while a smaller subset of reports flag IoT-targeted operations. The volume of reports is exceptionally high, and the detection footprint spans 20 separate honeypot sensors, demonstrating that this is not an isolated incident but rather persistent scanning and exploitation activity that has been observed across multiple security monitoring points. The nine-month reporting window from first to most recent detection confirms ongoing, sustained hostile behavior rather than opportunistic or transient abuse.
Hacking activity associated with this address suggests systematic attempts to gain unauthorized access to systems, exploit vulnerabilities, or probe for weaknesses in exposed services. The IoT-targeted classification indicates the IP has also been involved in scanning for or attacking poorly secured internet-connected devices such as cameras, routers, and smart appliances. Together, these threat patterns expose networks to data breaches, device compromise, lateral movement, and potential recruitment into botnets. Any service directly exposed to the internet with weak authentication or unpatched vulnerabilities faces elevated risk from traffic originating from this address.
Network administrators should block 207.90.244.21 at the firewall or edge device level given its high threat score and report volume. Deploying tools such as fail2ban or equivalent intrusion-prevention systems can automatically detect and ban repeated connection attempts. All exposed services should enforce strong, unique credentials and implement rate-limiting to reduce the effectiveness of automated attacks. Regular security audits, prompt patching, and network segmentation—especially for IoT devices—are essential defensive measures against the exploitation patterns this IP represents.