6 min read

Internet Security & Threat Trends 2026: A Research Summary

Updated Published by Kishan Prajapat, SEO & Content Lead

This is a summary of public sources, listed under Data Sources at the end, not original research. Figures are only given where we can link to where they came from.

Summary

This summary pulls together what public threat-intelligence and abuse-reporting sources describe about automated scanning and credential-stuffing in 2025–2026. The clearest trend is a shift in where attack traffic comes from. Blocking known hosting-provider networks used to stop a large share of scanning and login abuse. Attackers now increasingly route that traffic through residential proxy networks and mobile carrier networks behind Carrier-Grade NAT, so it looks like ordinary household or mobile use. Many of those residential exit points are compromised home devices (routers, IP cameras, NAS boxes) running default passwords or unpatched firmware. The practical result is that IP blocklists and hosting-network blocks catch less than they used to, and defenders need signals beyond the IP address.

Key Findings

  • 1Traffic is moving to residential IPs: public reporting on credential stuffing and bot abuse describes a steady move from datacenter IP ranges to residential proxy networks, which are much harder to block without affecting real users.
  • 2Hosting networks still matter: large-scale SSH and service scanning continues to come from rented cloud and VPS servers, so hosting-network signals remain useful even if they’re no longer enough on their own.
  • 3Mobile CGNAT is a blind spot: many subscribers share each public IP on mobile networks, so blocking one address can lock out large numbers of legitimate users. Attackers exploit exactly that reluctance to block.

Methodology

This is a summary of publicly available reporting and data, not an original measurement. It draws on the sources listed under Data Sources, read alongside the network diagnostics covered in our guide to how attackers use IP addresses. No figures are given where we couldn’t attribute them to a source.

Analysis

Research into these networks describes a consistent pattern. An attacker rents access to a residential proxy service, which provides a rotating list of household exit IPs, and cycles scanning or login attempts through them. Because each exit IP belongs to a real consumer ISP, reverse DNS and geolocation look normal and a single address rarely sends enough traffic to trip rate limits. Some signals still help. Tunnelled or proxied connections can show a lower effective MTU than a typical 1500-byte broadband link, round-trip times through residential exits vary more than datacenter traffic, and the TLS or TCP fingerprint of a script often doesn’t match the browser its User-Agent claims to be. None of these is proof on its own, and legitimate users on PPPoE, VPNs or mobile networks can show the same traits, so they work best combined. Our article on why your IP address matters covers what an IP does and doesn’t reveal.

Industry Insights

Online retailers see proxy-routed bots during product launches and with card testing, where stolen card details are tried in small purchases. SaaS and login-heavy services see credential stuffing that replays passwords from earlier breaches. In both cases the defence has shifted from “block the bad IP” to evaluating each request: device and TLS fingerprints, behaviour, and the reputation of the network behind the IP.

Actionable Recommendations

  • ✓Use ASN checks as one signal: look up the network behind each login or checkout IP with an ASN lookup or an IP data API, and require extra verification when a “home user” connects from a hosting network.
  • ✓Treat unusual MTU and fingerprint mismatches as signals, not blocks: legitimate users on PPPoE, VPNs and mobile networks also have smaller MTUs, so flag and combine these signals rather than dropping traffic.
  • ✓Adopt passkeys: moving users to FIDO2/WebAuthn passkeys removes the value of stolen password lists entirely.
  • ✓Rate-limit by more than IP: include account, device and network reputation in rate limits so rotating IPs doesn’t reset the limit. Our guide to checking IP blocklists explains how reputation lists work.

Data Sources

Frequently Asked Questions