Harvesting SSH Credentials: Insights from My Honeypot Network

Millions of break-in tries hit fake servers — and the comments instantly turned savage

TLDR: A researcher’s fake servers got hammered with 1.53 million login tries in a month, showing just how constant internet break-in attempts really are. But commenters stole the spotlight by mocking laughable passwords, questioning whether the data means much, and wondering what the bots do when they finally get inside.

A hobby security project quietly set out 15 fake internet-facing machines across the world, then sat back and watched the chaos: 1.53 million login attempts from 6,790 unique internet addresses in just 30 days. On paper, that’s a fascinating peek into the nonstop background noise of the web. But in the comments, the real show began, with readers instantly splitting into two camps: “wow, that’s wild” versus “hold on, this isn’t as meaningful as you think.”

The sharpest pushback came from people dunking on the word “harvesting.” One commenter flatly argued that no real secrets were collected here, just junk guesses and patterns, basically calling the whole thing a stats project dressed up in a scary headline. Others were less interested in semantics and more obsessed with the comedy of bad passwords. The biggest laugh line? A sarcastic jab at using “toor” as a root password — that’s just “root” backwards — which commenters treated like the digital version of hiding your house key under the mat. Another user escalated the bit by claiming a single weird symbol like “%” might now be safer than old-school passwords, which is exactly the kind of cursed internet wisdom people love to quote.

And then came the genuinely creepy question hanging over the thread: if these bots ever do get in, what happens next? Spam machine? Crypto scam? Fake websites? That curiosity gave the whole discussion a darker edge. So yes, the numbers are huge, with Europe leading by sheer attack volume and Asia by unique sources, but the comments turned this from a data dump into a full-blown spectator sport. For readers, the lesson was simple: the internet is trying your locks all day, and the crowd is arguing about whether the thief is dumb, dangerous, or both.

Key Points

  • The article reports first-month results from a global SSH honeypot network deployed on 15 dedicated IPv4 servers across five VPS providers in July 2026.
  • The dataset contains 6,790 unique attacker IPs, 1,531,053 total login attempts, 131,922 unique username-password pairs, 12,238 unique usernames, and 97,621 unique passwords.
  • The analysis includes only login attempts; scans and other attack types are explicitly excluded from the current report.
  • Asia accounts for the largest share of unique attacker IPs at 60.1%, while Europe accounts for the largest share of login attempts at 60.2% and the highest attempts per IP.
  • At the country level, China leads by unique attacker IPs, while the Netherlands leads by total login attempts with 686,449, or 44.8% of the total.

Hottest takes

"root password of 'toor' is very clever" — asveikau
"It's all worthless data" — daneel_w
"% is my new root password" — pastage
Made with <3 by @siedrix and @shesho from CDMX. Powered by Forge&Hive.