For the last week of June, our honeypot fleet saw a steady, unremarkable background of around 600 distinct attackers a day. Then, on July 6, that number jumped to nearly 1,500 — and over the next four days it climbed past 2,800 and stayed there. This is what a real attack surge looks like in the data: not one loud event, but a broad, sustained rise in the sheer number of different machines knocking on the door. Here is what drove it, the two very different shapes the traffic took, and what a surge like this can and cannot tell you.
Beginning July 6, 2026, the count of unique source IPs attacking the Deception Check fleet each day rose from a ~600/day baseline to a 2,700–2,900/day plateau — a roughly 4–5× increase that held for the rest of the window. Across the surge we logged 11,807 distinct IPs. The traffic sorted cleanly into two archetypes: broad fleet-wide scanners that reached at least 15 decoys across four continents, and single-target floods that fixated on one node and hammered it tens of thousands of times — the loudest being the Mirai-lineage IoT loader we dissect in a companion piece. The rise was not random noise: it contained clear structure, including several addresses from one flagged network block and coordinated /24 pairs. We report the counts and shapes our sensors recorded and stay deliberately cautious about attributing them to any campaign or actor.
The most honest way to read a honeypot fleet is to stop looking at raw volume — which any single misbehaving bot can inflate — and look instead at how many different machines show up. That number is harder to fake and closer to a real measure of interest. Through late June it sat flat: 232, 578, 619, 565, 656, 601, 628, 531, 687 distinct IPs on successive days. A quiet, healthy baseline. Then July 6 landed at 1,442, July 8 at 2,755, and July 10 at 2,890, and the fleet never returned to its old floor. Whatever changed on the 6th did not spike and fade; it reset the baseline to four or five times what it had been.
We are careful not to over-read a single fleet's view of the internet. A rise like this can reflect a new scanning campaign, a botnet expanding its worker pool, a block of cloud or residential addresses being turned to the task, or simply our own decoys becoming better known and more indexed by the scanners that catalogue exposed services. Most likely it is some blend. What we can say without hedging is that the change was real, sharp, dated, and sustained — and that it showed internal structure rather than looking like uniform background hiss.
When we broke the surge down by what each source actually did, the top talkers split into two clean archetypes — and the split matters, because they represent different intentions.
Scanners spread themselves across the whole fleet. One address, 5.61.209.43, opened 48,562 sessions and reached at least 15 decoys across four continents; 94.154.43.243 did the same at smaller scale. These are the internet's cartographers — mapping what is exposed and where, feeding target lists. Floods do the opposite: they lock onto a single node and pound it. 175.107.0.198 threw 83,734 sessions at one decoy and nothing else; 187.189.119.83 and 46.205.244.93 each fixated on a single OT-style decoy. A flood is a bot that found something it liked and committed — usually an automated loader trying, over and over, to recruit what it believes is a vulnerable device.
The detail that separates a real campaign signature from ambient noise is repetition of structure. We saw it. Three of the heaviest single-target floods — 175.107.0.198, 175.107.3.227, and 175.107.0.91 — all originate from the same network block, 175.107.0.0/19, an address range that third-party reputation services flag as a source of repeated abuse. Separately, two coordinated pairs, 45.153.34.151/.167 and 45.156.87.253/.254, showed near-identical fleet-wide scanning behaviour from adjacent addresses. Neighbours behaving identically is the fingerprint of shared tooling or a shared operator — the difference between a crowd and a formation.
Stop looking at raw volume, which any single bot can inflate, and look at how many different machines show up. That number is harder to fake and closer to real interest.
A surge in unique attackers is a genuine signal, and the useful thing it tells a defender is timing and shape: attention rose on a specific date, it is dominated by IoT-style telnet floods and broad service scanning, and it is coming from identifiable clusters you can watch. That is actionable. What it is not is proof of a coordinated operation or grounds to name a culprit. Scanners and loaders run overwhelmingly from compromised third-party devices and rented infrastructure; the addresses we list are far more likely to be waypoints and victims than the hand on the wheel. We publish the clusters and counts because they help you tune detections and blocklists, not because they identify anyone.
Deception Check runs a fleet of language-model-backed honeypots and edge decoys that imitate real enterprise and operational-technology equipment, so we can watch attackers from the other side, at the moment they reach an exposed system. This surge surfaced on its own from routine fleet telemetry. First-party data, honest caveats.
© 2026 Deception Check. All figures are computed from first-party honeypot telemetry over the stated window; source-network reputation context is third-party and dated. No attribution to any named actor or campaign is made.