Severe Risk
IP 162.216.150.214 is a critical-risk address operated through Google Cloud Platform infrastructure that has accumulated 227 abuse reports from automated honeypot sensors over approximately nine months, with recent activity centering on hacking activity including unauthorized SSH access attempts detected via intrusion-detection signatures.
The address, which traces to United States-based Google Cloud Platform (ASN AS396982), was first reported in September 2025 with continued reporting activity extending through June 2026, indicating sustained rather than opportunistic malicious behaviour. All 20 most recent report sources originate from automated honeypot sensors, yielding a 75 percent confidence rating that this IP is actively engaged in hostile reconnaissance and intrusion activity. The activity frequency of 3 out of 10 suggests methodical, periodic scanning rather than high-volume burst attacks, consistent with credential-stuffing campaigns or systematic brute-force probing of exposed SSH services.
The dominant threat category—hacking activity—encompasses unauthorized access attempts, exploitation probing, and session establishment against targeted services. The specific detection of SSH session activity on expected ports via Suricata intrusion-detection rules indicates this address is actively attempting to establish remote administrative access to exposed Linux and network infrastructure. For organisations running publicly accessible SSH services, such probing represents a direct pathway to server compromise, data exfiltration, and lateral movement within internal networks if credentials are weak or authentication is unchallenged.
Operators should block this address at the network perimeter firewall and implement rate-limiting on SSH authentication attempts to mitigate credential-guessing campaigns. Deploying defensive tools such as fail2ban or analogous log-analysis frameworks can automatically temporal-block repeated authentication failures. Enforcing key-based authentication exclusively, implementing multi-factor authentication for administrative access, and ensuring SSH services are restricted to known management IP ranges will substantially reduce exposure to this category of threat.