High Risk
IP 195.96.138.135 is a high-risk address linked to VoIP fraud, with a threat level of 7/10 and a confidence score of 91% based on 226 abuse reports from automated honeypot sensors. The IP is registered in Great Britain and operated through AS210924 (ssd networks limited), with activity consistently reported between April and May 2026.
The data reveals a persistent threat actor: 226 total reports across an elevated activity frequency of 8/10, with 20 of those reports specifically documenting Fraud VoIP activity. All detections originated from automated honeypot infrastructure, indicating systematic scanning or exploitation attempts rather than isolated incidents. The two-month reporting window demonstrates sustained intent, not opportunistic probing. The network operator, ssd networks limited, operates within the United Kingdom, placing this source in a jurisdiction where such activity carries significant legal risk—yet continues unabated.
VoIP fraud exploits telephone infrastructure to route unauthorized calls, frequently targeting premium-rate or international numbers for direct financial gain. Attackers may compromise SIP endpoints, abuse open proxies, or leverage stolen credentials to hijack call sessions. For an organization running exposed VoIP hardware, an IP with this reputation increases the likelihood of toll fraud, service theft, or lateral movement into adjacent systems. The high report volume and activity frequency suggest this address participates in automated campaigns rather than manual exploitation.
Operators should immediately block or rate-limit connections from 195.96.138.135 at the firewall level and monitor inbound SIP traffic for anomalies. Enforcing strong authentication on all VoIP endpoints—including certificate-based SIP TLS and multi-factor authentication—reduces credential abuse risk. Restricting international and premium-rate dialing outbound rules limits financial exposure if compromise occurs. Deploying defensive tools such as fail2ban to auto-ban repeat offenders and reviewing honeypot logs for evolving tactics will strengthen long-term posture against this threat cluster.