Substantial Risk
IP address 91.196.152.23 is a critical-risk French address that security monitoring systems have flagged 157 times over approximately nine months for sustained hacking activity, including intrusion attempts and exploitation probing against exposed services. With a threat level of 10 out of 10 and an activity frequency rated 8 out of 10, this IP represents a persistent, high-confidence threat that defenders should treat as actively malicious until further notice.
Automated honeypot sensors across twenty distinct detection points recorded these incidents between September 2025 and June 2026, yielding a confidence score of 87 percent for the attribution. The IP originates from network AS213412 operated by ONYPHE SAS, a French registered entity, placing the source infrastructure within France's jurisdiction. The volume of reports—averaging roughly seventeen per month over the observation window—combined with the consistent presence across multiple geographically distributed sensors indicates deliberate, methodical targeting rather than opportunistic scanning noise.
The dominant reported category of hacking encompasses various intrusion vectors such as unauthorized access attempts, vulnerability exploitation and credential-based attacks against services exposed to the internet. For any organization running publicly accessible SSH, Telnet, HTTP interfaces or similar entry points, repeated contact from an address with this reputation profile substantially elevates the risk of successful compromise if adequate hardening is absent. The sustained cadence of activity suggests an automated campaign or a persistent operator maintaining ongoing access attempts across a wide attack surface.
Site operators are advised to block this IP at the firewall or network edge layer immediately, and to consider implementing automated blocking tools such as fail2ban or equivalent dynamic deny-lists to reactively ban repeat offenders. Authentication hardening measures—including disabling password-only authentication in favour of certificate-based SSH access, enforcing strong passphrase policies and implementing account lockout thresholds—dramatically reduce the effectiveness of intrusion attempts. Regular security patching, intrusion detection monitoring and review of authentication logs for matching source addresses will further mitigate risk from similar persistent scanning activity.