Significant Threat
IP address 91.231.89.190, allocated to French network operator ONYPHE SAS, is a high-risk address that has generated 179 abuse reports from automated honeypot sensors over approximately six months, indicating persistent intrusion activity with a threat level of 8/10 and a confidence score of 88 percent.
The majority of recent reports — 19 of the 20 most recent threat classifications — categorise this IP as involved in general hacking activity, while one report flags it for IoT-targeted behaviour. All 179 reports across the detection window were submitted by 20 distinct automated honeypot sensors, reflecting wide-scale detection rather than isolated observations. The IP was first reported in January 2026 and most recently flagged in June 2026, with an activity frequency rating of 8/10, suggesting consistent rather than sporadic malicious engagement throughout this period.
The dominant hacking classification encompasses various intrusion attempts, exploitation attempts targeting exposed services, and unauthorised access probing. When an IP maintains this level of sustained, multi-sensor detection over half a year, it signals automated scanning infrastructure or coordinated campaigns rather than opportunistic drive-by attempts. The secondary IoT-targeting flag indicates the same address has additionally been associated with attempts to exploit weak security in connected devices, cameras, or routers — a threat vector distinct from traditional server compromise but equally dangerous for organisations with poorly secured device estates.
Operators should block or aggressively rate-limit connections from this address at the network perimeter, implement fail2ban or equivalent log-based blocking to auto-respond to authentication failures, enforce strong credential policies on all exposed services, and segment IoT devices onto isolated network zones to limit lateral movement risk if any single device is compromised.