Critical Alert
IP 91.231.89.191 is a critical-risk address operating from French infrastructure that has generated 161 abuse reports across automated honeypot sensors within a six-month window, driven predominantly by sustained hacking activity and targeted exploitation of Internet of Things devices. The IP's threat level sits at the maximum 10 out of 10, with a confidence score of 91 percent, placing it among the most reliably attributed hostile sources currently in circulation. With an activity frequency rated 8 out of 10 and reports sourced from 20 separate honeypot deployments, the volume and consistency of hostile traffic leaving this address leave no ambiguity about its intent.
Detection data spanning January 2026 through June 2026 confirms persistent engagement with internet-facing systems during that period, with the address routing through AS213412 operated by ONYPHE SAS, a French entity. The 161 reports break down primarily into general hacking activity, encompassing a broad spectrum of intrusion attempts and vulnerability exploitation, alongside a smaller but notable subset explicitly targeting IoT and ICS infrastructure. The geographic origin in France combined with the diversity of detected attack patterns suggests an automated scanning or compromise campaign rather than opportunistic noise, given the sustained report volume and specificity of targeting.
The dominance of hacking-category activity indicates this address is being used to probe and exploit vulnerabilities across a wide range of exposed services, from web applications to network infrastructure. When combined with the IoT-targeted subset, the real-world risk extends to the compromise of smart devices, cameras, routers and industrial control systems that lack robust hardening. An address with this reputation operating at high frequency against internet-facing assets represents a credible pathway for initial access, lateral movement and subsequent payload delivery, particularly against unpatched or misconfigured endpoints.
Site operators should treat connections originating from 91.231.89.191 as hostile and block them at the network perimeter without deliberation. Implement rate-limiting on authentication endpoints and expose only essential services to reduce attack surface. IoT and ICS devices on the network should be placed in isolated segments, updated with current firmware and stripped of default credentials. Deploy or configure defensive tools such as fail2ban or equivalent log-analysis frameworks to automatically ban repeated offending sources and monitor for the connection and IoT-targeted patterns associated with this address.