Skip to main contentSkip to footer
Threat Intelligence

ReportedIP Blacklist Passed 30,000 Threat IPs in September 2026

Updated Patrick Schlesinger
Milestone card showing the ReportedIP blacklist at 30,926 high-confidence threat IPs, up 7,401 IPs in 30 days, with CMS login as the top attack vector

On September 21, 2026, the daily ReportedIP blacklist export crossed 30,000 threat IPs with a confidence score of 75 or higher for the first time, and it held 30,926 entries on September 26. Since a scoring change on September 28 lets addresses that stop attacking fall out, the same export listed 7,180 IPs on September 29.

The list is free to download in TXT, JSON and CSV and is rebuilt once a day around 04:20 UTC. Formats, checksums and the download location are documented on the blacklist documentation page.

How did the ReportedIP blacklist grow from 20,000 to 30,000 IPs?

All counts in this article come from the daily export, the same files that are published for download. Until September 29, 2026, an address was in that export when its confidence score was 75 or higher, it was not on the whitelist and its most recent report was at least 48 hours old. Since the export of September 30, the 48 hours count from its first report. The export first went above 20,000 on July 27, 2026 and above 30,000 eight weeks later.

DateIPs in the daily exportWhat happened
July 27, 202620,289First export above 20,000
August 27, 202623,525Start of the last 30 days before this article
September 21, 202630,547First export above 30,000
September 26, 202630,926Publication of this article
September 29, 20267,180First daily export with inactivity decay

In the 30 days before September 26 the export grew by 7,401 IPs, or 31%. Compared with July 27 it had gained 10,637 IPs. The growth was not steady: between September 25 and September 26 the list shrank from 31,355 to 30,926 entries, and on September 26 another 7,174 addresses above the threshold were still inside the 48-hour window and visible only through the live API.

Which attacks did the listed IPs carry out?

Every listed IP was reported by the community network for real attacks. The export splits the addresses into nine thematic lists, and one address can sit in several of them.

Thematic listIPs listed (Jul 28, 2026)IPs listed (Sep 26, 2026)IPs listed (Sep 29, 2026)
CMS login attacks17,93827,6546,944
Web attacks (SQLi, XSS, path traversal)16,54126,1036,758
Brute force9,87714,9153,017
Malware distribution7,6369,6262,045
Malicious infrastructure3,7444,754505
APT-linked activity1,9812,533750
DDoS1,9912,425256
Spam8001,347239
Fraud610901235

On September 26 the category counts added up to 90,258 across 30,926 unique addresses, so the average listed IP appeared in 2.9 of the nine lists. An attacker that brute-forces a login today often probes the same site for injection points tomorrow.

89.4% of the listed IPs targeted CMS login pages on September 26, up from 87.7% on July 28. In the smaller export of September 29 the share is 96.7%. Password guessing against web logins is catalogued as MITRE ATT&CK T1110, and WordPress absorbs most of that traffic. On September 25 alone the network received 26,895 attack reports from 9,620 distinct IPs, against 16,133 reports on July 27. Our WordPress attack report for May through July 2026 breaks the vectors down.

Why does the blacklist list fewer than 30,000 IPs today?

Since September 28, 2026, the score of an address that goes quiet decays to zero. Two weeks after its most recent report, the whole confidence score starts to halve every 30 days. An address scored 90 drops below the listing threshold of 75 within about three weeks without a new report. Before this change, addresses that had stopped attacking could stay on the list for weeks.

The first daily export under the new rule held 7,180 IPs. The live list at confidence 75, which has no 48-hour delay, held 12,545 addresses on September 29, and 4,173 of them scored 90 or higher. The attack volume did not drop: on September 28 the network logged 32,042 reports from 11,156 distinct IPs. What changed is that every listed address was reported recently enough to still score 75 or higher. Part of the drop also came from the export filter of that time, which left out every address reported in the previous 48 hours, including attackers that were still active. With the filter used from September 30, a dry run on September 29 returned 12,514 IPs instead of 6,934.

The 30,000 mark therefore describes the list as it was scored in September 2026. New reports lift an address again, and once it is back at 75 it returns with the next daily export. The 48-hour wait only applies to its first report, so the count will rise again when attack waves come. The change is explained in the self-cleaning blacklist announcement and in the API changelog.

How does an IP end up on the blacklist?

The feed is generated automatically from community reports, without manual picks. An address makes the cut only when all of these hold:

  • Confidence score of 75 or higher, computed from report volume, reporter diversity, recency and threat severity
  • 48-hour delay: an address enters the published files 48 hours after its first report and stays while its score is 75 or higher (until September 29, 2026, the delay counted from its most recent report)
  • Whitelist filter: known crawlers, monitoring services and legitimate infrastructure never enter the feed
  • Inactivity decay: two weeks after the last report the score starts to fall, and the address leaves once it drops below 75

The full calculation is documented under confidence score. Operators who cleaned up a compromised host can use the IP delisting form without waiting for the decay.

How do you use the blacklist on your server?

The download ships ready-made formats next to the raw data: formats/nginx-deny.conf for Nginx, formats/apache-htaccess.txt for Apache and formats/iptables.sh for firewall-level blocking. For ipset, nftables, IPv6 and cloud WAF setups, the network-level blocking guide has a sync script with ETag support and a sanity check that refuses to load a truncated list.

WordPress sites get the same intelligence without manual syncing: the free ReportedIP Hive plugin checks visitor IPs against the live network, blocks known attackers in real time and reports new attacks back. Linux servers outside WordPress can run the ReportedIP Agent, which loads the list into the kernel firewall every 15 minutes and is open to testers with free server licences. For a manual setup with ipset, nftables and fail2ban, see our guide to protecting a web server.

Frequently asked questions

Why does the blacklist now list fewer than 30,000 IPs?

Addresses that stop attacking now leave the list on their own. Since September 28, 2026, a score starts to halve every 30 days once two weeks have passed without a report. The daily export fell to 7,180 IPs on September 29, while the number of incoming reports kept rising. With the export filter used from September 30, a dry run returned 12,514 IPs.

How often is the blacklist updated?

The downloadable files are rebuilt once a day, around 04:20 UTC. Every build regenerates all 18 files, including the nine thematic lists, the server-ready formats and a metadata file with SHA-256 checksums. For data that is minutes old instead of a day old, use Hive, the Agent or the API.

Is the blacklist free to use?

The published files are free for commercial and private use under the CC BY 4.0 licence. Live data without the 48-hour delay comes from the ReportedIP API: single checks are free up to 1,000 a day, and the current list is available from the Contributor plan.

How does an IP get removed from the list?

Removal happens in two ways. Automatically, when the score decays below 75 because nobody reports the address for several weeks. Or through a delisting request after the operator has resolved the compromise, which removes the address without waiting for the decay.

Get the list, join the network

Leave a Reply

Your email address will not be published. Required fields are marked *

Fill out this field
Fill out this field
Please enter a valid email address.
You need to agree with the terms to proceed