Project SHINE found a large number of industrial and infrastructure-related devices that appeared in SHODAN data as connected to the public internet—but its figures describe a historical search snapshot, not today’s exposure. The researchers analyzed metadata collected from 14 April 2012 through 31 January 2014 and published their findings on 1 October 2014. They did not scan or attempt to access the devices.
What was Project SHINE?
Project SHINE—short for “SHodan INtelligence Extraction”—was a research and awareness project that used SHODAN metadata to identify devices that appeared to be directly connected to the public internet. The researchers were interested in the potential exposure of supervisory control and data acquisition (SCADA) systems and other industrial control systems (ICS), as well as related infrastructure.
The Project SHINE findings report describes data gathered from 14 April 2012 through 31 January 2014. Its purpose was to make organizations more aware of discoverable devices and potential risks, not to exploit systems or verify their security. The report states: “At no point during the activities of Project SHINE did we ever perform any scanning, or attempt to directly access any of the embedded devices and/or computer systems connected to the Internet.” Read the Project SHINE findings report.
How many internet-connected systems did Project SHINE find?
In their 2015 presentation, the researchers reported 2,186,971 devices in the project’s results. They estimated that 586,997 devices—about 26.84% of that reported total—fell into the traditional ICS/manufacturer grouping displayed in the presentation. SecurityWeek’s 2014 account separately described roughly 586,997 sampled industrial systems, including RTUs and PLCs. These are study-era classifications, not counts of devices known to be vulnerable or compromised.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problems#1 Best Overall
| Reported figure | What it describes | Source and date |
|---|---|---|
| 2,186,971 devices | Total devices in the project’s reported results | Project SHINE researchers’ presentation, 2015 |
| 586,997 devices (about 26.84% of 2,186,971) | Estimated count in the presentation’s traditional ICS/manufacturer grouping | Project SHINE researchers’ presentation, 2015 |
| 13,475 systems | HVAC and building automation systems reported as a sample subset | SecurityWeek, 2014 |
| 204,416 devices | Serial-to-Ethernet devices reported as another sample subset | SecurityWeek, 2014 |
| 182 manufacturers | Traditional SCADA/control-system manufacturers identified for the researchers’ search queries | SecurityWeek, 2014; a closely related unique-manufacturer count appears in the 2015 presentation |
The categories extended beyond conventional programmable logic controllers (PLCs) and remote terminal units (RTUs). The presentation also lists intelligent electronic devices and sensors, SCADA and human-machine-interface servers, building automation and medical devices, plus nontraditional categories such as traffic and lighting controls, automotive controls, HVAC and environmental systems, power regulators and UPS equipment, security and access control, serial-port servers, data radios, mining equipment, and traffic cameras. The report and SecurityWeek also mention examples such as wind farms, water utilities and substations. These examples do not establish that every identified device was unsafe.
Were SCADA systems exposed to the internet?
Project SHINE found systems whose SHODAN metadata suggested public-internet connectivity during the study period. That is evidence of discoverability in the data the researchers examined—not proof that every device was operational, reachable in the same way, or accessible without authorization. Nor does appearing in a search result alone establish a security vulnerability.
Rank #2
The project’s method also had classification limits. The 2015 presentation notes that some search results were unrelated to infrastructure, company names changed after acquisitions, and shared or similar software could result in incorrect manufacturer attribution. The researchers said they could not establish an internet-wide baseline, so the results cannot show how exposure changed over time. A missing SHINE result would not prove that an organization had no internet-connected control equipment.
Did Project SHINE prove those devices were hacked?
No. The project was about finding and classifying systems visible in SHODAN metadata, not confirming compromise. Its results do not demonstrate that a device was breached, that an attacker controlled it, or that a safety incident occurred. They also do not show that every result represented critical infrastructure.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →ICS-CERT’s July–September 2013 Monitor provides separate contemporaneous context: it said it received reports of internet-connected control systems from researchers including Bob Radvanovsky and described one reported system as lacking password protection and being directly accessible. That incident example is not part of SHINE’s totals. See the ICS-CERT Monitor, July–September 2013.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What can operators learn from the findings?
The project-era lesson was to understand what equipment an organization owns and what can be reached from public networks. SecurityWeek reported that Radvanovsky urged organizations to audit their environments and include security in engineering design and implementation reviews. Those are practical starting points, but the 2014 report cannot determine a facility’s present-day exposure.
Rank #4
- Maintain an accurate inventory of control-system and related infrastructure assets, including equipment that may not be thought of as a conventional ICS device.
- Review which assets are reachable from public networks through an authorized, site-specific assessment.
- Include security considerations in system design and implementation reviews, rather than relying only on discovery after deployment.
Any decision about current exposure requires current, authorized assessment of the specific environment. SHINE’s historical results provide no current internet-wide count or present-day trend line.
Quick Recap
Best Value
- Industrial Cybersecurity: Efficiently monitor the cybersecurity posture of your ICS environment, 2nd Edition
- ABIS BOOK
- Packt Publishing
Sources and dates
- Project SHINE (SHodan INtelligence Extraction) Findings Report, dated 1 October 2014; data window 14 April 2012–31 January 2014.
- 10th SANS ICS Security Summit Project SHINE Presentation, by Bob Radvanovsky and Jake Brodsky, 24 February 2015.
- “Project SHINE Reveals Magnitude of Internet-connected Critical Control Systems”, Fahmida Y. Rashid, SecurityWeek, 6 October 2014.
- ICS-CERT Monitor, July–September 2013.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →

