Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Asia-Pacific did not filter Telnet traffic as consistently as several countries’ reported figures might suggest. A January 2026 global traffic drop was sharp, but it did not mean that exposed devices disappeared: Shadowserver estimated about 410,000 active internet addresses with accessible Telnet devices in the region, according to figures reported by Dark Reading.

What happened to Telnet traffic in January 2026?

GreyNoise data reported by Dark Reading showed global Telnet traffic falling over three hours on January 14, 2026, from about 65,000 sessions per hour to 11,000 sessions per hour. That was an 83% drop in average traffic.

The regional picture was less uniform. The report attributed the following shares of Telnet sessions as blocked or curtailed:

Country Sessions blocked or curtailed
Taiwan 77%
India 70%
Japan 65%
China 59%

These are GreyNoise figures as reported by Dark Reading in February 2026, not new measurements. The percentages describe sessions filtered or curtailed, not the share of devices secured or removed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

Why might traffic have fallen?

GreyNoise vice president of data science Bob Rudis offered a possible explanation: operators were introducing controls to manage heavy automated traffic, including AI scraping, and those changes may also have reduced Telnet activity. That is an attributed interpretation, not proof that scraping controls caused the drop or evidence of a coordinated regional effort to eliminate Telnet.

How many devices still expose Telnet in Asia-Pacific?

Shadowserver estimated 839,000 active internet addresses globally with accessible Telnet devices, including about 410,000 in Asia-Pacific, according to the Dark Reading report. An address estimate is not a count of unique owners or necessarily a count of distinct physical devices.

Rank #2
WatchGuard Firebox T45-PoE Network Security/Firewall Appliance (WGT47000-US+WGT470063)
  • WatchGuard Firebox T45 tabletop appliances bring enterprise-level network security to small office/branch office and retail environments. These appliances are small-footprint, cost-effective security powerhouses that deliver all the features present in WatchGuard’s higher-end UTM appliances, including all security capabilities, such as AI-powered anti-malware, threat correlation, and DNS-filtering.
  • 5G and Wi-Fi 6 enabled models available. Up to 3.94 Gbps firewall throughput, 5 x 1Gb ports, 30 Branch Office VPNs
  • Zero-touch deployment makes it possible to eliminate much of the labor involved in setting up a Firebox to connect to your network - all without having to leave your office. A robust, Cloud-based deployment and configuration tool comes standard with WatchGuard Firebox appliances. Local staff connects the device to power and the Internet, and the appliance connects to the Cloud for all its configuration settings.
  • Firebox T45 models make network optimization easy. With integrated SD-WAN and optional 5G technology, you can ensure failover to the cellular network, minimize disruptive connectivity, and establish secure and reliable connections for small offices.
  • Standard Support includes 24x7 access to technical support, with an unlimited number of incidents with a targeted response time of 24 hours for low priority, 8 hours for medium priority, 4 hours for high priority, and live calls for critical priority. Support is Web-Based and Phone-Based.

The report also said more than half of Telnet scanning traffic originating from Asia-Pacific addresses came from Chinese IP address space; India accounted for 14% and South Korea 12%. These figures describe the reported source geography of scanning traffic, not the location of all vulnerable devices or the identity of the people operating scans.

Why the exposure figures need context

Traffic volume and accessible-device estimates measure different things. A fall in observed sessions can happen while devices remain reachable, so a traffic decline alone does not show that systems were patched, replaced, or made safe.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Ubiquiti Unifi Security Appliance (USG), Single,White
  • Integration with Unifi Controller. Powerful firewall performance
  • Convenient VLAN support. QoS for enterprise VoIP
  • VPN server for secure communications. 10/100/1000Base-T
  • 3 Ports - Management Port - SlotsGigabit Ethernet - Wall Mountable, Desktop
  • Refer instruction manual for troubleshooting steps.

Shadowserver’s observed detections also changed as its measurement improved. The report says adding less common Telnet ports increased detections around January 20, while later filtering improvements reduced them. Changes over time therefore reflect both possible real-world changes and shifts in what Shadowserver could detect and filter; the reported series should not be read as a simple device-count trend.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Who still uses Telnet, and what should operators do?

Telnet may persist on small-business and consumer networks, including internet-connected cameras and other IoT equipment. Rudis said, “Most companies have cleaned up Telnet, but there’s a lot of Telnet on small-business and consumer networks — IoT, like cameras.”

Shadowserver Foundation CEO Piotr Kijewski described Telnet as “an unnecessary attack surface” that has long been replaced for remote terminal access, especially by SSH. For network operators, the practical response is to remove Telnet exposure where it is not needed and use SSH for remote terminal access. Filtering traffic can reduce what reaches a service, but it is not a substitute for disabling Telnet, securing the device, or replacing unsupported equipment.

Quick Recap

Bestseller No. 3
Ubiquiti Unifi Security Appliance (USG), Single,White
Ubiquiti Unifi Security Appliance (USG), Single,White
Integration with Unifi Controller. Powerful firewall performance; Convenient VLAN support. QoS for enterprise VoIP
$184.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.