A 2017 Trend Micro study reported that Los Angeles had the most Shodan-discoverable internet-facing assets among the ten largest U.S. cities it examined, at approximately four million. But the findings are a month-long snapshot of visible devices—not a current city ranking, a count of successful attacks, or a comprehensive measure of cybersecurity. The available reporting does not establish the complete ten-city order.
What the 2017 study measured
Trend Micro analyzed a month of results from Shodan, a search engine that indexes devices and services reachable on the internet. Its comparison covered the ten largest U.S. cities by population and counted internet-facing assets that could be discovered through that data. Dark Reading’s account of the study was published on February 15, 2017: Dark Reading’s report. Trend Micro’s follow-on page discusses the study’s wider sector coverage: Trend Micro’s study page.
Discoverability indicates that an asset was visible or accessible from the public internet under the study’s method. It does not establish that attackers had compromised it, that every counted asset was vulnerable, or that the city government owned or managed it. Nor is an internet-wide scan a full security audit of a city’s residents, businesses, institutions, or public services.
What the study reported about cities
Los Angeles led the reported overall comparison
Los Angeles was reported to have approximately four million exposed devices, the highest overall exposed-asset total among the cities studied. This is the study’s reported figure, not a current count.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
New York ranked seventh, despite its population
New York ranked seventh in overall exposed assets. The Dark Reading account said New York had nearly four times Houston’s population but 3.78 times fewer exposed cyber assets. That comparison concerns raw observed totals; it does not establish per-person risk or show that one city was more secure in every respect.
Different cities led different device categories
The article identified category leaders that differ from the overall result:
- Houston and Chicago had the most exposed webcams.
- San Jose led in exposed PBX phones and devices using SNMP or Telnet.
- Phoenix led in exposed network-attached storage (NAS) devices.
- Chicago led in exposed medical databases.
A city leading one device category is not necessarily the city with the highest overall exposed-asset total.
The available sources do not show a complete top ten
The retrieved reporting and Trend Micro page provide selected rankings and comparisons, but not the full city-by-city ordering or complete underlying count table. It is therefore not possible to responsibly name or rank all ten cities from these findings alone.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
Which exposed assets stood out
Dark Reading reported that firewall administrative interfaces were the most frequently found exposure across the cities assessed. Other commonly identified assets included webcams, routers and wireless access points, printers, and PBX phones. The study also drew attention to exposed databases, including medical databases in its city-category comparison.
Trend Micro researcher Numaan Huq described the stakes of database exposure: “Databases are a huge gap in security for companies where, if an attacker gets into the database, then you’re basically looking at them consuming everything without too much effort,” Huq told Dark Reading.
Rank #4
Why internet exposure can matter—and what it does not prove
An internet-facing device can give an attacker a point to investigate or attempt to access. The study described potential consequences such as data theft or exposure, moving laterally from an initial foothold toward more valuable systems, and using compromised devices in distributed denial-of-service (DDoS) attacks. These are risks associated with exposure, not outcomes shown for every asset in the count. A device being discoverable does not by itself prove it was exploited.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Why the findings should be read as historical
The reported results came from a one-month Shodan snapshot in 2017. Devices, network configurations, and internet exposure change over time, so those findings cannot tell readers which U.S. cities are most exposed today. They also should not be treated as a city cybersecurity score: the study measured discoverable assets, not the effectiveness of every organization’s defenses or the frequency of successful attacks.
Recommended Free Tools
Best Value
Trend Micro’s follow-on page also records an erratum: Lafayette, Indiana was mistakenly named in the article and research paper; the correction is Lafayette, Louisiana. That correction is a reminder to interpret the historical reporting carefully, rather than to infer an unsupported city ranking.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

