Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A 2017 Trend Micro study reported that Los Angeles had the most Shodan-discoverable internet-facing assets among the ten largest U.S. cities it examined, at approximately four million. But the findings are a month-long snapshot of visible devices—not a current city ranking, a count of successful attacks, or a comprehensive measure of cybersecurity. The available reporting does not establish the complete ten-city order.

What the 2017 study measured

Trend Micro analyzed a month of results from Shodan, a search engine that indexes devices and services reachable on the internet. Its comparison covered the ten largest U.S. cities by population and counted internet-facing assets that could be discovered through that data. Dark Reading’s account of the study was published on February 15, 2017: Dark Reading’s report. Trend Micro’s follow-on page discusses the study’s wider sector coverage: Trend Micro’s study page.

Discoverability indicates that an asset was visible or accessible from the public internet under the study’s method. It does not establish that attackers had compromised it, that every counted asset was vulnerable, or that the city government owned or managed it. Nor is an internet-wide scan a full security audit of a city’s residents, businesses, institutions, or public services.

What the study reported about cities

Los Angeles led the reported overall comparison

Los Angeles was reported to have approximately four million exposed devices, the highest overall exposed-asset total among the cities studied. This is the study’s reported figure, not a current count.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

New York ranked seventh, despite its population

New York ranked seventh in overall exposed assets. The Dark Reading account said New York had nearly four times Houston’s population but 3.78 times fewer exposed cyber assets. That comparison concerns raw observed totals; it does not establish per-person risk or show that one city was more secure in every respect.

Different cities led different device categories

The article identified category leaders that differ from the overall result:

  • Houston and Chicago had the most exposed webcams.
  • San Jose led in exposed PBX phones and devices using SNMP or Telnet.
  • Phoenix led in exposed network-attached storage (NAS) devices.
  • Chicago led in exposed medical databases.

A city leading one device category is not necessarily the city with the highest overall exposed-asset total.

The available sources do not show a complete top ten

The retrieved reporting and Trend Micro page provide selected rankings and comparisons, but not the full city-by-city ordering or complete underlying count table. It is therefore not possible to responsibly name or rank all ten cities from these findings alone.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which exposed assets stood out

Dark Reading reported that firewall administrative interfaces were the most frequently found exposure across the cities assessed. Other commonly identified assets included webcams, routers and wireless access points, printers, and PBX phones. The study also drew attention to exposed databases, including medical databases in its city-category comparison.

Trend Micro researcher Numaan Huq described the stakes of database exposure: “Databases are a huge gap in security for companies where, if an attacker gets into the database, then you’re basically looking at them consuming everything without too much effort,” Huq told Dark Reading.

Why internet exposure can matter—and what it does not prove

An internet-facing device can give an attacker a point to investigate or attempt to access. The study described potential consequences such as data theft or exposure, moving laterally from an initial foothold toward more valuable systems, and using compromised devices in distributed denial-of-service (DDoS) attacks. These are risks associated with exposure, not outcomes shown for every asset in the count. A device being discoverable does not by itself prove it was exploited.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why the findings should be read as historical

The reported results came from a one-month Shodan snapshot in 2017. Devices, network configurations, and internet exposure change over time, so those findings cannot tell readers which U.S. cities are most exposed today. They also should not be treated as a city cybersecurity score: the study measured discoverable assets, not the effectiveness of every organization’s defenses or the frequency of successful attacks.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Trend Micro’s follow-on page also records an erratum: Lafayette, Indiana was mistakenly named in the article and research paper; the correction is Lafayette, Louisiana. That correction is a reminder to interpret the historical reporting carefully, rather than to infer an unsupported city ranking.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.