There were 21.1 billion active IoT devices online at the end of 2025, and attackers treat every one as a way in. IoT malware attacks rose 124% in a single year, and the largest distributed denial-of-service attack ever recorded was fired from a botnet of just 13,000 hijacked devices. This is what the current IoT security statistics show, and what they mean for the networks businesses actually run.
The core reason IoT security keeps getting harder is arithmetic. Every year there are more connected devices, and each one adds surface area an attacker can probe. IoT Analytics counted 21.1 billion active IoT devices worldwide at the end of 2025, a 14% increase over the year before, and it expects the base to keep climbing through the decade.

Put on a timeline, the growth curve is steep and shows no sign of flattening. The device base roughly doubles across the current decade.
Active IoT Devices Worldwide (billions)
Most of these devices were never designed with security as a priority. Cameras, sensors, printers, smart TVs, building controls, and medical equipment ship to do one job cheaply, and security is an afterthought bolted on later, if at all. That is why device growth translates so directly into risk: the population of internet-facing hardware is expanding far faster than the discipline of managing it. Businesses that already track laptops and servers often have no inventory at all of the connected devices sitting on the same network, which is exactly the visibility gap that turns a single weak camera into a doorway. Our connected-device management guides cover how to bring that inventory under control.
Source: IoT Analytics, Number of Connected IoT Devices
Get a free security audit of your connected devices
Attackers have noticed the growing device population, and the attack telemetry proves it. SonicWall, which monitors a global network of sensors, recorded a 124% year-over-year increase in IoT malware attacks, one of the sharpest jumps of any threat category it tracks. IP cameras were hit especially hard.
Routers sit at the center of the problem. Zscaler’s ThreatLabz research found that routers absorb more than 75% of observed IoT attacks, because a compromised router is both a botnet recruit and a foothold for moving deeper into a network. Manufacturing and transportation are the most-targeted sectors, each accounting for 20.2% of IoT malware attacks, or more than 40% combined.
| Metric | Figure | Source |
|---|---|---|
| IoT malware attacks, year-over-year change | +124% | SonicWall |
| Attacks blocked on IP cameras (2024) | 17 million+ | SonicWall |
| Total malware attacks across global sensors | 6.06 billion | SonicWall |
| Router share of observed IoT attacks | 75%+ | Zscaler ThreatLabz |
| Manufacturing share of IoT malware attacks | 20.2% | Zscaler ThreatLabz |
| Transportation share of IoT malware attacks | 20.2% | Zscaler ThreatLabz |
Two Tier 1 datasets tell the real story when read together. IoT devices grew 14% year over year (IoT Analytics), while IoT malware attacks grew 124% over a comparable period (SonicWall).
Formula: 124% attack growth divided by 14% device growth equals roughly 8.9 times.
In other words, attack volume is climbing nearly nine times faster than the number of devices. The threat is not simply that there are more devices; it is that each device is being targeted far more aggressively than the year before. Calculation and interpretation original to CNiC Solutions.
For a wider view of how these attacks fit the overall threat landscape, see our broader cybersecurity statistics, and for the specific exposure smaller firms face, our data on attacks against small businesses.
Source: SonicWall 2025 Cyber Threat Report | Zscaler ThreatLabz Mobile, IoT, and OT Report
See how managed IT keeps device fleets patched and monitored
The payoff for attackers who compromise IoT devices at scale is the botnet: a fleet of hijacked hardware that can be pointed at any target on command. Botnets are why a $30 camera matters to a business that has never heard of it, because that camera can help take down someone else’s network, or its own. The malware families behind these botnets are remarkably concentrated.
The record-setting attack is worth sitting with. In October 2024, Cloudflare blocked a 5.6 terabit-per-second DDoS attack that lasted only 80 seconds and originated from about 13,000 IoT devices running a Mirai variant. It broke the previous record, a 3.8 Tbps attack, set weeks earlier. In the fourth quarter of 2024 alone, the number of attacks exceeding 1 Tbps grew 1,885% over the prior quarter. Volume like that does not require a sophisticated adversary; it requires a lot of poorly secured devices, which the world now has in abundance.
| Botnet and DDoS Metric | Figure | Source |
|---|---|---|
| Largest DDoS attack on record | 5.6 Tbps | Cloudflare |
| IoT devices in the record botnet | ~13,000 | Cloudflare |
| Duration of the record attack | 80 seconds | Cloudflare |
| Prior DDoS record (same period) | 3.8 Tbps | Cloudflare |
| Total DDoS attacks mitigated (2024) | 21.3 million | Cloudflare |
| Growth in attacks over 1 Tbps (Q4 2024) | +1,885% quarter over quarter | Cloudflare |
For most businesses the risk runs in two directions. Their own devices can be conscripted into a botnet that attacks others, creating liability and bandwidth costs, and their own services can be knocked offline by a botnet aimed at them. Both scenarios point to the same defenses: keep devices patched, isolate them from critical systems, and have a recovery plan for when something does go down.
Source: Cloudflare DDoS Threat Report, Q4 2024
Build a backup and recovery plan for attack downtime
Attack volume tells you how hard the door is being pushed. Vulnerability data tells you where the door is weakest. Forescout’s fifth annual Riskiest Connected Devices report, drawn from millions of devices, found that network infrastructure, and routers in particular, has overtaken traditional endpoints as the riskiest category on business networks.
It is tempting to file IoT security under doorbell cameras and smart speakers. The data says otherwise. The riskiest connected devices on business networks are routers, IP cameras, printers, and building controls, and in healthcare they are connected medical devices. Nozomi Networks analyzed more than 500,000 wireless networks and found only 6% were adequately protected against basic deauthentication attacks, with 68% running without Management Frame Protection. These are the networks businesses run every day, not hobbyist gadgets.

The scale of the underlying weakness has been documented for years. Palo Alto Networks’ Unit 42 published a landmark IoT threat report in 2020 that analyzed 1.2 million devices. Its findings became the baseline the industry still references, and while the report is now several years old, the structural problems it identified, unencrypted traffic and flat networks that let malware spread, remain common today.
Unit 42 IoT Threat Report, 2020 Baseline (share of IoT devices or networks)
The pattern across every current source is consistent: the devices that route and connect a network are more dangerous than the laptops sitting on it, because a weakness in the plumbing exposes everything downstream. Segmenting IoT devices onto their own network, changing default credentials, and patching firmware on a schedule address the majority of what these reports flag.
Source: Forescout Riskiest Connected Devices of 2025 | Palo Alto Networks Unit 42 IoT Threat Report (2020 baseline)
Bring your network infrastructure under active management
IoT risk is not spread evenly. It concentrates in sectors that run large fleets of specialized connected equipment, and healthcare is the clearest example. Claroty’s Team82 analyzed 2.25 million connected medical devices across 351 healthcare organizations and found the exposure is close to universal.

Manufacturing and transportation top the list for raw attack volume, while retail carries the riskiest devices on average, followed by financial services, government, healthcare, and manufacturing, according to Forescout. The common thread is operational technology and connected devices that cannot easily be taken offline to patch, which is precisely what makes them attractive targets.
| Sector Finding | Figure | Source |
|---|---|---|
| Healthcare orgs with high-risk IoMT devices | 89% | Claroty Team82 |
| CISA KEVs found on healthcare networks | 63% | Claroty Team82 |
| Manufacturing share of IoT malware attacks | 20.2% | Zscaler ThreatLabz |
| Transportation share of IoT malware attacks | 20.2% | Zscaler ThreatLabz |
| Riskiest sector by average device risk | Retail | Forescout |
| Critical manufacturing share of ICS advisory CVEs | 75% | Nozomi Networks |
For regulated industries, the stakes go beyond downtime. A breached connected device in a healthcare, legal, financial, or accounting environment can trigger reporting obligations and penalties under frameworks such as HIPAA, PCI-DSS, and SOC 2. That is where a strategic view of device risk, not just a firewall, becomes a compliance requirement rather than a nice-to-have.
Source: Claroty Team82, State of CPS Security: Healthcare Exposures 2025
Get a Virtual CIO to map device risk to compliance
Spending and regulation are both catching up to the threat, if slowly. The IoT security market is forecast to nearly triple across the second half of the decade as organizations move device security from an afterthought to a line item.
Three regulatory regimes are pushing manufacturers and operators toward secure-by-default devices. The direction of travel is the same everywhere: no more universal default passwords, mandatory vulnerability reporting, and clear support timelines.
| Regulation | Region | Status | Key Point |
|---|---|---|---|
| Cyber Resilience Act | European Union | Full enforcement December 2027 | Fines up to 15M euros or 2.5% of global turnover; mandatory vulnerability reporting from September 2026 |
| PSTI Act | United Kingdom | Enforceable since April 2024 | Bans universal default passwords on consumer connectable products |
| Cyber Trust Mark | United States | Launched 2025 (voluntary) | FCC label to NIST criteria; required for consumer IoT sold to the US government by January 2027 |
Regulation raises the floor for new devices, but it does nothing for the billions already deployed. The devices on a network today were largely built before these rules existed, which means the responsibility for securing them stays with the organizations that run them. That is the gap between what the market is buying and what the threat data demands.
Source: MarketsandMarkets IoT Security Market Forecast | European Commission, Cyber Resilience Act | FCC US Cyber Trust Mark
The statistics point to a short list of defenses that address most of what these reports flag. None of them require ripping out hardware, and most can be done in an afternoon:
For businesses in regulated fields, these steps are not just good hygiene; they are the difference between a contained incident and a reportable breach.
The full set of IoT security statistics from this report, with the primary source and reference year for each. Journalists and researchers are welcome to cite this table with attribution to CNiC Solutions and the original source named in each row.
| Statistic | Figure | Source | Year |
|---|---|---|---|
| Active IoT devices worldwide | 21.1 billion | IoT Analytics | 2025 |
| IoT device growth, year over year | +14% | IoT Analytics | 2025 |
| Active IoT devices worldwide | 18.5 billion | IoT Analytics | 2024 |
| Forecast active IoT devices | 39 billion | IoT Analytics | 2030 |
| IoT malware attacks, year over year | +124% | SonicWall | 2025 |
| Attacks blocked on IP cameras | 17 million+ | SonicWall | 2024 |
| Total malware attacks across global sensors | 6.06 billion | SonicWall | 2025 |
| Botnet share of malicious IoT payloads (Mirai, Mozi, Gafgyt) | 75% | Zscaler ThreatLabz | 2025 |
| Router share of observed IoT attacks | 75%+ | Zscaler ThreatLabz | 2025 |
| Largest DDoS attack on record | 5.6 Tbps | Cloudflare | 2024 |
| IoT devices in the record DDoS botnet | ~13,000 | Cloudflare | 2024 |
| DDoS attacks mitigated | 21.3 million | Cloudflare | 2024 |
| Routers as share of devices with most dangerous vulnerabilities | 50%+ | Forescout | 2025 |
| Year-over-year rise in average device risk | +15% | Forescout | 2025 |
| Wireless networks adequately protected against deauth attacks | 6% | Nozomi Networks | 2025 |
| Healthcare orgs with high-risk IoMT devices | 89% | Claroty Team82 | 2025 |
| CISA KEVs found on healthcare networks | 63% | Claroty Team82 | 2025 |
| IoT security market size | $28.67 billion | MarketsandMarkets | 2025 |
| Forecast IoT security market size | $80.30 billion | MarketsandMarkets | 2031 |
| IoT device traffic unencrypted (historical baseline) | 98% | Palo Alto Unit 42 | 2020 |
Every statistic in this report traces to a Tier 1 primary source: a research institution, security vendor with disclosed telemetry, government agency, or major market analyst. No figure is drawn from a blog post citing another blog post, and no statistic is estimated or invented. Where a figure is older than the current reporting cycle, it is labeled as a historical baseline in context.
Primary sources referenced:
You are welcome to cite any statistic or the summary table above in your own reporting, provided you attribute it to CNiC Solutions and the original primary source named alongside the figure. The CNiC Solutions Analysis box (attack growth versus device growth) is original analysis derived from IoT Analytics and SonicWall data and should be attributed to CNiC Solutions.
The takeaway from every dataset points the same way: the number of connected devices is growing fast, the attacks against them are growing faster, and the weakest links are the routers, cameras, and specialized devices that most organizations do not actively manage. The devices are already on your network. The question is whether anyone is watching them. A free security audit is the fastest way to find out what is connected and where the gaps are.
Most IT reporting drowns leaders in numbers that never answer the only question that matters: is…
The most effective IT cost reduction strategies start with eliminating waste you are already paying for,…
Insider threats are no longer a rounding error in the security budget. In 2026, the average…
Most breaches do not start with a genius hacker breaking through a firewall. They start with…