Identity infrastructure exposed to the internet

Directory servers, Kerberos, remote desktop and identity providers are meant to sit behind the edge. These are the ones that don't: a daily count of identity systems that internet-wide scanners can reach right now, worldwide and in the UK.

Updated 04 Oct 2026, 23:17 (UK time) · Source: Shodan

LDAP directory servers (port 389)

563,034worldwide
25,480 in the UK

Directory servers answering the internet invite password spraying, anonymous binds and enumeration of every account and group.

Most exposed: CN 207,642 · SG 154,074 · US 53,978
port:389

Kerberos KDCs (port 88)

710,975worldwide
19,873 in the UK

An exposed KDC lets anyone request tickets: the starting point for AS-REP roasting and offline password cracking.

Most exposed: SG 161,156 · US 105,332 · CN 100,146
port:88

Remote Desktop (port 3389)

2,258,280worldwide
87,776 in the UK

Remote Desktop on the open internet is still the most common way into a network: credential stuffing, then a live session.

Most exposed: CN 726,078 · US 401,258 · SG 195,317
port:3389

SMB file sharing (port 445)

829,560worldwide
41,386 in the UK

SMB facing the internet exposes NTLM authentication and file shares to relay and brute-force attacks.

Most exposed: US 163,385 · PK 82,147 · DE 57,296
port:445

Keycloak identity servers

26,160worldwide
728 in the UK

Identity provider admin and login pages in the open; fine for login, a problem when the admin console answers too.

Most exposed: US 8,703 · DE 4,164 · FR 1,565
http.title:"Keycloak"

Outlook / Exchange web sign-in pages

64,287worldwide
2,432 in the UK

Outlook web sign-in pages are prime targets for password spraying and real-time phishing proxies.

Most exposed: DE 14,920 · US 12,882 · FR 2,897
http.title:"Outlook"

Kubernetes API servers (port 6443)

53,129worldwide
1,204 in the UK

A reachable Kubernetes API is one leaked service-account token away from the whole cluster.

Most exposed: US 13,642 · CN 7,569 · DE 7,461
port:6443 product:"Kubernetes"

Jenkins dashboards open to the internet

1,597worldwide
61 in the UK

Build servers hold deployment keys and cloud credentials: non-human identities with real power.

Most exposed: US 441 · CN 397 · DE 139
http.title:"Dashboard [Jenkins]"

How these numbers are made

Each figure is a Shodan count query, refreshed once a day: the number of internet-facing hosts Shodan's scanners last saw answering on that port or serving that page. A count is exposure, not compromise: some hosts are honeypots, research systems or deliberately public, and Shodan's view lags reality by days. Nothing on this page comes from scanning anyone; it reads what Shodan has already recorded.

The point is the pattern: identity systems that should only answer inside a network, or behind an identity-aware proxy, answering the whole internet. If one of these is yours, talk to me.