Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Half of the 6 Million Internet-Facing FTP Servers Lack Encryption
    Cybersecurity

    Half of the 6 Million Internet-Facing FTP Servers Lack Encryption

    adminBy adminApril 20, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    File transfer attack
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Approximately 6 million internet-accessible systems are using FTP today, and almost half of them do not use encryption, a fresh Censys report shows.

    In use for more than half a century, FTP uses a client-server model architecture to facilitate the transfer of files and folders between computers.

    Unlike modern protocols, however, FTP transmits data unencrypted and has been deemed insecure for years. Its continued use exposes enterprises and end users alike to avoidable risks.

    The number of hosts running an internet-facing FTP service has dropped by 40% since 2024 (from 10.1 million to 5.94 million), but the protocol still accounts for 2.72% of all internet-visible systems, Censys says.

    Also alarming is the fact that 2.45 million of the observed FTP services show no evidence of encryption. With no observed TLS handshake, these servers either lack support for encryption, were not upgraded, or did not complete a handshake during Censys’ scanning.

    “This is not a guarantee that all 2.45 million transmit files and credentials in cleartext, but it is the population with no observed evidence of encryption,” the internet intelligence provider notes.

    Advertisement. Scroll to continue reading.

    Most of the FTP-visible hosts are in the US (1.2 million). China (866,000), Germany (467,000), Hong Kong (415,000), Japan (366,000), and France (343,000) also house significant numbers of such systems.

    Some of the largest hosting and broadband providers worldwide account for the most FTP hosts, including China Unicom’s CHINA169 (405,000), Alibaba (227,000), OVH (177,000), Hetzner (138,000), KDDI Web Communications (127,000), and GoDaddy (126,000).

    Censys’ analysis of the FTP hosts revealed that Pure-FTPd is the most commonly running server, accounting for roughly 1.99 million services. It is followed by ProFTPD with 812,000 services and vsftpd (the standard FTP daemon in most Linux distributions) with 379,000 services.

    Microsoft’s legacy web and FTP server platform, IIS (Internet Information Services), accounts for 259,000 services. All Windows Server instances with the FTP role enabled would run IIS FTP by default, and more than 150,000 of these services have never had encryption set up, Censys says.

    In fact, of the 2.45 million FTP hosts that lack encryption, 994,000 services do not implement AUTH TLS on the scanned port, 813,000 ask for a password before establishing an encrypted channel, and more than 170,000 do not have explicit TLS support.

    “The geography, ASN distribution, and server technology mix in this dataset all point toward the conclusion that most Internet-facing FTP configurations are a byproduct of commodity hosting and broadband defaults,” Censys notes.

    Organizations are encouraged to either completely remove FTP from their environments or transition to more secure alternatives, such as SFTP (SSH File Transfer Protocol) and FTPS, which offer encrypted file transfer capabilities and have broad client compatibility.

    “For most use cases, FTP can be replaced without significant disruption. If FTP must remain, enabling Explicit TLS is a configuration change, not a protocol upgrade, and both Pure-FTPd and vsftpd support it natively,” Censys notes.

    Related: Millions of Internet Hosts Vulnerable to Attacks Due to Tunneling Protocol Flaws

    Related: BlastRADIUS Attack Exposes Critical Flaw in 30-Year-Old RADIUS Protocol

    Related: Thousands of Websites Hijacked Using Compromised FTP Credentials

    Related: Up to 25% of Internet-Exposed ICS Are Honeypots: Researchers

    encryption FTP InternetFacing Lack Million Servers
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleHow EU organizations can turn sovereign cloud theory into action
    Next Article How to Build a Product Quiz in WordPress That Recommends & Converts
    admin
    • Website

    Related Posts

    Encryption Consulting launches CertSecure Manager v3.3 with zero-touch certificate renewals

    May 20, 2026

    GitHub confirms breach of 3,800 repos via malicious VSCode extension

    May 20, 2026

    Grafana GitHub Breach Exposes Source Code via TanStack npm Attack

    May 20, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Google‘s AI search optimization guide: what to do next

    June 4, 2026

    Google Must Let Websites Opt Out Of AI Search Features In UK

    June 4, 2026

    [NEW] How to Use Meta’s WhatsApp AI Agent in WordPress

    June 4, 2026

    CompTIA debuts AutoOps+ certification | Network World

    June 4, 2026
    Categories
    • Blogging (90)
    • Cybersecurity (1,955)
    • Privacy & Online Earning (236)
    • SEO & Digital Marketing (1,372)
    • Tech Tools & Mobile / Apps (1,796)
    • WiFi / Internet & Networking (332)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Google‘s AI search optimization guide: what to do next

    June 4, 2026

    Google Must Let Websites Opt Out Of AI Search Features In UK

    June 4, 2026

    [NEW] How to Use Meta’s WhatsApp AI Agent in WordPress

    June 4, 2026
    Most Popular
    • Google‘s AI search optimization guide: what to do next
    • Google Must Let Websites Opt Out Of AI Search Features In UK
    • [NEW] How to Use Meta’s WhatsApp AI Agent in WordPress
    • CompTIA debuts AutoOps+ certification | Network World
    • Your #1 competitive advantage in Google Ads: Customer Match
    • 9 ways to improve SEO rankings and traffic
    • Why Users Are Fleeing To AI-Free Search & What It Means For SEO
    • Is the iPhone 16e the Best Value Upgrade?
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.