Hundreds of thousands of (forgotten) IoT and OT devices are exposed to the internet
The “set and forget” approach — where you buy a device, set it up, and then forget all about it — could have serious consequences, including risks to human life. A new research result from DTU Compute shows that thousands of IT systems worldwide can easily be exposed to cyber-attacks. Review the IT systems of all connected devices and only connect them to the internet if it is necessary, the researchers advise.
Smart City with IoT and OT systems. Graphics: Copilot
Monday 29 June 2026
Hanne Kokkegård
If hackers gain access to the air conditioning system in a building, they can, with just a few clicks, suffocate those inside the building. You might think that such systems are, of course, protected against malicious cyber-attacks. Two cybersecurity researchers at DTU Compute thought so too — but they were proven wrong.
When they began investigating IT security and screened the Internet broadly worldwide for vulnerable Operational Technology (OT), which is used in manufacturing and critical infrastructure (e.g., healthcare, city automation, and energy systems), it became clear that numerous IT systems were not secured against hacking.
“At the beginning, we believed it would be impossible to find critical infrastructure exposed to the internet. But we found examples such as oil pipelines in Mexico that were open and exposed to the internet, with everybody just being able to change the pressure and the valves of those devices remotely from home,” says Ricardo Yaben, Postdoc at DTU Compute.
Even though attackers have compromised millions of such devices over the years, exploiting their lack of management and weak cybersecurity, there are still plenty of vulnerable IT systems.
“We found thousands and thousands of building automation devices — HVAC systems, illumination, gas, and waste management controllers, etc. — and large-scale automation devices that were completely accessible. That was very surprising — especially because these are systems we assume are highly regulated and secure. But they are not, and they will probably remain in that condition for many years.”
Many older systems were not designed with cybersecurity in mind
Together with his colleague in the section for Cybersecurity Engineering at DTU Compute Professor Emmanouil Vasilomanolikis, Ricardo Yaben has found cybersecurity issues of neglected, obsolete, and abandoned IoT (mainly used by consumers at home, such as coffee machines or home assistants and OT devices all over the world. It is about the devices themselves — especially the ones controlling larger systems.
In total, ~7K OT devices, and ~65K IoT devices remain vulnerable in 2025. These numbers fluctuate a lot though.
“The reasons vary across organisations, but many of these systems were never designed with cybersecurity in mind. There was no perceived need for it in the beginning, whether it was a smart fridge or a water treatment plant, they thought there was nothing to gain from hacking such devices and systems, especially in critical infrastructure, which requires deep understanding of OT systems, a novelty knowledge even among current specialists and engineers. There were even assumptions – like in international conventions – that such systems would not be targeted. But that is not respected anymore,” Ricardo Yaben says.
Normally, the weakness relates to a very common problem known as “set and forget”. You buy a device, you set it up, and then forget about it. Because it works, people assume it will either update itself or someone else will take care of it. And people only return to it when it stops working.
For example, wind turbines. They are placed in remote locations, such as offshore, and they are connected to the internet for monitoring. But you do not manually check them every day. They are expected to run for many years without intervention. The same applies to building automation — lighting, heating, ventilation systems, and so on.
The researchers call these systems digital ghost ships. A ghost ship is a ship still at sea but without a crew. These devices are similar: they are still online, but nobody is managing them.
Vulnerabilities are visible from the outside
To understand how the researchers performed the Internet-wide scanning, think about a radar system. Ricardo Yaben and Emmanouil Vasilomanolakis have sent out probes across the Internet, and devices that respond indicate that they are active. Then the two DTU researchers send further queries to identify what kind of systems they are.
“Vulnerabilities are visible from the outside, we don’t need to enter the systems. It is like having a door without a lock — you can tell it is insecure just by looking at it,” Ricardo Yaben says.
He and Emmanouil Vasilomanolakis looked at open ports — essentially the “doors” of a system. Different services respond to different ports, so by probing them they can infer whether a device is, for example, a PLC (a small industrial computer used to control and automate machines and technical systems), a building system, or something else.
“Our visibility depends on which services we scan. Out of thousands of possible ports, we only probe a subset. That means we may not see everything. But many of them expose what we call a banner. This is a greeting message that is part of the communication protocol. It often contains information such as the software or firmware version. From that, we can infer how outdated the device is. By scanning the entire internet and repeating the scans over time, we could observe changes – for example, whether devices were updated or remained the same,” Ricardo Yaben explains.
The text continues below the factbox.
Advice
How to secure your systems
How should you react according to the new knowledge about exposed OT and IoT systems? The advice builds up depending on whether you are an organisation or an individual.
For individuals:
Change default configurations and credentials
Disable unnecessary internet connections
Be aware that many devices communicate online even if it is not obvious
And for organisations:
Use VPNs for remote access
Implement secure authentication and access control (e.g., bearer token authentication with role-based access control), limiting access to only what is required
Enable encryption (e.g., DTLS) and rotate certificates before they expire
Monitor exposed systems continuously
Use Cyber Threat Intelligence (CTI) services to identify ongoing threats
Source: DTU
Relatively small numbers in Denmark, but…
The research showed a big difference between IoT and OT. IoT devices tend to go online and offline frequently and are harder to track over time. OT devices, however, are designed to remain online almost constantly — close to 100% uptime.
In the study, about 50% of vulnerable OT devices remained unchanged from one year to the next, which suggests they may be abandoned. For IoT devices, the number was closer to 20%.
The United States shows the largest exposure, partly because of its size and differences in regulation and behaviour.
“In Denmark, the number of findings is relatively small, which is good. Most of what we found were building automation systems, such as heating systems – often in hotels. But even one vulnerable OT system can be critical — for example, a railway system.”
In contact with relevant organisations
Naturally, a significant responsibility rests on researchers when they possess such important knowledge.
During the work, they have collected insights and feedback from both researchers and industry, and the results have been published in conferences and journals.
The DTU researchers also work with CERT organisations, such as DKCERT; expert teams that monitor cyber threats and help organisations respond to and mitigate cyber-attacks. Additionally, they conduct ethical disclosure campaigns, where they inform organisations about vulnerabilities and suggest ways to mitigate them.
“In cybersecurity, we use threat models, but in simple terms: if a system is accessible from the internet without authentication or access control, it is a risk. The key message is that many devices remain connected to the internet while staying vulnerable over long periods,” says Ricardo Yaben.
He and Emmanouil Vasilomanolakis have been working on this line of research for a couple of years now. The new paper, for example, is an extension of their previous work that received best paper awards.
Facts
About the research
Paper: Digital ghost ships: abandoned, neglected, and obsolete IoT & OT devices exposed to the Internet
Authors: Ricardo Yaben and Emmanouil Vasilomanolakis, Technical University of Denmark
The research focuses on identifying Digital Ghost Ships (DGSs) using common scanning tools to find indicators of security misconfigurations and misuse.
Moreover, Ricardo Yaben and Emmanouil Vasilomanolakis compared two Internet-wide scans conducted one year apart, focusing on security issues in eight IoT and OT protocols: MQTT, CoAP, XMPP, Modbus, OPC UA, RTPS, DNP3, and BACnet.
During the first scan (S1) they found 675,896 DGSs, and 75,007 during their second scan (S2).
Lastly, they examined the IP reputation of the vulnerable devices and found that 7,424 (S1) and 792 (S2) DGSs were reported at least once.