Key Takeaways
- The share of homes under attack is shrinking relative to overall subscriber growth, even as the total volume of blocked threats rises.
- A tiny fraction of households (the top 1 %) absorbs 31‑52 % of all blocked threat traffic each month; in some regions a single home generated nearly three million blocked events in a year.
- Roughly 24‑26 % of homes face threats every month (the “chronic core”) and produce 58‑66 % of total blocked volume, while homes hit only once contribute less than 0.4 % of the threat load.
- Persistent risk is driven by always‑on, poorly maintained devices—Network Attached Storage (NAS) units, gaming consoles, and desktop computers—rather than smartphones.
- Established homes (connected before Aug 2025) show higher chronic attack rates (86 % persistently targeted for ≥ 3 months) than newly onboarded homes, yet new subscribers also arrive with compromised hardware, doubling their median monthly threats.
- Reporting based on mean values obscures reality: in North America the mean blocked threats per home per year is 447, whereas the median is only 88—a five‑fold gap caused by the chronic core.
- Threat patterns differ by region: North America shows the greatest overall growth but concentration; Europe exhibits genuine spread of attacks; Japan has a higher share of phishing and spam and a distinct device profile centered on consoles and laptops.
- Effective protection requires continuous, AI‑driven intelligence that tracks individual devices and homes over time, detects deviations from normal behavior, and triggers automated remediation—static rules or signature‑based tools cannot reveal the chronic core.
Overview of the Study
Plume’s research team analyzed threat activity detected and blocked across millions of subscriber homes in North America, Europe, Japan, and Southeast Asia from May 2025 through April 2026. The dataset encompasses a mix of malware, phishing, and spam events captured by the company’s AI‑native network intelligence platform. By examining a full year of activity, the study provides a longitudinal view of how threats evolve in residential networks and what patterns emerge when looking at both the breadth (number of homes attacked) and depth (volume of threats per home).
Challenging Conventional Wisdom
Traditional security thinking assumes that as an ISP’s subscriber base expands, the proportion of homes under attack will rise in tandem. Plume’s data contradicts this expectation. In two of the four deployments studied, the share of homes being attacked actually declined year‑over‑year while the total number of blocked threats increased. For example, in North America the attacked‑home count grew by 14 % while the subscriber fleet expanded by 26 %; in Japan attacked homes rose 19 % against a 26 % fleet increase. Consequently, the attack rate (attacked homes divided by total homes) is falling relative to fleet size, indicating that threats are not spreading uniformly across the network.
The Concentration Paradox
Despite a lower proportion of homes under attack, the blocked threats per 1,000 homes rose over the study period. This apparent paradox is explained by threat concentration: a shrinking group of homes is absorbing an ever‑larger share of malicious traffic. The platform continues to block these events, so the absolute number of blocked threats climbs even though fewer distinct households are experiencing attacks. The concentration effect means that the risk burden is being shouldered by a minority of users, a dynamic that traditional aggregate metrics fail to capture.
The Chronic Core: 1 % Absorbing Half the Threat
The most striking illustration of this concentration is the “chronic core.” Across all deployments, the heaviest 1 % of homes account for 31‑52 % of monthly blocked threat volume. In North America, that top percentile corresponds to roughly 34,600 homes; in Europe, just 3,200 homes generate more than half of all blocked threats. An extreme outlier—a single residence—recorded nearly 3 million blocked threat events over the twelve‑month window. This is not a statistical fluke but a structural reality: a small set of persistently targeted households drives the bulk of the threat load.
Persistent Exposure and the Always‑On Device Hypothesis
Further analysis shows that 24‑26 % of homes face threats every month throughout the study period, and this chronic group produces 58‑66 % of all blocked traffic. By contrast, homes that were compromised in only a single month contribute less than 0.4 % of total blocked volume, underscoring that the majority of risk stems from repeat exposure. The hardest‑hit households are not dominated by smartphones; instead, they feature an overrepresentation of Network Attached Storage (NAS) devices (2‑3× the network average), gaming consoles (up to 4× overrepresented in Japan), and desktop computers. These always‑on devices, often running outdated firmware and never remediated, become persistent footholds for attackers. Because they operate quietly in the background, subscribers rarely notice the compromise, and without continuous network‑level behavioral analysis, the threat remains invisible.
Established vs. New Subscriber Homes
The study also examined the difference between long‑standing and newly connected subscribers. Homes that joined the network before August 2025 exhibited a markedly higher chronic attack rate: 86 % were persistently targeted for three or more months. In contrast, only 70 % of newer homes showed similar persistence. This gap reflects the time needed for unpatched, always‑on devices to accumulate in a household. Nevertheless, new subscribers are not immune. Homes onboarded from September 2025 onward experienced a median of 21 blocked threats per active month, nearly double the 11 threats recorded for established homes. The threat arrives with the device—compromised hardware, outdated firmware, or unpatched systems—meaning the network inherits risk the moment a subscriber connects.
How Averages Mislead: Mean vs. Median
Reliance on average (mean) metrics can severely distort risk perception. In North America, the mean number of blocked threats per home per year is 447, while the median is only 88—a five‑fold disparity. This gap is driven entirely by the chronic core, whose extreme threat volumes pull the average upward. Security dashboards and ISP reporting that emphasize means therefore overstate the experience of the typical subscriber while obscuring the severity faced by the worst‑affected households. Decision‑makers who base resource allocation on such averages may underinvest in the deep, persistent protections needed for the chronic core.
Regional Variations in Threat Landscape
Threat dynamics are not uniform across geography. North America recorded the highest year‑over‑year growth in blocked threats (+35.6 %), yet fleet expansion outpaced this increase, suggesting that attacks are concentrating rather than spreading. Europe tells a different story: blocked threats rose 9.6 %, but attacked homes grew 23 % against a mere 7 % fleet increase—a 16‑point gap indicating genuine, fleet‑adjusted attack growth; here the threat is demonstrably spreading. Japan’s overall threat growth was modest at 1.4 %, but the attack composition diverged: phishing accounted for 22.8 % and spam for 16.8 % of blocked traffic, far higher than in other regions, while malware remained dominant. These regional nuances demand tailored detection priorities.
Device Fingerprints Vary by Market
The specific devices driving risk also differ by market. In North America, the most heavily targeted homes cluster around NAS storage and always‑on computing devices. In Japan, the worst‑affected residences show a disproportionate presence of gaming consoles and laptops. Consequently, a one‑size‑fits‑all detection strategy is ineffective; ISPs must adjust their monitoring focus to reflect local device‑based attack surfaces, whether that means scrutinizing NAS outbound traffic in NA or monitoring console‑to‑command‑control flows in Japan.
Implications for ISPs: Need for Living Intelligence
Overall, the findings reveal that the security challenge for ISPs has shifted from measuring breadth (percentage of homes touched) to addressing depth, persistence, and concentration. A small number of households, using long‑lived, poorly maintained devices as persistent footholds, absorb a disproportionate share of attacks month after month. Protecting these homes—and demonstrating that protection to subscribers—requires a living intelligence layer that continuously learns normal behavior for each device and home, detects deviations in real time, and triggers automated remediation. Static rules or signature‑based systems cannot reveal the chronic core; only AI‑fueled, longitudinal analysis across millions of homes can make the hidden risk visible, actionable, and ultimately protectable. By adopting such an approach, ISPs can move beyond misleading averages and deliver targeted, effective security that matches the true shape of modern home‑network threats.

