The Perimeter Now Includes Home Routers, Comcast Says

Estimated reading time: 5 minutes

Comcast Business counted 79.3 billion cybersecurity events in its 2026 threat report. The more telling findings sit deeper in its research, in hijacked home devices and stolen logins.

Seventy-nine billion is a number built for a headline.

Comcast Business counted 79.3 billion cybersecurity events across its security customers between March 2025 and February 2026. That works out to about 2,514 every second.

Comcast is careful about what the number means. Raw totals “measure the breadth of our visibility,” the report says, not confirmed attacks or successful compromises. The total more than doubled from last year because Comcast deployed more sensors to more customers.

Dig into the research behind the total, and a different picture emerges. Some of the infrastructure attackers depend on sits in ordinary homes.

Get The Cyber Insurance News Upload Delivered
Subscribe to our weekly newsletter!

Residential Proxy Networks In Homes And Offices

Residential proxy networks are large herds of hijacked consumer and business devices. Attackers route traffic through them so it arrives from addresses that look ordinary. That lets them slip past geo-blocking and IP reputation lists.

Comcast detected 3.7 billion proxy events over 12 months, excluding routine proxy and VPN traffic. Of those, 2.5 billion bounced through chains of devices to hide their source.

Operators build these networks from devices few people think about. They target unpatched gear and devices still using default passwords, such as low-cost security cameras. Some streaming boxes ship with the malware already installed, Comcast says.

Comcast’s Threat Research Lab helped expose one network at national scale. Six IP addresses led to roughly 750,000 addresses in homes and businesses, allegedly run by a Chinese provider called IPidea. Google dismantled its infrastructure under a court order in January. The network was running again within two weeks. Comcast’s account cites reporting by The Wall Street Journal.

See also  10 Cybersecurity Predictions: SpyCloud Identifies Identity Threats That Will Dominate 2026

From The Living Room To The Corporate Network

The report traces how a hijacked home device becomes a business problem. An attacker who buys access to one of these residential proxy networks can reach other devices behind the same firewall. From an infected camera, the attacker can move to a phone on the same WiFi. If that phone joins a corporate network, the exposure travels with it.

Few security programs map those devices. “Cyber risk does not respect those boundaries,” said Amit Verma, chief technology officer of Comcast Business.

Residential proxy networks also blur attribution. Comcast’s report, again citing The Wall Street Journal, notes a joint warning in April from agencies in nine countries. They said Chinese state-sponsored operators were routing through hacked consumer devices to frustrate attribution. For carriers with state-backed attack exclusions, attribution carries weight.

Identity-Based Attacks Log In Rather Than Break In

“Attackers have stopped needing to break in,” said Noopur Davis, Comcast’s chief information security and product privacy officer. Attackers arrive with stolen credentials and move through the network the way an employee would, she said.

Phishing and drive-by compromise made up 59% of the events Comcast recorded. Comcast logged 5.8 million events tied to browser session hijacking and extension abuse. Malicious browser extensions accounted for 95.1% of them.

The report also flags an inventory problem with non-human identities. APIs, service accounts, and AI agents each need permissions, and each widens the identity attack surface.

Recent reporting points the same way. Proofpoint documented a phishing kit that passes standard MFA and captures session cookies. Nudge Security’s Russell Spitler described approved apps connecting to AI agents and other tools after sign-off.

See also  Cybersecurity Incidents Surge As Identity Attacks Dominate 2026 - Sophos Report

Attack Steps That Travel Together

Comcast analysts tested 91 possible pairings of attacker tactics. Nine occurred together far more often than chance and passed every statistical test the team applied.

Attacker tactic pairings that appear together more often than chance. Source: Comcast Business 2026 Cybersecurity Threat Report.

Reconnaissance and network discovery appeared together four times more often than chance. Stealing logins and moving through the network appeared together 2.18 times more often. Comcast presents each pairing as a cue for defenders. When one behavior appears, its partner is worth looking for.

The report also details a sequence Zscaler ThreatLabz documented last week. Attackers flood an inbox with spam, then pose as the IT help desk on Microsoft Teams. The target grants a remote session to fix the problem. Each step looks routine on its own.

The headline total shows how much Comcast can see. The research underneath shows where attackers hide: in devices no one in the business owns, manages, or monitors.

FAQ – Residential Proxy Networks

What did Comcast’s 2026 threat report find?

Comcast Business recorded 79.3 billion cybersecurity events across its security customers between March 2025 and February 2026. Comcast says the total reflects the breadth of its visibility, not confirmed attacks.

What are residential proxy networks?

Networks of hijacked home and business devices, such as cameras, routers and streaming boxes. Attackers route traffic through them so it appears to come from ordinary addresses.

How big is the problem?

Comcast detected 3.7 billion proxy events in 12 months, 2.5 billion of them bounced through several devices. Its research lab helped expose one network of roughly 750,000 addresses.

How can a home device affect a business?

An attacker can move from an infected camera to a phone on the same WiFi. If that phone joins a corporate network, the exposure goes with it.

See also  CyberCube and Aviva Partner: AI Boosts Cyber Threat Intelligence and Risk Management

Why does Comcast say attackers no longer need to break in?

Attackers increasingly use stolen credentials and hijacked sessions to log in as legitimate users. Phishing and drive-by compromise made up 59 percent of the events Comcast recorded.

Why does this matter for cyber insurance?

The devices involved often sit outside anything an insured owns or monitors, and state-linked use of these networks complicates the attribution that state-backed attack exclusions depend on.

Leave a Comment

×