BGP hijack infecting networks caused by a comedy of errors that’s not funny at all

by | Sep 9, 2026 | Technology

BGP hijack infecting networks caused by a comedy of errors that’s not funny at all

An unknown group of attackers carried out a supply chain attack that compromised networks by hijacking Internet address space used by Softaculous, a UAE-based company that provides software installation and virtualization management platforms for hosting providers and data centers. The attackers exploited security gaps in the routing configuration maintained by hosting provider Hetzner Online, combined with weaknesses in how Softaculous managed digital certificates, to gain control of IP addresses that the company used to distribute software updates. Once in control of this address space, the attackers deployed malicious code disguised as legitimate updates to unsuspecting users.

The attack succeeded due to a series of compounding errors across multiple organizations. Softaculous failed to implement code signing, a standard security practice that would have allowed users to verify the authenticity of software updates before installation. Hetzner Online’s loose routing security configuration allowed attackers to repeatedly hijack the IP addresses over two separate periods spanning a 33-hour window. When Hetzner initially reclaimed the address space after 12 hours, the attacker simply performed the hijack again, and it took the company nearly 10 hours to respond the second time. During the attack window, Softaculous warned that installations could have received malicious packages, though the company believed only a small number of servers were actually compromised.

The incident highlighted fundamental weaknesses in Internet routing security that have persisted for decades. The Border Gateway Protocol, which directs traffic across the Internet, was originally built on trust, allowing network operators to make routing announcements without cryptographic verification. While security measures like RPKI Route Origin Validation have been developed to prevent such hijacks, the attackers exploited gaps in how Hetzner configured these protections. BGP experts characterized the lapses as preventable mistakes that should not have allowed the attack to persist. The organizations involved did not immediately respond to requests for comment on the incident.

The attack underscores ongoing vulnerabilities in Internet infrastructure that cybersecurity researchers have warned about for years. Large-scale BGP hijacking incidents have previously rerouted massive amounts of data through attacker-controlled networks. As internet architects continue working to strengthen routing security protocols, the incident demonstrates that technical solutions alone cannot prevent attacks when organizations fail to implement basic security practices like code signing and proper network monitoring.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI