BGP hijack infecting networks caused by a comedy of errors that’s not funny at all

by | Sep 19, 2026 | Technology

BGP hijack infecting networks caused by a comedy of errors that’s not funny at all

A coordinated supply chain attack successfully compromised networks by hijacking a block of internet address space used by Softaculous, a United Arab Emirates-based provider of web software installation and virtualization management platforms. The attackers exploited weaknesses in the routing security configuration of hosting provider Hetzner Online and processes for obtaining valid TLS certificates to redirect traffic and distribute malicious software updates to unsuspecting customers.

The hijacking involved multiple security lapses across several organizations. Hetzner Online’s loose routing configuration allowed attackers to misdirect traffic during two separate incidents spanning 33 hours total. Most critically, Softaculous had failed to implement code signing for software updates—a standard security practice—meaning recipients could not cryptographically verify the authenticity of update packages. Softaculous acknowledged that installations receiving diverted traffic during the attack window could have received malicious updates, though the company believed only a limited number of servers were actually compromised.

The attack unfolded when a specific IP prefix was announced into the global routing table with a forged origin path that appeared valid according to RPKI (Resource Public Key Infrastructure) security protocols. Hetzner Online initially reclaimed the hijacked address space after 12 hours, but when the provider ceased announcing the correct route, attackers executed a second hijack that went undetected for an additional 10 hours. Poor monitoring practices at Hetzner Online, Softaculous, and Zet.net meant the hijacking persisted intermittently for approximately 22 hours before discovery.

BGP (Border Gateway Protocol) hijacking attacks target the fundamental infrastructure that connects autonomous systems across the internet. Security experts characterized the combination of failures as preventable mistakes, noting that proper implementation of existing security measures and standard development practices would have blocked the attack. The incident highlighted gaps between theoretical security protocols and their practical deployment at internet service providers and software vendors.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI