Ben Cartwright-Cox via routing-wg wrote on 03/09/2026 11:07:
For me, the real question is why did the transit provider accept a the hijacked prefix from someone that's not upstream of the victim?
Yeah... especially since as both AS62390:AS-NEXONHOST and AS-ZETNET do not contain (nor have in the last month) Hetzner, so I assume everything was just unfiltered.
It looks like that, for sure. Ingress prefix filtering is a headache because there are no generic tools to handle it, which means that everyone is stuck in a cook-your-own situation. Many organisations handle this by manual updates or by default-permit, at least until the first major incident. Also, this is only half the story: the other half is ingress packet filtering whether via urpf or manual ACL. This may or may not be applicable to any particular downstream for reasons which are well understood. Nick