Orange Spain faced a significant internet outage due to BGP Traffic Hijacking by a threat actor named 'Snow'. The hijacking was caused by exploiting vulnerabilities in the company's RIPE account and implementing an invalid RPKI configuration. BGP relies on trust and malicious actors can redirect traffic to malicious destinations. RPKI is a cryptographic solution that associates BGP route announcements with the correct originating AS number. The Orange Spain outage resulted in network issues, but no client data was compromised. The hacker gained access through stolen credentials and mentioned the absence of two-factor authentication.
Table of contents
The BGP Traffic HijackIntroducing RPKI: A Solution to BGP HijackingOrange Spain OutageOrange Spain’s Response and RecoveryCredentials Compromised through Information-Stealing MalwareHacker’s Admission and MotivationOrange Spain Incident AnalysisConclusionSort: