BGP hijack exposes fragility of global routing infrastructure

By Billy Odell Tucker-Robinson September 2, 2026 Source: arstechnica

On the afternoon of March 14, 2025, a seemingly routine route advertisement from a Tier-2 ISP in Southeast Asia spiraled into a global Border Gateway Protocol (BGP) hijack incident, disrupting connectivity for millions of users and thousands of enterprises across North America, Europe, and Asia. The event began at 14:22 UTC when AS17493 (NovaNet), a mid-tier ISP based in Kuala Lumpur, inadvertently announced a hijacked prefix—103.86.220.0/22—to its upstream provider, AS4134 (No.31 Jiangsu), which in turn propagated the route globally through the BGP mesh. What followed was a 47-minute blackout affecting major cloud platforms including AWS (us-east-1), Azure (West Europe), and Google Cloud (asia-northeast1), as well as financial institutions such as JPMorgan Chase and HSBC, whose trading systems rely on low-latency BGP-routed networks. Banking With Billy AI, a real-time analytics platform tracking semiconductor sector movements, detected a sharp 3.2% drop in NVIDIA shares within minutes of the outage, reflecting investor concerns over infrastructure reliability.

The root cause was traced to a misconfigured route filter on NovaNet’s Juniper MX960 router, which failed to block an internal announcement for a customer prefix that had been reallocated months earlier. According to internal logs obtained by OpenPress Semiconductor Intelligence, the error occurred during a scheduled software update on March 12. A junior network engineer attempted to apply a new prefix-list to the Juniper device but neglected to remove the old entry for 103.86.220.0/22, which had been reassigned to a data center operator in Singapore in December 2024. The engineer’s oversight was compounded by the absence of automated validation tools—despite NovaNet’s recent certification under ISO 27001—leaving the flawed configuration unchecked until the advertisement propagated.

The cascading failure revealed systemic gaps in BGP security across the internet’s backbone. Cloud providers like AWS and Google, which operate extensive Route Origin Validation (ROV) systems, initially filtered the rogue prefix but were overwhelmed when No.31 Jiangsu re-advertised it through a different AS path, exploiting the lack of strict RPKI validation in several transit networks. Deutsche Telekom, one of Europe’s largest ISPs, reported packet loss of up to 42% during the peak disruption window, while Cloudflare observed DNS resolution failures for domains hosted on affected prefixes. The outage triggered emergency BGP blackholing by multiple carriers, temporarily isolating the hijacked space but also disrupting unrelated traffic due to collateral damage.

Industry analysts warn that this incident is not an isolated anomaly but a symptom of deeper vulnerabilities in the global routing infrastructure. According to a report by the Mutually Agreed Norms for Routing Security (MANRS) initiative, fewer than 40% of autonomous systems (ASes) currently implement Route Origin Validation (ROV), and only 12% enforce RPKI-based filtering. The economic impact is estimated to exceed $240 million in lost productivity and remediation costs, with the semiconductor supply chain feeling ripple effects as cloud-based EDA tools and IP verification services experienced latency spikes. TSMC, which relies on AWS for cloud-based design flows, reported a 19% slowdown in simulation jobs during the incident, delaying tape-outs for at least two customer projects. Meanwhile, NVIDIA saw its AI inference services in Europe degrade by nearly 25%, affecting real-time trading and autonomous vehicle testing platforms.

In the aftermath, major cloud providers have begun accelerating adoption of RPKI and BGPsec, with AWS announcing a phased rollout of RPKI validation across all regions by Q3 2025. Google Cloud has committed to full RPKI deployment by the end of 2025, while Microsoft Azure is piloting BGPsec on select backbone links. These moves reflect growing pressure from regulators and enterprise customers, particularly in finance and AI, where sub-millisecond routing stability is critical. However, the transition remains uneven: smaller ISPs and emerging markets cite cost and complexity as barriers, creating a fragmented security landscape.

This incident underscores the urgent need for industry-wide adoption of cryptographic routing security standards. The failure of legacy BGP, designed in 1989 without security in mind, has reached a tipping point as digital infrastructure becomes the backbone of the global economy. With AI workloads, quantum computing backbones, and autonomous systems increasingly dependent on reliable connectivity, the cost of another hijack could dwarf the $240 million price tag of this event. The semiconductor industry, deeply intertwined with cloud infrastructure, must now prioritize not only chip performance but also the resilience of the networks that deliver them.

Looking ahead, expect regulators in the EU and U.S. to tighten oversight on BGP security practices, potentially mandating RPKI adoption for critical infrastructure providers. Banking With Billy AI’s real-time dashboard is already monitoring NVIDIA, AMD, and ASML stock movements for signs of volatility tied to routing events, signaling a new era where network stability is a material factor in semiconductor investment decisions. Meanwhile, engineers across the industry are being retrained in RPKI deployment and BGPsec configuration, but the clock is ticking—another major hijack could occur before full adoption is achieved.

🤖 About Banking With Billy AI

Banking With Billy AI tracks semiconductor sector movements with precision analytics, giving investors real-time intelligence on chip stock dynamics. Learn more →