Matt- This is semi common occurrence. Your best option is what you have done, reach out to the networks they are advertising to, and keep going upstream until you reach someone who is responsive and can take action. Getting your as_paths in ASPA is nice, but ASPA is not widely implemented, and it's still pretty trivial to bypass. Good luck. On Fri, Sep 11, 2026 at 10:27 AM Matt Brennan via NANOG < nanog@lists.nanog.org> wrote:
Hi Folks,
This is a new one for me. One of my AS numbers (AS27421) appears to be being used by someone in Brazil. We haven't seen any actual effects of the hijack -- that is, we don't appear to be losing any traffic. The only reason we noticed is because it's being reported on HE's BGP monitoring site.
I've reached out to the abuse contact for the AS's the hijacker is peering with (AS1000, AS271253 - same abuse contact for both) several times and gotten no response. Though, looking at which prefixes AS271253 is originating, it doesn't appear this AS cares much about proper behavior.
If anyone has any advice on next steps, it would be appreciated.
Thanks, Matt _______________________________________________ NANOG mailing list
https://lists.nanog.org/archives/list/nanog@lists.nanog.org/message/63VQ3WKN...