But our AS2 "hijacks" and MIT, etc. are usually the result of router syntax errors trying to prepend, I really hope someone isn't trying to prepend 27421 times... 🙂 On 9/11/26 10:53 AM, Christopher Morrow via NANOG wrote:
The u-del folk (as2?) have some fun stories about this sort of problem :( I think they've even done at least 1 nanog talk about this?
There's also a long history of 'bad actors' using ASN at IX's (amsix and u-new-mexico I recall for us in the past) in order to make it seem like legit sources were sending traffic to places.
"Gosh, I don't THINK UNM has a network out to AMS do they? that seems sus (as the kids say these days)"
The impact you might see is non-reachability to things they announce? and/or them not being able to access your announced resources :( Also, people on the intertubes are going to be made about your 'bad behaviors' coming out of brazil :(
Its likely that the 2/1 abuse contacts you reached out to are the part of the problem here, escalate perhaps? :)
On Fri, Sep 11, 2026 at 10:26 AM Matt Brennan via NANOG <nanog@lists.nanog.org> wrote:
Hi Folks,
This is a new one for me. One of my AS numbers (AS27421) appears to be being used by someone in Brazil. We haven't seen any actual effects of the hijack -- that is, we don't appear to be losing any traffic. The only reason we noticed is because it's being reported on HE's BGP monitoring site.
I've reached out to the abuse contact for the AS's the hijacker is peering with (AS1000, AS271253 - same abuse contact for both) several times and gotten no response. Though, looking at which prefixes AS271253 is originating, it doesn't appear this AS cares much about proper behavior.
If anyone has any advice on next steps, it would be appreciated.
Thanks, Matt _______________________________________________ NANOG mailing list https://urldefense.com/v3/__https://lists.nanog.org/archives/list/nanog@list...