After Rostelecom sent erroneous route announcements to divert traffic intended for Apple’s servers to its network, Apple was able to prevail in its legal dispute with the Russian telco.
Aftab Siddiqui, a network engineer working on the Mutually Agreed Norms for Routing Security (MANRS) project, reported that on July 26–27, Rostelecom began advertising routes over the border gateway protocol (BGP) for a little over 12 hours for a portion of Apple’s network.
Internet customers who were trying to connect to Apple’s services in some areas of the Internet may have been routed via the Rostelecom network as a result, Siddiqui wrote.
According to Siddiqui, the 17.70.96.0/19 assigned Apple IP address block appeared to have been affected by the traffic hijacking by Rostelecom autonomous system (AS) 12389 network.
Accidental misconfigurations have caused some of the instances, such as the one in 2004 when Turkish provider TTNet pretended to represent the entire Internet, preventing millions of customers from accessing reliable websites for hours at a time.
Others point to nation-state participation, such as the 2018 Iran Telecommunications Telegram prefix hijack.
As happened in February of this year when the South Korean cryptocurrency site KlaySwap was attacked and over US$2 million in cash were seized, criminals have been known to utilise BGP hijacking to steal traffic.
According to Siddiqui, it is the duty of network operators to guarantee an internationally reliable and secure routing infrastructure, which involves establishing legitimate ROAs for all of their resources.
“A routing system that blocks bad traffic is necessary for your network’s safety.”


