Get fresh insights, pro tips, and thought starters–only the best of posts for you.
BGP hijacking is a cyberattack in which an Autonomous System (AS) falsely announces ownership of IP address ranges through the Border Gateway Protocol (BGP), which misroutes, intercepts, monitors, or drops internet traffic.
BGP is the inter-domain routing protocol that enables internet service providers (ISPs), cloud providers, and other networks to exchange reachability information. It selects routes based on routing policies and path attributes, helping data traverse networks across the internet.
In a hijacking incident, a malicious actor or sometimes a misconfigured network, advertises IP prefixes it does not legitimately own. Because BGP largely operates on trust between networks, other routers may accept the false announcement and redirect traffic through the attacker’s network.
The result can range from service disruption to traffic interception and large-scale outages.
A typical BGP hijacking attack follows these steps:
| Scenario | Traffic Destination | Outcome |
| Normal BGP routing | Legitimate network owner | Services operate normally |
| BGP hijacking | Malicious or unauthorized network | Traffic interception, redirection, or outage |
| Route leak | Unintended third-party network | Performance degradation and instability |
BGP hijacking can have serious consequences for businesses, service providers, and end users.
Common risks include:
Because internet routing is interconnected globally, even a single incorrect BGP announcement can affect users across multiple regions.
| Type | Description |
| Prefix hijacking | An attacker announces ownership of another organization’s IP range. |
| Sub-prefix hijacking | A more specific route is advertised, often overriding legitimate routes. |
| Route leaks | Legitimate routes are unintentionally propagated to networks that should not receive them. |
| Traffic interception hijacking | Traffic is routed through an attacker and then forwarded to the intended destination. |
No single control can eliminate BGP hijacking, but organizations can significantly reduce exposure by adopting routing security best practices.
Key defenses include:
These measures can help detect, validate, or reject unauthorized route announcements and reduce the likelihood or impact of routing incidents.
Hexnode supports endpoint management, compliance tracking, policy enforcement, and patch deployment as part of broader security hygiene.
Centralized device management, policy enforcement, compliance monitoring, alerting, and patch deployment help organizations maintain endpoint posture as part of a defense-in-depth security strategy.
By helping IT teams manage endpoint policies, monitor compliance, and deploy OS updates, Hexnode can support a broader defense-in-depth approach alongside routing security controls designed to reduce cyber risk.
No, but HTTPS helps protect data confidentiality even if an attacker redirects traffic.