Global BGP Leak: Internet Disruption Caused by DDoS Mitigation Provider
2025-04-11

This post analyzes a BGP routing mishap on April 1st, 2025. A BGP leak from a DDoS mitigation provider (AS3223) caused brief internet disruption and misdirected traffic globally. The leak lasted approximately 20 minutes, affecting over 30,000 routes. The analysis details the type of leak (path error, not origination error) and explores how RFC 9234's "Only to Customer" BGP path attribute could have prevented it. Using Kentik's BGP visualization and NetFlow data, the post illustrates the impact on internet traffic, including misdirected and dropped traffic.
Tech