Orange Spain BGP Hijack via RIPE NCC Account Breach
On January 3, 2024, an attacker who had obtained credentials for Orange Spain’s RIPE NCC portal account created malicious RPKI Route Origin Authorizations (ROAs) for Orange Spain’s prefixes (AS12479). By associating the prefixes with a different, invalid origin AS, the attacker caused RPKI-validating routers around the world to mark Orange Spain’s legitimate route announcements as “Invalid” and drop them.
The resulting routing disruption lasted approximately 2.5 hours and caused widespread Internet connectivity problems for Orange Spain’s customers. The attacker reportedly used the handle “Ms_Snow_OwO” and taunted the operator on social media.
RIR account access translates directly into the ability to modify routing security configurations affecting global reachability. RIPE NCC subsequently accelerated work on mandatory MFA for all accounts with routing-related access.