Internet traffic for Google, Facebook, Apple was briefly rerouted to Russia
Starting at 04:43 (UTC) 80 prefixes normally announced by organizations such Google, Apple, Facebook, Microsoft, Twitch, NTT Communications and Riot Games were now detected in the global BGP routing tables with an Origin AS of 39523 (DV-LINK-AS), out of Russia.
One of the interesting things about this incident is the prefixes that were affected are all network prefixes for well known and high traffic internet organizations. The other odd thing is that the Origin AS 39523 (DV-LINK-AS) hasn’t been seen announcing any prefixes for many years (with one exception below), so why does it all of sudden appear and announce prefixes for networks such as Google?
BGP hijack layperson explainer
Basically, a router somewhere in Russia claimed to be the owner of some ip addresses belonging to Google, Facebook, etc. Other neighbouring routers began forwarding packets from actual users to this router. The packets contain the HTTPS requests people were making to these sites.
Internet traffic goes through whatever path will get it to it's destination fastest. Big Routers advertise to each other how long it will take to get somewhere through them. There have been times when either due to bugs, or due to a desire to slurp traffic, some machines have falsely advertised shorter routes causing traffic to pas through routes traffic wouldn't normally pass through. This time it was somewhere in Russia. This can be mitigated like most malicious acts / network errors if you write clever enough rules, but is hard because you have to identify the bad actors, or paths that lead to them.
#RussiaFSB?

















