According to a new report, three United States payment processing companies were targeted by BGP hijacking attacks on their DNS servers. These Internet routing attacks were designed to redirect traffic directed at the payment processors to servers controlled by malicious actors who would then attempt to steal the data.
On three separate dates in July, Oracle has stated that they saw what appeared to be BGP hijacks that targeted the DNS servers for U.S. payment processors Datawire, Vantiv, or Mercury Payment Systems.
According to Oracle, the first attack started on July 6th 2018 with a short duration attack that attempted to reroute the following network prefixes, or blocks of IP addresses. These attacks were targeting the Vantiv and Datawire payment processing companies.
220.127.116.11/24 Savvis 18.104.22.168/24 Vantiv, LLC - Vantiv 22.214.171.124/24 Vantiv, LLC - Vantiv 126.96.36.199/24 Q9 Networks Inc. - Datawire 188.8.131.52/24 Q9 Networks Inc. - Datawire
On July 10th another attack was conducted that tried to reroute the same prefixes, but according to Oracle, this time it lasted for 30 minutes. The attackers conducted further hijacks throughout July, including one attack on Mercury Payment Systems and another attack on Vantiv and Datawire that lasted as long as 3 hours.
In two of the attacks on July 10th and 13th targeting Datawire, Oracle observed traffic being routed out of Luhansk in eastern Ukraine to IP addresses in Dutch Caribbean island of Curaçao.
Oracle thinks this may be just the beginning of these types of attacks.
“If previous hijacks were shots across the bow, these incidents show the Internet infrastructure is now taking direct hits,” Oracle’s research stated. “Unfortunately, there is no reason not to expect to see more of these types of attacks against the Internet.”