Back to Blog

U.S. Payment Processing Services Targeted by BGP Hijacking Attacks

August 6, 2018

By: Lawrence Abrams

According to a new report, three United States payment processing companies were targeted by BGP hijacking attacks on their DNS servers. These Internet routing attacks were designed to redirect traffic directed at the payment processors to servers controlled by malicious actors who would then attempt to steal the data.

On three separate dates in July, Oracle has stated that they saw what appeared to be BGP hijacks that targeted the DNS servers for U.S. payment processors Datawire, Vantiv, or Mercury Payment Systems.

According to Oracle, the first attack started on July 6th 2018 with a short duration attack that attempted to reroute the following network prefixes, or blocks of IP addresses. These attacks were targeting the Vantiv and Datawire payment processing companies.

 64.243.142.0/24 Savvis
 64.57.150.0/24 Vantiv, LLC - Vantiv
 64.57.154.0/24 Vantiv, LLC - Vantiv
 69.46.100.0/24 Q9 Networks Inc. - Datawire
 216.220.36.0/24 Q9 Networks Inc. - Datawire

On July 10th another attack was conducted that tried to reroute the same prefixes, but according to Oracle, this time it lasted for 30 minutes. The attackers conducted further hijacks throughout July, including one attack on Mercury Payment Systems and another attack on Vantiv and Datawire that lasted as long as 3 hours.

Second Vantiv BGP Attack
Second Vantiv BGP Attack (Source: Oracle)

In two of the attacks on July 10th and 13th targeting Datawire, Oracle observed traffic being routed out of Luhansk in eastern Ukraine to IP addresses in Dutch Caribbean island of Curaçao.

Oracle thinks this may be just the beginning of these types of attacks.

“If previous hijacks were shots across the bow, these incidents show the Internet infrastructure is now taking direct hits,” Oracle’s research stated. “Unfortunately, there is no reason not to expect to see more of these types of attacks against the Internet.”

More: https://www.bleepingcomputer.com/news/security

Contact us

Safety is essential to your decision making. We are sure that our team can clarify any doubts. After all, we understand security.

contact@sikur.com

Follow us

Try SIKUR





Contact Us
First Name*
Last Name*
E-mail*
Mobile Number*
Company*
Country*
Tell us what do you need* ?
Products: Hold CTRL+Click to add more than 1.* ?
Comments
I agree to the Privacy Policy and Terms of Service.