In July 2018, attackers apparently manipulated Internet routing to reach authoritative DNS infrastructure associated with Datawire, Vantiv and Mercury Payment Systems. The incidents could redirect some users toward attacker-controlled websites, but the available reporting does not establish that payment-card databases or the processors’ internal applications were breached.
This was a historical campaign, reported publicly on August 6–7, 2018—not a newly verified 2026 attack. The key lesson is that a payment service can be put at risk indirectly, through BGP and DNS, even when its application servers remain uncompromised.
What happened
Border Gateway Protocol (BGP) is the system autonomous systems use to exchange Internet-reachability information. A BGP hijack occurs when a network originates or propagates an unauthorized route for someone else’s IP prefix. Parts of the Internet may then send traffic toward the wrong network.
Contemporary reporting described apparent hijacks of prefixes containing authoritative name servers used by three payment-related businesses: Datawire, Vantiv and Mercury Payment Systems. Vantiv and Mercury were associated with Worldpay; Datawire provided connectivity for transporting financial transactions to payment-processing systems. These were not issuing banks or card networks such as Visa or Mastercard.
#1 Best Overall
Oracle’s analysis and reports from SecurityWeek and BleepingComputer describe routing manipulation and suspicious DNS behavior. They do not prove compromise of a payment database or confirmed theft of card data.
The July 2018 timeline
| Date | Reported event |
|---|---|
| July 6 | Digital Wireless Indonesia (AS38146) announced several prefixes associated with Vantiv and Datawire. The event was brief and did not propagate broadly. |
| July 10 | Malaysian operator Extreme Broadband (AS38182) announced the same five prefixes. One observed event lasted about 30 minutes; another, shorter event was reported that day. |
| July 11 | Prefixes associated with Mercury Payment Systems were reportedly targeted. |
| July 12–13 | Previously targeted prefixes were announced again. One Vantiv/Datawire-related event lasted nearly three hours. |
A more detailed sequence appears in the ClearSky 2018 cyber-events report. Routing observations are evidence of where announcements and traffic appeared, not proof of where attackers were physically located.
Historical prefixes reported in the incident
BleepingComputer reproduced these /24 prefixes for the first reported event:
64.243.142.0/24 Savvis
64.57.150.0/24 Vantiv, LLC
64.57.154.0/24 Vantiv, LLC
69.46.100.0/24 Q9 Networks Inc. / Datawire
216.220.36.0/24 Q9 Networks Inc. / Datawire
They are historical observations, not a current blocklist or a statement of present ownership. Routing, corporate ownership and service assignments can change.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Rank #2
How a BGP event became a DNS attack
- An attacker or associated network announces a legitimate prefix without authorization.
- Some upstream networks accept and propagate that announcement.
- Traffic for the legitimate prefix is routed toward the announcing network.
- If the prefix contains an authoritative DNS server, queries can reach attacker-controlled infrastructure.
- A rogue DNS server can return forged records for selected domains.
- Recursive resolvers cache those answers for the returned time-to-live (TTL).
- Users may continue receiving false answers after the BGP announcement ends, until caches expire or are flushed.
This is different from breaking into a domain owner’s DNS software. The route to the name server was manipulated so that the attacker could influence name resolution.
Why the TTL mattered
Oracle reportedly observed forged responses with a TTL of approximately five days, compared with a normal TTL of about 10 minutes (600 seconds). A long TTL could extend the effect of a short routing event. It did not mean every user worldwide stayed redirected for five days: resolver policy, DNSSEC validation, cache state and record-specific behavior can shorten or change the practical duration. Some accounts describe the value as roughly a week, so it is best treated as an approximation.
Why payment infrastructure was attractive
Payment processors and transaction-connectivity providers sit between merchants, applications and financial institutions. Their domains and APIs can be valuable targets for phishing, credential theft, malware delivery, fraudulent transactions or disruption. Attacking authoritative DNS can affect how many related services are found without first compromising the application server.
The available reports establish an opportunity for malicious redirection, not a completed card-data theft operation. A route hijack can also produce only an outage or intermittent failures; interception, redirection and denial of service are distinct outcomes.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesRank #3
What users and companies could have faced
- Fake payment, merchant or wallet pages designed to collect passwords or payment details.
- Malware or exploit delivery from an impostor site.
- Misrouting of API or service traffic and resulting transaction failures.
- Fraud attempts against users who ignored browser certificate warnings.
- Redirection to cryptocurrency-theft sites or other criminal infrastructure.
Observed traffic associated with Datawire was reported as routing from eastern Ukraine toward address space associated with Curaçao. That geographic pattern does not identify the attackers or prove they were located in either place.
Did HTTPS prevent the attack?
HTTPS can expose many fraudulent redirects, but it is not a complete defense. A browser normally warns when an impostor lacks a valid certificate for the requested hostname. A user who bypasses that warning remains vulnerable, and non-browser clients may validate certificates poorly. DNS manipulation can still cause outages, misleading errors and traffic diversion. If an attacker obtains a valid certificate through a separate weakness, certificate warnings may not appear.
There is no basis for saying BGP hijacking automatically defeats TLS. Certificate validation determines whether many forms of impersonation are detected; it does not stop the route manipulation itself.
Was this a man-in-the-middle attack?
A hijacked route can place an attacker in a position to intercept or redirect traffic, but the July evidence most clearly supports DNS redirection and attempted traffic misdirection. It does not establish that attackers decrypted encrypted payment traffic or maintained a complete end-to-end man-in-the-middle position for all affected users.
Possible connection to the April 2018 cryptocurrency incident
Oracle noted similarities with an April 2018 hijack of Amazon’s authoritative DNS service that redirected MyEtherWallet users to a fraudulent site; that incident was associated with cryptocurrency theft. Contemporary coverage said the payment-processor events might be related, but that is an assessment rather than proven attribution. See Oracle’s account and SecurityWeek’s reporting.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Controls that reduce the risk
RPKI and route-origin validation
Resource Public Key Infrastructure lets an address holder publish Route Origin Authorizations (ROAs) identifying permitted originating autonomous systems. Networks that perform Route Origin Validation can reject or de-preference invalid announcements. RPKI does not solve every path manipulation, route leak or operational error, and protection depends on networks actually validating and enforcing results.
Prefix filtering
Transit providers and peers should enforce customer route filters, reject unauthorized or overly specific announcements, and block bogon and reserved space. Filters are powerful when maintained accurately, but stale customer data creates gaps.
Continuous monitoring
Monitor BGP announcements and withdrawals, origin-AS changes, path and geographic shifts, propagation, DNS answers, certificates and reachability from multiple locations. A short hijack can matter if it reaches a major recursive resolver.
Best Value
DNSSEC
DNSSEC allows validating resolvers to reject forged records without valid signatures. It does not prevent a route hijack and cannot protect users whose resolvers do not validate. Key-rollover, expired-signature and DS-record mistakes can also make legitimate services unreachable.
Independent DNS and network diversity
Using multiple authoritative DNS providers, prefixes and autonomous systems reduces dependence on one route. The trade-off is more coordination, consistent DNSSEC management, failover testing and monitoring.
TLS and application controls
- Strict certificate validation and certificate-transparency monitoring.
- HSTS where appropriate.
- Mutual TLS for service-to-service payment connections.
- Signed API requests and endpoint authentication that does not rely solely on DNS.
- Fraud analytics and transaction-risk controls.
What the incident taught the payment industry
- A routing event lasting minutes or hours can have a longer DNS effect when forged records are cached.
- Critical services can be attacked indirectly without a confirmed application or database breach.
- Limited route propagation does not mean zero exposure; one major resolver or transit path may serve many users.
- Accidental route leaks and malicious hijacks can look similar, so attribution requires caution.
- Routing security is shared among address holders, transit providers, DNS operators and recursive resolvers.
The central distinction is simple: this was a BGP-and-DNS incident with potential payment-sector consequences, not a proven compromise of the processors’ payment-card databases.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.




