BGP.Exchange Website Compromised (Sept. 12, 2026)

Sicherheit (Pexels, allgemeine Nutzung)[German]A quick update that a blog reader brought to my attention. BGP.Exchange has been hacked, and the site has been compromised. As of September 12, 2026, the website has been defaced, and it appears that spam is also being sent through their email system. Here's a brief overview of the situation.

What is BGP.Exchange?

According to the provider, BGP.Exchange is a free, global, and virtual Internet Exchange Platform (IXP). It enables networks worldwide to easily exchange data and routing information (peering) in a matter of seconds via tunnel protocols such as GRETAP, VxLAN, or ZeroTier, without having to be physically connected to a traditional data center.

A Note from a Reader

Grman blog reader contacted me via email today, September 12, 2026, at around 1:26 p.m. (Thanks for the heads-up—since I'm currently on the road and the internet is down here, this is a belated response and just a "quick update"). Finn wrote with the subject line "BGP.Exchange Compromised":

Good afternoon,

I just wanted to quickly mention that the public BGP exchange "BGP.Exchange" was compromised today.

Finn writes that he received emails today from the "administrator" containing Nazi song lyrics. On Discord, there are reports of many more emails and other messages. The reader notes that, based on his observations, peering via the exchange is currently disrupted. His VPN tunnels are no longer working. It's also no longer possible to log in to the provider's portal.

Finn concluded his message by noting, "Technically, of course, something could have been done with the traffic as well."

The BGP-Exchange website has been hacked

I tried to access the URL BGP.Exchange, and the following message appears on the page in question.

BGP.Exchange-Hack
BGP.Exchange hacked

The smartphone screenshot of the page above definitely looks like a hack; the site is no longer under the operator's control. I don't have access to Discord, but there's a post on reddit.com titled " Weird Mail from BGP.Exchange," where someone asks if others have also received a "strange" email. I've included a screenshot of that email below.

BGP.Exchange-Mail
BGP.Exchange mail

This doesn't look good at all. The Reddit user then added: "This seems to be a bigger problem; I expect a few more emails today. It's just copy-and-paste spam from some Chinese person. BGP isn't affected by this at the moment." The current situation is as follows:

  • Website defacement: The main landing page of BGP.Exchange was replaced with a defacement message titled "Bitch Daniel," accusing the platform of financial exploitation, waste of resources, and operating a virtual IXP (VIXP).
  • Malicious and Harassing Emails: Users and network operators reported receiving numerous strange, harassing, or disturbing spam emails. The emails contained real user data (such as full names) as well as explicit obscenities and profanity in the Cantonese language.

It appears that the emails are indeed being sent through the platform. Anyone who is a member of BGP.Exchange should immediately end any active sessions, change shared login credentials, and block incoming emails from this domain until an official statement regarding the cause of the issue is released.

This entry was posted in issue, Security and tagged , , . Bookmark the permalink.

Leave a Reply

Your email address will not be published. Required fields are marked *

Note: Please note the rules for commenting on the blog (first comments and linked posts end up in moderation, I release them every few hours, I rigorously delete SEO posts/SPAM).