Back to Campus Special: Get CyberGhost VPN from /mo only

Back to Campus Special: now
/mo only Get Offer

Get Offer
Get Plan

45-day money-back guarantee

IP Hijacking

IP Hijacking Definition

IP hijacking is the unauthorized announcement of IP address ranges, or prefixes, that belong to another network. During a hijack, a network announces that it can route traffic for IP prefixes it isn't authorized to originate. If other networks accept and propagate the announcement, traffic intended for the legitimate network may be redirected, intercepted, or disrupted.

An IP hijack commonly occurs through the Border Gateway Protocol (BGP), which networks use to exchange routing information across the internet. For this reason, IP hijacking is often referred to as BGP hijacking, route hijacking, or prefix hijacking. Attackers can also hijack traffic through techniques like Address Resolution Protocol (ARP) spoofing and Domain Name System (DNS) spoofing.

How IP Hijacking Works

  1. A network announces its routing information: Networks use BGP to share which IP prefixes they're responsible for.
  2. Attackers announce an unauthorized route: A malicious actor or misconfigured system advertises IP addresses it doesn't own or control.
  3. Other networks accept the announcement: If networks don't filter or validate the false route, routers may update their routing tables and treat it as legitimate.
  4. Traffic follows the wrong path: Routers send internet traffic intended for the legitimate network along the false route instead.

Risks of IP Hijacking

IP hijacking can affect where traffic goes, whether services load, and how attackers abuse stolen address space.

How Networks Help Prevent IP Hijacking

IP hijacking is primarily prevented at the network level. Internet service providers and other network operators use routing security measures to verify route announcements and detect suspicious changes before they spread across the web.

Some of the most common safeguards include:

IP Hijacking vs DNS Hijacking

Although both attacks can redirect internet traffic, they target different parts of the network.

IP HijackingDNS Hijacking
Redirects traffic by announcing unauthorized IP address rangesRedirects traffic by changing how domain names resolve to IP addresses.
Targets internet routing through BGPTargets the DNS
Often affects networks or IP prefixesOften affects domains, devices, or DNS settings

Read More

FAQ

The terms are often used interchangeably when discussing internet routing. BGP hijacking describes the specific mechanism in which unauthorized IP prefixes are announced through BGP. IP hijacking or prefix hijacking may be used more generally to describe the resulting unauthorized routing of an IP address range.

No. A VPN can't prevent IP hijacking because route announcements are controlled by network operators rather than individual users. VPN encryption may help protect the contents of traffic if routing is disrupted or redirected, but it doesn't prevent the underlying routing hijack. 

IP hijacking changes how networks route internet traffic, while DNS hijacking changes how domain names resolve to IP addresses. Although both attacks can redirect traffic, they target different parts of the internet infrastructure. 

×

BACK TO CAMPUS OFFER

OFF

with 2 Bonus Months

Limited Time Discount

undefined45-Day Money-Back Guarantee