CANTV (AS8048) BGP route leak diverts Venezuelan traffic through Sparkle’s Italian transit network (January 2026)
On January 2, 2026 (detected around 15:40 UTC by Cloudflare Radar), a BGP route leak originating from AS8048 (CANTV, Venezuela’s state-owned telecommunications operator): eight IP prefixes, including blocks belonging to Dayco Telecom (200.74.224.0/20) that host critical infrastructure such as banks and mail servers, appeared routed through CANTV via the Italian ISP Sparkle (AS6762) and the Colombian ISP V.tal GlobeNet (AS52320) on the AS route. Networking analyst Graham Helton (Low End Orbit) reported this and hypothesized that it might have been intelligence gathering prior to Maduro’s capture. Cloudflare (Bryton Herdes) dismissed that theory and concluded that it was almost certainly due to a configuration flaw (overly lax export policies) rather than a deliberate attack, noting that AS8048 appeared in the route about 10 times (which made the route LESS attractive, contrary to what a man-in-the-middle attacker would seek) and that it was one of approximately eleven similar incidents since December 2025.
Impact details
Validated routing anomaly with potential impact on accessibility or performance; there is no public evidence of confirmed data interception or a confirmed service disruption for customers.
Classification & severity
- Category
- Availability
- Subtype
- route leak
- Confidence
- High
Cloudflare’s technical analysis identifies a BGP route leak likely caused by an inadequate route export/import policy, not by malicious activity.
Severity assessment
Medium- Functional impact
- Degraded (non-critical)
- Information impact
- None
- Affected scope
- Sector
- Critical service
- Potential
- Public confidence
- Limited
- Recoverability
- Regular
Cloudflare confirms a BGP route leak from CANTV or an issue with the routing policy. No confirmed data interception or widespread service disruption for customers has been detected.
Timeline
A BGP route leak from AS8048 (CANTV) was detected by Cloudflare Radar around 15:40 UTC: Eight Venezuelan IP prefixes were abnormally routed through Sparkle (Italy, AS6762) and GlobeNet (Colombia, AS52320).
Network teaming engineer Graham Helton (Low End Orbit) identifies the anomaly using public data from Cloudflare Radar and hypothesizes that it may be related to intelligence gathering or espionage linked to the operation against Maduro.
Cloudflare (Bryton Herdes) publishes an analysis concluding that it was almost certainly a configuration error and not an attack; The Register and other media outlets report on it. Excessive prepending by AS8048 made the route less attractive, contradicting the man-in-the-middle theory.
Additional analysis (FastNetMon, SDxCentral) confirms that the event was a hairpin route leak (violation of the valley-free rule) and one of ~11 similar incidents involving AS8048 since December 2025.