route leak

CANTV (AS8048) BGP route leak diverts Venezuelan traffic through Sparkle’s Italian transit network (January 2026)

On January 2, 2026 (detected around 15:40 UTC by Cloudflare Radar), a BGP route leak originating from AS8048 (CANTV, Venezuela’s state-owned telecommunications operator): eight IP prefixes, including blocks belonging to Dayco Telecom (200.74.224.0/20) that host critical infrastructure such as banks and mail servers, appeared routed through CANTV via the Italian ISP Sparkle (AS6762) and the Colombian ISP V.tal GlobeNet (AS52320) on the AS route. Networking analyst Graham Helton (Low End Orbit) reported this and hypothesized that it might have been intelligence gathering prior to Maduro’s capture. Cloudflare (Bryton Herdes) dismissed that theory and concluded that it was almost certainly due to a configuration flaw (overly lax export policies) rather than a deliberate attack, noting that AS8048 appeared in the route about 10 times (which made the route LESS attractive, contrary to what a man-in-the-middle attacker would seek) and that it was one of approximately eleven similar incidents since December 2025.

Impact details

Validated routing anomaly with potential impact on accessibility or performance; there is no public evidence of confirmed data interception or a confirmed service disruption for customers.

Classification & severity

Category
Availability
Subtype
route leak
Confidence
High

Cloudflare’s technical analysis identifies a BGP route leak likely caused by an inadequate route export/import policy, not by malicious activity.

Severity assessment

Medium
Functional impact
Degraded (non-critical)
Information impact
None
Affected scope
Sector
Critical service
Potential
Public confidence
Limited
Recoverability
Regular

Cloudflare confirms a BGP route leak from CANTV or an issue with the routing policy. No confirmed data interception or widespread service disruption for customers has been detected.

Availability

Timeline

Compromise

A BGP route leak from AS8048 (CANTV) was detected by Cloudflare Radar around 15:40 UTC: Eight Venezuelan IP prefixes were abnormally routed through Sparkle (Italy, AS6762) and GlobeNet (Colombia, AS52320).

Discovery

Network teaming engineer Graham Helton (Low End Orbit) identifies the anomaly using public data from Cloudflare Radar and hypothesizes that it may be related to intelligence gathering or espionage linked to the operation against Maduro.

Disclosure

Cloudflare (Bryton Herdes) publishes an analysis concluding that it was almost certainly a configuration error and not an attack; The Register and other media outlets report on it. Excessive prepending by AS8048 made the route less attractive, contradicting the man-in-the-middle theory.

Update

Additional analysis (FastNetMon, SDxCentral) confirms that the event was a hairpin route leak (violation of the valley-free rule) and one of ~11 similar incidents involving AS8048 since December 2025.

Evidence & sources

5 sources