HackMyIP
← Back to News
2026-06-17 BleepingComputer

India's Telegram Ban Triggers BGP Hijack, Disrupts UAE Users

RegulationPrivacyIncident Response

On June 16, 2026, India's Ministry of Electronics and Information Technology invoked Section 69A of the IT Act to block Telegram nationwide until June 22, following a recommendation from the National Testing Agency (NTA) over the platform's role in trafficking leaked exam materials. A separate order compels Telegram to disable its message-editing feature in India until June 30. Telegram has already moved the Delhi High Court to challenge the blocking order, with a hearing scheduled for June 18. The Internet Freedom Foundation (IFF) has called the move "constitutionally incompatible" and a disproportionate response to exam fraud.

The crackdown did not stay inside India's borders. Telegram CEO Pavel Durov accused Indian telecom Reliance of using BGP hijacking to "sabotage" access for users outside India, including in the UAE. Doug Madory, Director of Internet Analysis at Kentik, confirmed that AS18101 announced Telegram's IP prefixes shortly after the domestic block went live, redirecting and disrupting traffic meant for the real Telegram network. Network researcher Anurag Bhatia independently verified the hijack against public routing data, while policy researcher Pranesh Prakash traced the leak through FLAG Telecom (AS15412), a former RCom-owned transit provider that failed to drop the RPKI-invalid announcement, which is how the disruption spread to users as far as the UAE. Durov framed the incident as possible competitive interference given Reliance's ties to Meta, and urged network operators worldwide to reject unauthorized BGP announcements from AS18101.

The routing collapse illustrates how a single country's enforcement action can cascade across the global internet when upstream providers fail to validate route origins. RPKI route-origin validation and filtering limited propagation of the bad route, but not before it reached international transit networks. Users and operators in affected regions can investigate their own exposure by running a DNS leak test to confirm whether queries are being silently rerouted, performing a WHOIS lookup on suspicious prefixes to verify legitimate ownership, and checking their privacy checkup to ensure no other services are being intercepted in transit. The episode underscores the fragility of internet routing and the collateral damage that national-level platform bans can inflict on users far beyond the jurisdiction imposing them.

Source: BleepingComputer →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a VPN? →How websites track you →Browser fingerprinting explained →