The BGP.Exchange compromise spared the route servers but exposed member data across 510 networks
On September 12, 2026 the virtual IXP BGP.Exchange was defaced and its authenticated email was abused to harass members, while the operator insists no route server was touched. Check your peering sessions, rotate credentials, and take stock of what the incident says about the gap between the management plane and the data plane.