# Telegram prefixes hijack by Rcom AS18101

DevFeed: [Telegram prefixes hijack by Rcom AS18101](<https://devfeed.tech/articles/telegram-prefixes-hijack-by-rcom-as18101-39780.md>)

Original publisher: [Read original article](<https://anuragbhatia.com/post/2026/06/telegram-prefix-hijack-by-rcom/>)

Published: 2026-06-16T19:44:03Z

Content type: opinion

Language: en

Sources: [Personal blog of Anurag Bhatia](<https://devfeed.tech/sources/personal-blog-of-anurag-bhatia.md>)

Topics: [BGP](<https://devfeed.tech/topics/bgp.md>), [networking](<https://devfeed.tech/topics/networking.md>), [Routing (disambiguation)](<https://devfeed.tech/topics/routing.md>)

Tags: [airtel](<https://devfeed.tech/tags/airtel.md>), [as15412](<https://devfeed.tech/tags/as15412.md>), [as18101](<https://devfeed.tech/tags/as18101.md>), [as4755](<https://devfeed.tech/tags/as4755.md>), [bgp](<https://devfeed.tech/tags/bgp.md>), [india](<https://devfeed.tech/tags/india.md>), [outage](<https://devfeed.tech/tags/outage.md>), [rcom](<https://devfeed.tech/tags/rcom.md>), [ripe-ris](<https://devfeed.tech/tags/ripe-ris.md>), [routers](<https://devfeed.tech/tags/routers.md>), [routing](<https://devfeed.tech/tags/routing.md>), [rpki](<https://devfeed.tech/tags/rpki.md>), [telegram](<https://devfeed.tech/tags/telegram.md>), [traffic](<https://devfeed.tech/tags/traffic.md>)

## AI overview

The article examines Rcom AS18101's apparent BGP hijacking of Telegram prefixes during Telegram's blocking in India. It confirms that Rcom originated at least one Telegram prefix and argues that the incident was more likely an accidental configuration error than intentional sabotage, while noting that the impact varied by upstream connectivity.

## Source excerpt

The last few hours were quite noisy with a lot of discussion around Telegram block and Rcom's hijack of Telegram prefixes. For those who may not know, Telegram has been blocked in India till 22 June 2026 (news here). The justification has been to avoid paper leak over the telegram. Anyways, I am not going into whether the block is good or bad as it can be part of an endless discussion depending on how one views it. Maybe some separate time but let's look at the BGP routing side of things. ISPs went for blocking it in all possible ways - from the usual DNS layer to block resolution of Telegram to also blackhole its prefixes. Telegram is a special case as they have their own ASN, IP prefixes etc making it easy to block them at the routing layer directly. I saw this on Airtel, where traffic seems to be dropping at their routers. mtr -wby0 -4 web.telegram.org Start: 2026-06-17T01:20:46+0530 HOST: desktop Loss% Snt Last Avg Best Wrst StDev 1. AS??? _gateway (172.16.0.1) 0.0% 10 0.2 0.2 0.2 0.2 0.0 2. AS??? 10.240.9.204 0.0% 10 4.6 7.4 4.2 25.7 6.5 3. AS??? 172.31.0.154 0.0% 10 8.1 13.5 6.4 26.4 6.2 4. AS9498 169.168.18.125.dhcp.anaronline.net (125.18.168.169) 0.0% 10 5.2 6.8 4.9 13.6 2.6 5. AS??? ??? 100.0 10 0.0 0.0 0.0 0.0 0.0 At 11:58 PM - Telegram CEO Pavel Durov tweeted and accused Reliance (technically Rcom and not Jio) for outage of Telegram outside of India by BGP hijacking. Indian telecom Reliance is sabotaging access to Telegram for millions of users OUTSIDE India (including the UAE) via a rogue method called BGP hijacking. The sabotage seems intentional, as Reliance has ignored multiple reports. This may be part of a competitive war, as... -- Pavel Durov (@durov) June 16, 2026 Technically it's true that Rcom AS18101 has hijacked Telegram's prefixes. Take e.g 91.105.192.0/23 - AS18101 started originating this prefix at 16:14:19 GMT / 21:44:19 IST on 16 June as visible from many RIPE RIS collectors including RIPE RIS RRC01 in London. It's bad and they should not ha