At 03:14 UTC, our BGP monitoring stack flagged an unexpected AS-PATH for a /22 prefix we originate. Within 90 seconds, traffic to that prefix dropped 40% as upstream peers accepted a more-specific announcement from an unauthorized origin.
We immediately triggered our incident playbook: isolated the affected edge routers, applied emergency prefix filters, and contacted upstream NOCs with IRR-validated route objects. RPKI ROV had not yet been enforced on two transit links — a gap we closed the same week.
Total time from alert to full traffic restoration: 15 minutes. Post-incident, we added automated prefix-origin validation and peer-specific community tagging for faster triage.