A major transit provider leaked routes learned from a downstream customer, pulling 40% of our outbound traffic through an unintended path. Latency spiked and packet loss appeared within minutes across multiple regions.
We correlated BGP updates with our looking-glass collectors and confirmed the leak via unexpected AS-PATH prepends. Emergency AS-PATH filters and prefix-list adjustments on edge routers contained the impact while we opened a P1 ticket with the provider.
MTTR was 45 minutes. We subsequently enforced RPKI ROV on all transit sessions and added automated alerts for path-length anomalies.