Backwater Forensics Publishes National Infrastructure Zombie Survey

Backwater Forensics Publishes National Infrastructure Zombie Survey

What Was Found

When one telecommunications carrier acquires another, the acquired IP space and routing infrastructure is supposed to be integrated or decommissioned. The research found systematic evidence that this integration is frequently incomplete. Pre-acquisition ASNs — Autonomous System Numbers that should have been retired — remain active in global BGP routing tables, announcing IP prefixes under routing authority that no longer corresponds to any publicly documented network operator. The investigation documented three distinct anomaly classes:

  • Zombie ASNs — pre-acquisition ASNs still announcing live prefixes with no accountable successor operator
  • Retention anomalies — pre- and post-acquisition ASNs routing in parallel, creating dual-authority conditions
  • Third-party control — routing authority held by an entity with no documented relationship to the acquisition chain

A total of 24 ASNs were documented across 6 acquisition cases, including findings related to Charter/TWC, Cablevision/Altice, EarthLink/Windstream, Insight/TWC, AT&T/@Home, and Verizon/MCI succession chains.


What Was Not Published

The physical infrastructure conditions that would allow an attacker to locate or exploit acquisition boundary vulnerabilities in the HFC backbone are outside the scope of this publication and have not been disclosed publicly. Those findings have been shared exclusively with CISA, the FBI, and relevant carriers through responsible disclosure. There are no current plans to publish them.

A formal notice of intended disclosure has been submitted to CISA. Backwater Forensics will remove or modify any published content upon request from CISA or other relevant federal agencies without delay.


Methodology

The national database was constructed from public carrier acquisition records — SEC merger documents, FCC franchise transfer filings, and ARIN/RDAP attribution data — before any validation data was collected. Case selection was determined a priori from acquisition histories, not from results. BGP routing state was validated via RIPEstat, bgp.tools, and ARIN RDAP. All data sources are public record.


About Backwater Forensics

Backwater Forensics is an independent digital forensics research practice specializing in infrastructure security, Apple device forensics, and forensic tooling. The practice publishes technical research and provides forensic services to investigators and legal professionals.

Contact:
research@backwaterforensics.com
backwaterforensics.com


#


Posted

in

by

Tags: