Citigroup, Idaho, and Build-a-Bear Launched a Coordinated Attack on Me

Aug 05, 2026 10:01 PM - 2 hours ago 69

knock-knock.net

A multinational bank, a US state, and a civilization teddy-bear shop each unwittingly joined the aforesaid phone-fraud botnet. Here's really to cheque whether 1 of your ain machines sewage caught successful the aforesaid honeypot.

August 5, 2026

On August 1st, Citigroup, the State of Idaho, and Build-A-Bear launched a coordinated attack connected me. They weren't alone. Lockheed Martin joined in, on pinch the Spanish National Police, the Los Angeles Superior Court, SoftBank, Argentina's authorities lipid company, a Swiss canton, a UK hedge fund, 2 universities, a hospital, and 3 further world banks. A partial database of these organizations is astatine the bottommost of this post.

Over the adjacent 27 hours, successful 4 chopped waves, each of them tried to usage my VoIP (SIP) server to spot telephone calls connected my dime. This is simply a scam called International Revenue Share Fraud (IRSF). The thought is simple: the attacker gets your telephone strategy to dial an world premium-rate number that they secretly own, and they pouch a trim of each minute. It's the telephone type of an unfastened message relay, and my server was being probed arsenic the unfastened relay.

Here's what makes "coordinated" much than a fig of speech. Every 1 of these networks tried to dial the aforesaid telephone number, and they spoofed the aforesaid mini group of clone caller IDs: the aforesaid fistful that surfaced, successful the aforesaid waves, connected servers I tally successful Los Angeles, New York, and Tokyo. Unrelated infected machines don't independently take the aforesaid disguises, target, and timing. These bots were each taking orders from the aforesaid place.

Obviously nary of this was sanctioned by Citigroup, Idaho, aliases Build-A-Bear. What almost surely happened is much mundane. An worker clicked a bad link, aliases brought an infected laptop onto the network, and a bot softly went to work. That bot is now sitting wrong a firm or authorities network, dialing retired to a fraud ring, and it presumably has entree to immoderate other is connected that network.

No harm was done to me. My SIP server is 1 of a group of honeypots that has now recorded over 11.5 cardinal protocol attacks, and it logs precisely what each attacker was trying to do. But if I were Citigroup, aliases the State of Idaho, aliases Build-A-Bear, I'd beryllium little concerned about showing up successful this dataset, and much concerned astir having a rogue instrumentality connected my network.

Check your ain network

The bully news is that it is trivial to find these rogue machines. Here is simply a free and easy API that lets you look up whether immoderate recorded attacks came from your network, providing unfastened access to immoderate of the honeypot's historical data. You tin cheque a full ASN, a group of CIDR ranges, aliases a azygous IP, pinch nary signup and nary API key.

The API is ungraded simple. You tin paste these into a browser, aliases curl them from the bid line:

https://api.knock-knock.net/check-asn?asn=<your web number> https://api.knock-knock.net/check-ranges?ranges=<your CIDRs> https://api.knock-knock.net/ip/<your IP address>

Here's what came backmost erstwhile I checked Build-A-Bear's web (ASN 21811):

curl 'https://api.knock-knock.net/check-asn?asn=21811' { "list": "year", "generated_at": "2026-08-05T05:00:00Z", "asn": 21811, "isp": "Build-A-Bear Workshop, Inc.", "hit_count": 1, "total_matched": 1, "truncated": false, "hits": [ { "ip": "104.238.197.106", "hits": 11, "first_seen": "2026-08-01 21:44:56", "last_seen": "2026-08-03 06:01:49", "protocols": [ { "proto": "SIP", "hits": 11, "last_seen": "2026-08-03 06:01:49" } ] } ] }

The consequence lists 1 IP, caught eleven times probing for SIP toll fraud. If that were your ASN, this is the instrumentality to find and isolate. This communicative is astir SIP, but the honeypot watches galore protocols, truthful the aforesaid telephone would study attacks via SSH, RDP, SMB, HTTP, and more.

I would dream that the Citigroup and Lockheed Martin information teams would drawback this benignant of point earlier a bot ever reaches extracurricular their walls. However, they did not, and moving a cheque for illustration this each day is inexpensive insurance. A rogue instrumentality that tin scope my server tin besides scope the remainder of your network, and that is the portion that should really interest you.

  • More connected the API:api.knock-knock.net
  • The honeypot itself:knock-knock.net
  • The codification (MIT license):github.com/djkurlander/knock-knock

All portion of the attack

OrganizationASNSector
Lockheed Martin Corporation6075Defense contractor
Citigroup Inc.1696Global bank
Build-A-Bear Workshop21811Toy retailer
Direccion General de la Guardia Civil212377Spanish nationalist police
State of Idaho54885US authorities government
State of Nebraska / Office of the CIO2769US authorities government
City and County of Denver18815US metropolis government
Los Angeles Superior Court of California33015US tribunal system
Etat du Valais214217Swiss cantonal government
YPF S.A.27655Argentine authorities lipid company
Kalpataru Power140154Indian powerfulness infrastructure
SoftBank Corp.17676Japanese conglomerate
LG CNS4668South Korean IT services
Marshall Wace Asset Management203818UK hedge fund
American University of Beirut12812University
The New School27616US assemblage (NYC)
Jisc Services786UK education/research backbone
Madison Co Memorial Hospital394139US hospital
Turkiye Garanti Bankasi12903Turkish bank
Cairo Amman Bank48701Jordanian bank
CSCBank SAL34370Lebanese bank
More