They Read, They Probed, We Logged Everything
By Kieron JH · 23 September 2025
Summary: We captured on-net access from the National Pharmacy Association while they reviewed our IPS and NPA coverage. We also logged a wave of cloaked requests through cloud providers. Crucially, many of those requests arrived via our own bait domains that mirror the organisations we are reporting on. That confirms targeted monitoring, not random browsing.
Methodology
We operate named bait domains that mirror organisations covered in our reporting. When a visitor interacts with a bait domain and follows a redirect into our site, the HTTP referrer shows the bait as the source. We log requests at the edge using Cloudflare, including ASN, IP, user agent, TLS, and challenge results.
All times below are UTC. At the time of logging Dublin was UTC+1. IPs in this article are masked to the last octet, IPv6 to the last hextet. Full records are retained offline for lawful disclosure.
What we caught on the record
Direct hits from ASN 197320 (National Pharmacy Association Ltd) landed on
/2025/09/12/ips-pharma-pattern-gaslighting-consequences/.
User agent reported Edge 140 on Windows 10. Our JavaScript challenge logged the visit cleanly.
Why that matters: On-net access establishes awareness. There is no credible way to claim ignorance after this. The request came from inside their own ASN.
What we caught off net
Across the same window we intercepted a stream of requests from cloud infrastructure, mainly Tencent Cloud, with Hostkey and Contabo in the mix. These were not normal browsers. They repeatedly failed JavaScript checks, wore repetitive iPhone and Safari headers, and hopped geographies in short bursts.
Honeypot referrers were the tripwire
We own and operate decoy domains that mirror the names of the organisations under scrutiny. Examples include
ips-pharma.org,
nationalpharmacyassociation.org,
and nigelwright.org.
When someone pokes those domains and follows through, the HTTP referrer shows our bait as the source. That is exactly what we logged.
Translation for the non-nerds: they walked into the trap. Not spoofed headers, not coincidence, but real clicks through our decoys into the live site. That is coordinated monitoring.
Awareness Timeline (Extract)
- 2025-09-22 14:18 UTC · ASN 197320 reached
/2025/09/12/ips-pharma-pattern-gaslighting-consequences/· JS challenge logged · UA Edge 140 on Windows. - 2025-09-22 19:11 to 22:49 UTC · Contabo and Hostkey sources requested
/2025/09/10/ukpharmacywatch-defcon-launch/with referrers matching our bait domains · challenged at the edge. - 2025-09-23 01:46 to 02:05 UTC · Tencent Cloud IPs in DE, US, HK, KR requested Nigel Wright and IPS pages via our bait domains · repeated JS detection failures · machine-like UA patterns.
Representative log highlights
Times in UTC. IPs masked to the last octet for privacy. IPv6 masked to the last hextet.
| Time | ASN | Org | IP | Referrer | Target | Action |
|---|---|---|---|---|---|---|
| 2025-09-22 14:18:07 | 197320 | National Pharmacy Association Ltd | 195.20.155.xxx | statics.teams.cdn.office.net | /2025/09/12/ips-pharma-pattern-gaslighting-consequences/ | JS challenge logged |
| 2025-09-23 02:04:54 | 132203 | Tencent Cloud | 43.131.23.xxx | www.ips-pharma.org | /2025/09/10/ukpharmacywatch-defcon-launch/ | The Wall |
| 2025-09-23 02:03:20 | 132203 | Tencent Cloud | 49.51.33.xxx | www.nigelwright.org | /2025/09/11/nigel-wright-service-obstruction-blocked-sar/ | The Wall |
| 2025-09-23 01:49:40 | 132203 | Tencent Cloud | 43.131.45.xxx | nationalpharmacyassociation.org | /2025/09/10/ukpharmacywatch-defcon-launch/ | The Wall |
| 2025-09-22 22:49:07 | 57043 | Hostkey | 2a05:b40:0:718:56ab:3aff:fe8b:xxxx | nationalpharmacyassociation.org | /2025/09/10/ukpharmacywatch-defcon-launch/ | The Wall |
Indicators of Concern
| Signal | Why it matters |
|---|---|
| On-net access from ASN 197320 | Confirms first-party awareness of reporting. |
| Referrers equal to our bait domains | Shows decoys were probed and followed into the live site. |
| Geographic hopping within minutes | Consistent with datacentre automation, not human browsing. |
| Identical mobile Safari user agents with JS missing | Headless or scripted clients failing JavaScript checks. |
| Cloud VPS sources across multiple providers | Typical of monitoring pipelines that rotate infrastructure. |
About the Nigel Wright hits
Some of the logged requests came through our Nigel Wright bait domains. It is important to be clear that we cannot attribute those hits to any specific person or organisation. The most likely explanation is that automated monitoring tools crawled all of our bait domains at once, following every redirection into the live site regardless of whether the cases were linked.
Attribution and Caveats
Cloud and VPS sources are shared infrastructure. Their appearance in logs indicates where traffic was routed, not who ultimately pressed go. We do not attribute intent to specific individuals without additional corroboration.
Requests that arrived via nigelwright.org reflect our bait domains being crawled in bulk. We cannot attribute those hits to any person or organisation. The pattern supports automated monitoring rather than individual readers.
What it tells us
- Awareness is formal. NPA on-net access is in the log. The record shows they read the page.
- Monitoring is active. Cloud probes hit our decoys first, then walked into our site. That is deliberate surveillance.
- The priority list is clear. IPS, NPA, Nigel Wright, and UKPharmacyWatch posts were tested the most, even when unlinked.
Our response
- Preserve everything. Raw logs, headers, fingerprints, ASNs, and timelines are archived with file hashes.
- Escalate controls, not drama. Managed challenges and rate limits for known clouds and noisy ASNs. Honeypots stay live.
- Keep the door open for corrections. If any party wishes to correct a fact, their reply will be published in full.
Right of Reply
Any party named here may provide a correction or clarification. Send to [email protected]. We will publish responses in full, with timestamps. If sensitive data is included by mistake, it will be deleted and not retained.
Evidence Handling
Raw logs, headers, and fingerprints are archived with SHA-256 hashes and immutable timestamps. Working copies are kept separate from originals. Unmasked IPs are retained offline for lawful disclosure only.
Public notice of awareness
The National Pharmacy Association network accessed our reporting on 22 September. Subsequent monitoring through cloud providers was detected and logged. If any party disputes accuracy, they should send a clear correction. Silence will be recorded as a choice.
Privacy note
For transparency with privacy, IP addresses above are masked to the last octet. IPv6 addresses are masked to the last hextet. Full unmasked records are retained offline for legal and regulatory disclosure only.







Be First to Comment