Press "Enter" to skip to content

National Pharmacy Association Monitoring Confirmed in Cloudflare Records

Evidence from Cloudflare showing a direct request from ASN197320 (National Pharmacy Association). The traffic originated while connected through Microsoft Teams CDN, confirming a live workstation. The exact page accessed was our IPS Pharma pattern and gaslighting consequences article.
NPA On-Net Access, Cloaked Cloud Probes, and Honeypot Hits

They Read, They Probed, We Logged Everything

By Kieron JH · 23 September 2025

Summary: We captured on-net access from the National Pharmacy Association while they reviewed our IPS and NPA coverage. We also logged a wave of cloaked requests through cloud providers. Crucially, many of those requests arrived via our own bait domains that mirror the organisations we are reporting on. That confirms targeted monitoring, not random browsing.

Methodology

We operate named bait domains that mirror organisations covered in our reporting. When a visitor interacts with a bait domain and follows a redirect into our site, the HTTP referrer shows the bait as the source. We log requests at the edge using Cloudflare, including ASN, IP, user agent, TLS, and challenge results.

All times below are UTC. At the time of logging Dublin was UTC+1. IPs in this article are masked to the last octet, IPv6 to the last hextet. Full records are retained offline for lawful disclosure.

What we caught on the record

Direct hits from ASN 197320 (National Pharmacy Association Ltd) landed on /2025/09/12/ips-pharma-pattern-gaslighting-consequences/. User agent reported Edge 140 on Windows 10. Our JavaScript challenge logged the visit cleanly.

Why that matters: On-net access establishes awareness. There is no credible way to claim ignorance after this. The request came from inside their own ASN.

What we caught off net

Across the same window we intercepted a stream of requests from cloud infrastructure, mainly Tencent Cloud, with Hostkey and Contabo in the mix. These were not normal browsers. They repeatedly failed JavaScript checks, wore repetitive iPhone and Safari headers, and hopped geographies in short bursts.

Honeypot referrers were the tripwire

We own and operate decoy domains that mirror the names of the organisations under scrutiny. Examples include ips-pharma.org, nationalpharmacyassociation.org, and nigelwright.org. When someone pokes those domains and follows through, the HTTP referrer shows our bait as the source. That is exactly what we logged.

Translation for the non-nerds: they walked into the trap. Not spoofed headers, not coincidence, but real clicks through our decoys into the live site. That is coordinated monitoring.

Awareness Timeline (Extract)

  • 2025-09-22 14:18 UTC · ASN 197320 reached /2025/09/12/ips-pharma-pattern-gaslighting-consequences/ · JS challenge logged · UA Edge 140 on Windows.
  • 2025-09-22 19:11 to 22:49 UTC · Contabo and Hostkey sources requested /2025/09/10/ukpharmacywatch-defcon-launch/ with referrers matching our bait domains · challenged at the edge.
  • 2025-09-23 01:46 to 02:05 UTC · Tencent Cloud IPs in DE, US, HK, KR requested Nigel Wright and IPS pages via our bait domains · repeated JS detection failures · machine-like UA patterns.

Representative log highlights

Times in UTC. IPs masked to the last octet for privacy. IPv6 masked to the last hextet.

Time ASN Org IP Referrer Target Action
2025-09-22 14:18:07 197320 National Pharmacy Association Ltd 195.20.155.xxx statics.teams.cdn.office.net /2025/09/12/ips-pharma-pattern-gaslighting-consequences/ JS challenge logged
2025-09-23 02:04:54 132203 Tencent Cloud 43.131.23.xxx www.ips-pharma.org /2025/09/10/ukpharmacywatch-defcon-launch/ The Wall
2025-09-23 02:03:20 132203 Tencent Cloud 49.51.33.xxx www.nigelwright.org /2025/09/11/nigel-wright-service-obstruction-blocked-sar/ The Wall
2025-09-23 01:49:40 132203 Tencent Cloud 43.131.45.xxx nationalpharmacyassociation.org /2025/09/10/ukpharmacywatch-defcon-launch/ The Wall
2025-09-22 22:49:07 57043 Hostkey 2a05:b40:0:718:56ab:3aff:fe8b:xxxx nationalpharmacyassociation.org /2025/09/10/ukpharmacywatch-defcon-launch/ The Wall

Indicators of Concern

SignalWhy it matters
On-net access from ASN 197320Confirms first-party awareness of reporting.
Referrers equal to our bait domainsShows decoys were probed and followed into the live site.
Geographic hopping within minutesConsistent with datacentre automation, not human browsing.
Identical mobile Safari user agents with JS missingHeadless or scripted clients failing JavaScript checks.
Cloud VPS sources across multiple providersTypical of monitoring pipelines that rotate infrastructure.

About the Nigel Wright hits

Some of the logged requests came through our Nigel Wright bait domains. It is important to be clear that we cannot attribute those hits to any specific person or organisation. The most likely explanation is that automated monitoring tools crawled all of our bait domains at once, following every redirection into the live site regardless of whether the cases were linked.

Attribution and Caveats

Cloud and VPS sources are shared infrastructure. Their appearance in logs indicates where traffic was routed, not who ultimately pressed go. We do not attribute intent to specific individuals without additional corroboration.

Requests that arrived via nigelwright.org reflect our bait domains being crawled in bulk. We cannot attribute those hits to any person or organisation. The pattern supports automated monitoring rather than individual readers.

What it tells us

  1. Awareness is formal. NPA on-net access is in the log. The record shows they read the page.
  2. Monitoring is active. Cloud probes hit our decoys first, then walked into our site. That is deliberate surveillance.
  3. The priority list is clear. IPS, NPA, Nigel Wright, and UKPharmacyWatch posts were tested the most, even when unlinked.

Our response

  • Preserve everything. Raw logs, headers, fingerprints, ASNs, and timelines are archived with file hashes.
  • Escalate controls, not drama. Managed challenges and rate limits for known clouds and noisy ASNs. Honeypots stay live.
  • Keep the door open for corrections. If any party wishes to correct a fact, their reply will be published in full.

Right of Reply

Any party named here may provide a correction or clarification. Send to [email protected]. We will publish responses in full, with timestamps. If sensitive data is included by mistake, it will be deleted and not retained.

Evidence Handling

Raw logs, headers, and fingerprints are archived with SHA-256 hashes and immutable timestamps. Working copies are kept separate from originals. Unmasked IPs are retained offline for lawful disclosure only.

Public notice of awareness

The National Pharmacy Association network accessed our reporting on 22 September. Subsequent monitoring through cloud providers was detected and logged. If any party disputes accuracy, they should send a clear correction. Silence will be recorded as a choice.

Privacy note

For transparency with privacy, IP addresses above are masked to the last octet. IPv6 addresses are masked to the last hextet. Full unmasked records are retained offline for legal and regulatory disclosure only.

Be First to Comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Mission News Theme by Compete Themes.