Google Vietnam DNS Hijacked
GOOGLE Vietnam's Primary webpage www.google.com.vn had its DNS hijacked. The responsibility for the hack was claimed by a group called Lizard Squad. The where abouts of the group were still untraced!

( screenshot of the twitter handle of Lizard Squad claiming responsibility)
Over a period of 2 days, it was observed that the DNS infrastructure was turned from usual Google name servers (ns1.google.com, ns2.google.com) to CloudFlare (173.245.59.108, 173.245.58.166) as reported by OpenDNS which was further confirmed by various publicly available tools. The visitors to the regular www[.]google[.]com[.]vn site were instantly redirected to the DigitalOceanhosted server with the following message for a brief period!

The DigitalOcean IP which was serving as the endpoint for Google Vietnam was reported to be based out of Netherlands till the time it was taken down.
Technical Details
Whats interesting is that the IP address in question was an IPv6 IP 2a03:b0c0:2:d0::23a:c001. Prefix: 2a03:b0c0:2::/48 Prefix description: DigitalOcean Country code: NL Origin AS: 202018 Origin AS Name: DOAMS3 DigitalOcean Amsterdam RPKI status: No ROA found First seen: 2014-08-13 Last seen: 2015-02-23 Seen by #peers: 170

Theories doing the round!
It is still not clear if whether the hacker group wanted to confuse the network analysts & legacy tools or they simply wanted to map a domain to any of the IP address they get their hands on. As hosting the site in Netherlands if combined with the facility of load balancing of CloudFlares infrastructure,it does show that some thought was weighed into managing the significant amount of traffic which was generated by the Google related requests. It is increasingly being speculated that the use of IPv6 for malicious & fraudulent sites will soon become commonplace with VPS providers not offering the option of selecting either IPv4 or IPV6 address for their servers to the customers anymore. It should be commended that CloudFlare did a great rescue operation in taking down this fraudulent site immediately after it was detected.