> Could there possibly be an innocent explanation where the channel through PRC somehow happens to be less saturated or otherwise faster?
AIUI these aren't empirical measurements of routes actual traffic takes, but reconstructions from historical BGP announcements. I guess when they say traffic was hijacked, they mean there were announcements originating from China Telecom for subnets that unquestionably aren't supposed to be served by them
How to detect that? Well, I guess after a hijack ends, it is possible to compare the origin ASNs announcing those subnets with before the hijack. If a subnet suddenly starts to be announced by an origin it had no prior relationship with, then that announcement later disappears, only for the subnet's old announcements to continue, it's easy to say this may have been a hijacking
It goes without saying when some origin begins publishing new addresses, humans were almost certainly involved somewhere along the chain. So for the innocence part, nope
I think they can report that Cogent are affected by analysing Cogent's own announcements, where BGP (IIRC) records the path of ASNs causing the announcement to be made. So CT -> Cogent announcement, then Cogent -> their customers announcement, that the origin is CT is actually identified in announcements the customers receive, and likely where data for reports like this are being collected
(disclaimer: I'm not a networking guy whatsoever)