Cloudflare Radar's fourth annual review of Internet patterns covers global and country-level trends across traffic, connectivity, and security for 2023. The data underlying the report comes from Cloudflare's network, which spans more than 310 cities in over 120 countries/regions and serves an average of over 50 million HTTP(S) requests per second, alongside over 70 million DNS requests per second. The interactive Year in Review site organizes findings into three sections: Traffic Insights & Trends, Connectivity & Speed, and Security.

Weekly visualizations on the site cover January 2 through November 26, 2023. Trends are available for more than 180 countries/regions, with smaller or less populated locations excluded where data is insufficient. Some metrics are presented only at a worldwide level. Traffic data for November 2-4 has been interpolated due to the Cloudflare control plane and analytics outage that occurred during those days.

The report introduces several new metrics this year while keeping methodologies consistent with the prior year wherever possible. A companion post specifically examines trends in top Internet services.

Traffic insights

Global traffic patterns in 2023 showed clear weekly rhythms and notable event-driven shifts. Mobile traffic continued to play a significant role in overall Internet usage, with its share varying by country and region. The report's interactive charts allow granular exploration of these patterns beyond what summary statistics can convey.

Connectivity and speed

Connectivity metrics tracked in the review include the prevalence of IPv6 adoption and the performance of key Internet protocols. The report also documents the growing use of post-quantum encryption, with 1.7% of TLS 1.3 traffic now protected by post-quantum cryptography.

Routing security improved globally during the year, measured by the share of RPKI valid routes. Significant growth in adoption was observed in countries including Saudi Arabia, the United Arab Emirates, and Vietnam.

Security highlights

Several security trends stand out from the 2023 data:

  • Just under 6% of global traffic was mitigated by Cloudflare's systems as potentially malicious or for customer-defined reasons. In the United States, 3.65% of traffic was mitigated, while South Korea saw 8.36%.
  • A third of global bot traffic originates from the United States, and over 11% comes from Amazon Web Services.
  • Finance was the most attacked industry globally, though the timing of mitigated traffic spikes and target industries varied widely across the year and by region.
  • Log4j remained a top attack target throughout 2023 despite being an older vulnerability. HTTP/2 Rapid Reset emerged as a significant new threat, starting with a series of record-breaking attacks.
  • Deceptive links and extortion attempts were among the most common threat types found in malicious email messages.

These findings only scratch the surface of the data available in the interactive Year in Review site, which allows users to filter by country or region and explore trends in detail. The underlying patterns offer opportunities for organizations to assess their own security posture and user experience in light of broader Internet developments.

Network Growth & Usage Patterns

1
Global Internet traffic grew by 25% in 2023, closely matching the peak growth rate seen in 2022. To establish this baseline, Cloudflare calculated the average daily traffic volume (excluding bots) from the second full week of January 2023 (January 8–14), allowing time for normal routines to resume after the holidays. The figures represent a seven-day trailing average compared against that baseline, with a similar 2022 trend line included for reference. Traffic patterns in Canada showed consistent year-over-year seasonality, with peak growth exceeding 30% in both years. Many countries displayed a clear drop in traffic heading into Christmas, with a slight rebound before New Year’s Day. Holiday effects are visible in country-level comparisons. In Indonesia, Turkey, and the United Arab Emirates, the celebration of Eid-Ul-Fitr around April 21–23, 2023 appears as a noticeable dip, mirroring the pattern seen during the 2022 observance on May 2–3. Italy’s traffic dropped around Easter Sunday and Monday (April 9–10), one week ahead of the similar 2022 decline. Extended connectivity disruptions also stand out clearly in the charts. Government-directed shutdowns in Mauritania ran from March 6–12 and May 30 to June 6, while Gabon experienced a shutdown from August 26–30. In Guam, Super Typhoon Mawar caused a multi-week traffic drop beginning May 24.
4

Service Popularity & Mobile Platforms

Google again ranked as the most popular overall Internet service, helped by its broad portfolio and the prevalence of Android devices. Among the emerging Generative AI category, OpenAI took the top spot, riding the success of ChatGPT launched a year earlier. Binance remained the most popular cryptocurrency service despite industry turmoil that year. Rankings are based on anonymized query data from Cloudflare’s 1.1.1.1 public DNS resolver, grouping domains that belong to a single service.
7
Android dominated mobile device traffic globally, accounting for over two-thirds of requests. In Bangladesh and Papua New Guinea, Android’s share exceeded 95%. Countries with the highest Android usage are largely in Africa, Oceania/Asia, and South America, many with lower gross national income per capita, likely reflecting the availability of budget-priced devices. In contrast, iOS share never topped 70% in any country, but nations with shares above 50%—including Denmark, Australia, Japan, and Canada—generally have higher gross national income per capita.
8
Traffic from SpaceX’s Starlink satellite Internet service nearly tripled globally in 2023. In the United States, Starlink traffic grew more than 2.5 times, while Brazil saw growth exceeding 17 times after the service launched there in mid-2022. In countries where Starlink became available during the year—Kenya, the Philippines, and Zambia—traffic grew rapidly following activation. The analysis tracked aggregate traffic associated with autonomous system AS14593.
9
Using the Cloudflare Radar URL Scanner launched in March 2023, scans of the top 5,000 domains identified the most common technologies across a dozen categories. Google Analytics led Analytics by a wide margin; React held a commanding lead among JavaScript Frameworks; and HubSpot topped Marketing Automation, though closely followed by competitors.
10

HTTP Version Adoption

HTTP/2 remained the dominant protocol globally, accounting for 47% of web requests in 2023. HTTP/3, completed in 2022 and running on top of QUIC, carried 20% of requests, offering improved performance over packet loss and network changes, faster connection establishment, and encryption by default. The remaining third used HTTP/1.x. Geographically, Asian countries including Nepal, Thailand, Malaysia, and Sri Lanka showed the highest HTTP/3 adoption rates, though none exceeded 35%. Conversely, over half of requests from Ireland, Albania, Finland, and China were made over HTTP/1.x.
11

Automation & Crawler Impact

NodeJS was the most common language for automated API requests, accounting for nearly 15% of non-browser, non-native-app API traffic. Go, Java, Python, and .NET held smaller shares.
12
In a visualization of aggregated IPv4 request traffic to Cloudflare from January 1 through November 26, 2023, the highest-volume address block was 66.249.64.0/20, belonging to Google. The block, one of several used by the Googlebot web crawler, shows warmer shading in a Hilbert curve plot that groups addresses at the /20 level, with each cell representing 4,096 IPv4 addresses. Unshaded areas do not necessarily indicate unused address space, but rather that the space generates no traffic to Cloudflare. The interactive visualization is available for exploration on the Year in Review website.
14

Connectivity, IPv6, and mobile traffic

Cloudflare’s network observes a substantial share of the world’s Internet traffic, and its annual analysis of that traffic offers a window into the health and evolution of global connectivity. The 2023 data shows a year of frequent outages, continued uneven progress on IPv6 adoption, and the persistent dominance of mobile devices in many regions.

Outage patterns and causes

More than 180 Internet outages were observed worldwide during 2023. Many were government-directed regional or national shutdowns, but technical failures, geopolitical conflict, fiber cuts, power outages, and severe weather all contributed to the total. Some outages lasted only a few hours; others stretched for months. Localized government-directed shutdowns in Manipur, India, and Amhara, Ethiopia, were ongoing after more than seven and four months, respectively, as of early December 2023. Iraq experienced repeated multi-hour nationwide shutdowns tied to academic exam periods, producing visible clusters in the outage timeline for June, July, and August.

The Cloudflare Radar Outage Center tracks these events using Cloudflare traffic data. The year-in-review timeline lets readers mouse over a dot to see metadata about an individual outage, and clicking opens a page with additional detail. Selecting a country or region filters the display to just the relevant events.

IPv6 adoption remains uneven

IPv6 has been a draft standard since 1998, and IPv4 address space has been effectively exhausted for some time. Yet aggregated across all of 2023, only one-third of IPv6-capable requests worldwide were actually made over IPv6. Providers have turned to network address translation and other workarounds, while cloud and hosting providers have paid as much as $50 per IPv4 address to acquire the address blocks they need.

Cloudflare has supported IPv6 since 2011, when it introduced a free Automatic IPv6 Gateway, and enabled IPv6 by default for all customers a few years later. But that only addresses one side of the equation; the user’s connection also needs to support IPv6. Analyzing the IP version used for each request to Cloudflare shows the distribution of traffic by protocol version throughout the year.

India leads the world in IPv6 adoption, thanks to near-complete adoption by Reliance Jio: 70% of dual-stacked requests from Indian users were made over IPv6. Malaysia followed at 66%. Saudi Arabia, Vietnam, Greece, France, Uruguay, and Thailand also saw more than half of dual-stacked requests made over IPv6 on average. On the other end of the spectrum, roughly 40 countries saw less than 1% of dual-stacked requests made over IPv6 during the year, a striking gap given how long the protocol has been available.

Connection quality leaders

Beyond outages, users often contend with slow connections or high latency. Aggregating results from speed.cloudflare.com tests taken in 2023 provides a geographic view of connection quality metrics, including average download and upload speeds and idle and loaded latencies. Iceland stands out: with over 85% of connections running over fiber, it ranks best across all four measured metrics, with average download speeds of 282.5 Mbps, average upload speeds of 179.9 Mbps, and average idle and loaded latencies of 9.6 ms and 77.1 ms, respectively. The distribution of download speeds in Iceland shows a large cluster between 0–100 Mbps, but also a significant number of tests well above that, including some over 1 Gbps.

Western European countries—Spain, Portugal, and Denmark—also placed in the top 10 across multiple quality metrics.

Mobile devices and traffic share

Mobile devices now account for 42% of global traffic at Cloudflare, with desktop devices responsible for the remaining 58%, in line with 2022 measurements. But the national picture varies dramatically. Some countries are heavily “mobile first,” relying on 4G/5G services rather than Wi-Fi or fixed connections. Zambia had the largest mobile device traffic share, at 79%. Countries with a mobile majority were concentrated in the Middle East and Africa, the Asia Pacific region, and South and Central America. Finland sits at the other extreme, with desktop traffic accounting for 80% of the total.

Security

20

Across all traffic to Cloudflare's network in 2023, just under 6% was mitigated, either as a potential threat or due to customer-defined rules. A smaller slice, roughly 2%, involved mitigations for DDoS attacks or WAF Managed Rules. The gap between these two figures varies by country. In Bermuda, the percentages for overall mitigation and DDoS/WAF-specific mitigation track closely together. In Pakistan and South Africa, the difference between the two trend lines is much more pronounced.

21

Cloudflare also examined where bot traffic originates by looking at the autonomous system and country associated with the IP address of each request. Cloud platforms dominate as sources of bot traffic, due to the ease of automating compute resource provisioning, low costs, distributed infrastructure, and high-bandwidth connections. Nearly 12% of global bot traffic comes from Amazon Web Services, and over 7% comes from Google. Consumer ISPs also contribute; U.S. provider Comcast accounts for over 1.5% of global bot traffic. The United States is the single largest source country, responsible for nearly a third of all bot traffic—four times Germany's 8% share. Within the U.S., Amazon's share of bot traffic edges out Google's.

22
23

Attack activity across industries was marked by volatility. Globally, Finance organizations were the most attacked industry over the course of the year. This industry, which includes mobile payments, investment/trading, and cryptocurrency platforms, was also a top target in many European countries—including Austria, Switzerland, France, the UK, Ireland, Italy, and the Netherlands—as well as in Canada, the U.S., and Mexico. The Health industry, spanning exercise equipment and medical testing device manufacturers, was a primary target across several African countries including Benin, Côte d'Ivoire, Cameroon, Ethiopia, Senegal, and Somalia.

The year started slowly, with no industry seeing more than 8% of traffic mitigated. Spikes followed: Professional Services and News/Media/Publications saw increases in late January, Health jumped in mid-February, and Law & Government saw a sharp rise in early March. Arts/Entertainment/Recreation organizations were hit with a multi-week campaign, with more than 20% of traffic mitigated during the weeks of March 26, April 2, and April 9. The year's overall peak hit the Professional Services industry, which saw a mitigated traffic share of 38.4% for the week of August 6—nearly double its January spike. The timing and targeting of these spikes varied significantly across countries and regions.

24

Although they are older vulnerabilities, attackers continued to actively target known weaknesses throughout 2023. Log4j remained a primary target, with attack volume consistently dwarfing that of other commonly exploited vulnerabilities, including those in Microsoft Exchange, Atlassian Confluence, VMWare, and F5's BIG-IP. Log4j attack volume saw spikes during the last week of October and in mid-to-late November. Attack activity targeting Atlassian vulnerabilities increased in late July and trended slowly higher through the rest of the year. The pattern varied by location—while France, Germany, India, and the U.S. saw sustained levels of Log4j attack traffic, other countries experienced infrequent, short-lived spikes.

25

The HTTP/2 Rapid Reset vulnerability (CVE-2023-44487), disclosed in October, emerged as a significant new threat. It abuses a weakness in the HTTP/2 protocol's request cancellation feature, leading to resource exhaustion on target servers. Between late August and early October, Cloudflare saw numerous attacks targeting this vulnerability. The average attack rate across these was 30M requests per second (rps), with nearly 90 attacks peaking above 100M rps. The largest hit 201M rps—nearly three times the size of the previous record-breaking attack. Notably, the attacker generated these attacks with a botnet of just 20,000 compromised systems, far smaller than the largest botnets with hundreds of thousands or millions of hosts. Given that average web traffic is estimated at 1–3 billion requests per second, similar attacks could conceivably focus an entire web's worth of requests on a few targets.

26

Post-quantum cryptography protects data from adversaries who might capture and store today's traffic for decryption by future quantum computers. Cloudflare enabled post-quantum key agreement at its edge by default in October 2022, but usage requires browser support. Google's Chrome browser began slowly enabling support in August 2023, and Cloudflare announced general availability of post-quantum cryptography for inbound and outbound connections in September. As Chrome version 116 and later started adopting the technology, usage grew gradually, with a significant increase on November 8. By the end of November, 1.7% of TLS 1.3 traffic was using post-quantum encryption—a share expected to grow rapidly in 2024 as Chrome's ramp continues and other browsers add support.

27

Email remains a primary entry point for attackers targeting enterprise networks. Cloudflare Area 1 Email Security analyzed an average of 2.65% of emails as malicious over the course of 2023. Weekly aggregated spikes exceeded 3.5%, 4.5%, and 5% in early February, early September, and late October, respectively. Malicious emails often contain multiple threat types, highlighting the need for comprehensive email security. Throughout most of the year, as much as 80% of malicious emails contained deceptive links. However, a strategy shift appeared in August as the share of emails with deceptive links began to fall while the share proposing extortion rose. By late October and into November, the two categories had traded places, with nearly 80% of analyzed malicious emails containing extortion threats. The shift was short-lived, as the extortion percentage fell almost as quickly as it rose. Identity deception and credential harvesting were also commonly identified, though their share gradually declined over the year.

28
29

Border Gateway Protocol (BGP) routing security improved globally in 2023, measured by the share of RPKI valid routes. RPKI cryptographically signs records that associate a BGP route announcement with its correct originating AS number, ensuring that routing information came from an authorized network. The global share of RPKI valid routes grew to nearly 45% by year's end, up six percentage points from the end of 2022. Progress varied widely by country. In the United States, increased attention from the Federal Communications Commission, which held a BGP Security Workshop on July 31, is arguably warranted: less than a third of U.S. routes are RPKI valid. That is significantly better than South Korea, where less than 1% of announced routes are RPKI valid, but trails Vietnam significantly. Vietnam's share of RPKI valid routes increased 35 percentage points during the first half of the year to 90%.

30

The Full-Year View From Cloudflare’s Network

Cloudflare’s annual Year in Review is built on the unique vantage point of its global anycast network, which handles a substantial share of the world’s web traffic. The 2023 edition compiles this data into a broad snapshot of how the Internet behaved over the past 12 months, examining shifts in traffic, performance, and security posture across countries and sectors.

The interactive report on the Cloudflare Radar site allows you to filter the year’s trends by specific metrics, regions, and industries. For example, you can examine changes in traffic volume, adoption of IPv6, or the prevalence of different attack vectors. The goal is to give organizations a data-driven basis for planning—especially around network capacity, security readiness, and user experience—heading into the next year.

Where the Data Comes From

All figures are derived from aggregated, anonymized data observed across Cloudflare’s network. This is not a survey or a sample of select sites; it is a measurement of actual requests and attacks seen by one of the largest edge networks in operation. Trends are presented on a country, region, and industry basis, which allows for a detailed comparison of how different corners of the online world evolved.

Because the data reflects what Cloudflare’s infrastructure handles, it is particularly strong on the metrics that matter for CDN, DNS, and security operations. That means traffic patterns on major platforms, as well as attack activity targeting them, are well represented—though it does not cover the entire Internet, and it is weighted toward sites and services that use Cloudflare.

Beyond the principal charts, the Year in Review site offers tools for deeper exploration. Rather than a single top-level narrative, the report’s value is in its breadth of interactive graphs. Users are encouraged to drill into the sections that matter most for their own context—whether that is tracking the growth of a protocol, comparing internet quality metrics by country, or seeing which industries faced the most attacks in a given quarter.

This makes the report a useful starting point for capacity forecasting, for evaluating new security measures, and for understanding how global events or technology shifts have reshaped traffic patterns. The trends seen in the past year can inform what an organization might expect in terms of network load, user demand, and security threats going forward.

Get in Touch and Credits

The Cloudflare Radar team welcomes direct questions and feedback. You can reach them via email at [email protected], or on social media on X/Twitter as @CloudflareRadar, on Mastodon at noc.social/@cloudflareradar, and on Bluesky at radar.cloudflare.com.

Producing the report was a cross-disciplinary effort within Cloudflare. The data science work was led by Sabina Zejnilovic, Jorge Pacheco, and Carlos Azevedo. Design was handled by Arun Chintalapati and Reza Mohammady. The front-end development was done by Vasco Asturiano, Nuno Pereira, and Tiago Dias. João Tomé contributed research on the most popular online services. Project and engineering management were provided by Davide Marquês, Paula Tavares, and Celso Martinho, with many other colleagues contributing answers, edits, and ideas along the way.