2024 in Review: Cloudflare Radar’s Annual Look at Internet Trends
Cloudflare has published its fifth annual 2024 Year in Review, aggregating data from its global network to offer a snapshot of how the Internet evolved from January 1 to December 1, 2024. The report covers traffic patterns, technology adoption, connectivity quality, security threats, and email abuse across 200 countries and regions. The interactive microsite allows for side-by-side comparisons against previous years and between specific geographies.
Traffic and Adoption
Cloudflare’s network, spanning more than 330 cities in over 120 countries, serves an average of over 63 million HTTP(S) requests per second and over 42 million DNS requests per second. From this vantage point, the data reveals a clear tug-of-war between mobile and desktop access. Mobile devices accounted for 41.3% of global traffic, and in nearly 100 countries, mobile represents the majority of all traffic.
On the device front, Apple iOS drove nearly one-third of global mobile traffic. Android’s dominance was particularly stark in 29 countries where it held over a 90% share, while iOS exceeded 60% in eight countries. In the browser arena, Google Chrome remains the overwhelming leader overall. Safari takes a commanding lead over Chrome on iOS devices, while Microsoft Edge is the second most-used browser on Windows, owing to its preinstalled default status.
Protocols and Development Technologies
Adoption of modern web protocols inched upward: nearly half of web requests used HTTP/2, and 20.5% used HTTP/3, both slightly up from 2023. Among the technologies powering websites, React, PHP, and jQuery remain prominent, and HubSpot, Google, and WordPress are the leading vendors of supporting services and platforms. A notable shift appeared among automated API requests, where Go surpassed Node.js as the most popular language.
Search engine preferences show strong regional variation. Google is the dominant search engine globally across every platform, though the runner-up varies: Baidu holds a distant second on mobile and operating systems, Bing does so on desktop and Windows, and DuckDuckGo ranks second on macOS. Chrome is the most used browser on macOS as well, but Safari is clearly ahead on iOS.
Connectivity
Connectivity quality and resilience varied widely. The top 10 countries by download speed all averaged more than 200 Mbps, with Spain consistently appearing among the leaders across Cloudflare’s Internet quality metrics. IPv6 adoption continues to grow unevenly: 28.5% of IPv6-capable requests were made over IPv6 throughout the year, led by India (68.9%) and Malaysia (59.6%). A separate signal: 20.7% of TCP connections were unexpectedly terminated before any useful data was exchanged, a metric Cloudflare associates with network tampering.
Reliability was a challenge in many regions. Cloudflare observed 225 major Internet outages during 2024, many caused by government-directed shutdowns of national or regional connectivity. Cable cuts and power outages were also significant contributors.
Security Landscape
Cloudflare’s systems mitigated 6.5% of global traffic as potentially malicious or for customer-defined reasons. That share exceeded 10% in 44 countries. South Korea saw 8.1% of its traffic mitigated, down slightly, while the United States rose to 5.1%. Bots remain a heavy burden: the United States alone generated over a third of global bot traffic, with Amazon Web Services responsible for 12.7% of that activity and Google for 7.8%.
Attack targeting shifted this year, with Gambling/Games becoming the most attacked industry, narrowly surpassing Finance from the prior year. Threat actors also continued weaponizing aging vulnerabilities: Log4j, first disclosed in 2021, remained an actively exploited target throughout 2024. On the defensive side, routing security improved; RPKI valid IPv4 address space grew 4.7% and valid routes increased 6.4% over the year.
Email Threats
Email security data showed that an average of 4.3% of emails processed were malicious, a figure inflated by sharp spikes in March, April, and May. Deceptive links and identity deception were the top threat types. Certain top-level domains proved especially risky: more than 99% of email messages from the .bar, .rest, and .uno TLDs were classified as spam or malicious.
The full dataset, including country-specific trends, year-over-year changes, and comparisons between regions, is available on the Year in Review microsite. The report also has a companion post focusing on trends among top Internet services.
Internet traffic: growth patterns and notable events
Cloudflare Radar measures traffic trends using the second full calendar week of January (January 8-15, 2024) as a baseline, allowing time for normal routines to resume after the holidays. Global traffic remained within a few percentage points of that baseline through mid-August, but then began accelerating consistently. By the end of November, worldwide traffic had grown 17.2% for the year.

Internet traffic trends worldwide in 2024
Guinea saw the most dramatic growth of any country, with traffic reaching 350% above baseline. The increase began in late February, peaked in early April, and stayed between 100% and 200% above baseline through the summer. While Guinea also saw growth in the September-November period in 2023, that year peaked at under 90% above baseline.
Major outages show up clearly in the data. Cuba experienced two large traffic drops in the fall: an October 18 collapse of the national electricity grid caused a disconnection lasting just over three days, and Hurricane Rafael triggered widespread power outages on November 6. Cuba's traffic has remained depressed since, as the country's electrical infrastructure continues to struggle.

Internet traffic trends in Cuba in 2024
Government-directed shutdowns also leave visible marks. In Bangladesh, authorities ordered mobile Internet shut down on July 18 in response to student protests, and fixed broadband was shortly taken offline as well. The near-complete loss of national connectivity was only gradually restored between July 23-28.
Holiday patterns appear too. Indonesia and the United Arab Emirates both show noticeable traffic dips around April 9-10, during the Eid al-Fitr festival that ends the Ramadan fast.
Most popular Internet services in 2024
Google again ranked first overall in Cloudflare's analysis of 1.1.1.1 public DNS resolver query data, helped by its broad portfolio and the popularity of Android devices. Meta's Facebook, Instagram, and WhatsApp also made the top 10. Generative AI traffic continued to grow, with OpenAI keeping the top position in its category on the strength of ChatGPT. The top five social media services — Facebook, TikTok, Instagram, X, and Snapchat — remained unchanged from previous years.
Starlink traffic continues rapid expansion
Starlink remains the leading satellite Internet provider, and Cloudflare measured worldwide traffic associated with its primary autonomous system (AS14593) growing 3.3x in 2024, matching the prior year's pace. Growth was steady through most of the year, accelerating in November, possibly driven by large customer software updates.

Starlink traffic growth worldwide in 2024
New markets show pent-up demand. Zimbabwe announced service availability on September 7, and traffic began growing almost immediately.
Growth in newer markets continued through the year in many countries. Malawi, where Starlink launched in July 2023, saw traffic grow 38x in 2024. Georgia, with service available since November 2023, saw over 100x growth after a slow start. Paraguay announced service on December 21, 2023, then registered over 900x growth after ramping up at the beginning of January.
IPv4 traffic: a Hilbert curve view of the Internet
Cloudflare's Year in Review includes a Hilbert curve visualization of aggregated IPv4 request traffic from January 1 through December 1, 2024. IP addresses are grouped in /20 blocks, meaning each square at the highest zoom level represents traffic from 4,096 addresses. Zooming in progressively reveals the autonomous system and country associated with each block. Warmer shading indicates higher request volume. Attribution at the default level shows the Regional Internet Registry for most address space, with pre-RIR blocks labeled by the owning organization.

Hilbert curve of aggregated 2024 traffic to Cloudflare across the IPv4 Internet
The address block generating the most requests in 2024 was, as in 2023, 66.249.64.0/20, owned by Google. That space is used by the Googlebot web crawler to retrieve content for search indexing — an explanation consistent with high request volumes given how many web properties sit on Cloudflare's network. Other top-20 prefix owners include Alibaba, Microsoft, Amazon, and Apple.
AI bot and crawler traffic trends
Cloudflare customers gained the ability to block AI crawlers with a single click in July, and AI Audit added deeper visibility into how AI platforms access site content. The AI bot and crawler traffic graphs on Radar, launched in September, show divergent patterns for two prominent bots. Bytespider, ByteDance's crawler used to download LLM training data, steadily declined through the year, with late-November activity down 80-85% from January levels. ClaudeBot, Anthropic's crawler, was largely absent until mid-April aside from small spikes potentially representing test runs. Traffic was more consistently non-zero from late April onward, but fell after an early peak.

Traffic trends for AI crawlers Bytespider and ClaudeBot in 2024
Post-quantum encryption adoption grows
Post-quantum cryptography — techniques designed to protect data against future decryption by sufficiently powerful quantum computers — saw mainstream adoption begin in 2024. Cloudflare enabled post-quantum key agreement by default on its network in October 2022, but it still requires client support. Google's Chrome 124 turned it on by default on April 17, and adoption among TLS 1.3 requests grew from just over 2% to around 12% within a month, reaching 13% by the end of November. Further growth is expected into 2025 from other Chromium-based browsers, growing default support in Mozilla Firefox, and initial testing in Apple Safari.

Growth of post-quantum encrypted TLS 1.3 traffic during 2024
Platform Wars: iOS vs. Android








Outages, IPv6, and Connection Health in 2024
Government-directed shutdowns drove most of the year's Internet outages
Cloudflare's global visibility allows it to track disruptions to Internet connectivity around the world. In 2024, 225 major outages were observed, with many attributed to government-directed regional and national shutdowns. The Cloudflare Radar Outage Center, which uses Cloudflare traffic data for insights, recorded events that ranged from a few hours to several weeks. Notable long-lasting disruptions included an eight-day outage in Haiti in September, caused by repair crews being barred from a damaged submarine cable, and a 10-day shutdown in Bangladesh in July affecting mobile and fixed providers. Conversely, Iraq saw repeated multi-hour shutdowns during exam periods in June through September, contributing to visible clustering on the timeline.
Over half of the recorded outage reasons in 2024 were government-directed shutdowns. The interactive timeline and map on the Year in Review microsite allow users to hover over events for metadata and filter by country or region to see specific outage reasons.

Global IPv6 adoption grew modestly, led again by India
IPv6, whose specification dates back to 1995, was designed to address the limitations of IPv4, which has long been exhausted. With providers paying $30-$50 per IPv4 address, the pressure to adopt IPv6 persists. Cloudflare has advocated for IPv6 since its Automatic IPv6 Gateway in 2011 and has offered it by default since 2014, though not all customers keep it enabled. Server-side support is only half the equation; end-user connections also need to support it.
At the global level, 28.5% of IPv6-capable, or dual-stacked, requests were made over IPv6 in 2024, up from 26.4% in 2023. India remained the leader at 68.9%, largely due to 94% adoption at Reliance Jio. Malaysia followed at 59.6%, with Saudi Arabia the only other country above 50%, at 51.8%. This contrasts with 2023, when Vietnam, Greece, France, Uruguay, and Thailand also exceeded that threshold. Adoption rates still vary widely, with 34 countries/regions, many in Africa, below 1%, and 96 below 10%.

Spain leads on connection quality
Data from speed.cloudflare.com tests, aggregated geographically, shows that all top 10 countries by Internet speed averaged download speeds above 200 Mbps. In 2024, Spain stood out: it led in download speed (292.6 Mbps) and upload speed (192.6 Mbps), and placed second globally for loaded latency (78.6 ms). Spain's performance is supported by strong progress toward EU "Digital Decade" objectives, with fiber-to-the-premises coverage at 95.2% and 5G coverage at 92.3%. High-speed fiber packages are also relatively affordable, with 100 Mbps to 1 Gbps plans priced between €30 and €46 per month. Speed distributions for Spain show clusters around 100 Mbps and 300 Mbps, with 87% of idle latency measurements under 50 ms and 65% of loaded latency measurements under 100 ms, supporting good experiences for gaming and videoconferencing.

Mobile traffic share holds steady
With roughly 70% of the world's population using smartphones, mobile devices are a primary means of Internet access. Analysis of user agent information in requests to Cloudflare at a global level shows that 41.3% of traffic came from mobile devices in 2024, with 58.7% coming from desktops. These figures are consistent with 2023 and 2022, indicating a "steady state" for mobile usage. In Sudan, Cuba, and Syria, over 77% of traffic came from mobile devices, making them the leaders in 2024. Countries/regions with majority mobile traffic were concentrated in the Middle East/Africa, Asia Pacific, and South/Central America.

TCP anomalies reveal network health signals
Cloudflare passively measures rates of connections that are unexpectedly terminated before useful data exchange. These anomalies can stem from DoS attacks, client behavior, or third-party tampering (e.g., network filtering). The global assessment of third-party connection tampering and the blog post on TCP resets and timeouts offer deeper analysis of this phenomenon.
Insights into these anomalies were launched on Cloudflare Radar in September. The system tracks the stage at which a connection unexpectedly closes: "Post SYN" (after a SYN packet but before an ACK), "Post ACK" (after acknowledgement but before useful data), and "Post PSH" (after a PSH packet indicating the requested resource). Aggregate global data for 2024 shows that over 20% of connections are terminated unexpectedly, with nearly half of those "Post SYN," often linked to DoS attacks or Internet scanning. Post-ACK (3.1%) and Post-PSH (1.4%) anomalies are more frequently associated with connection tampering, especially at high rates in specific networks.

Security in 2024: Mitigation Trends, Bot Traffic, and Persistent Threats
Cloudflare’s systems mitigated 6.5% of all global traffic in 2024 for reasons ranging from malicious activity to customer-defined rules. This represents an increase of nearly one percentage point from the 2023 figure. Of that total, only 3.2% was blocked specifically as a DDoS attack or by WAF Managed Rules, a rate slightly above the previous year. While more than 10% of traffic from 44 countries or regions had some form of mitigation applied, only seven saw DDoS or WAF mitigations exceed that threshold.
Country-level data shows significant variance. Albania recorded one of the highest overall mitigated traffic shares at 42.9%, while Libya led in DDoS/WAF-specific mitigations at 19.2%. The United States, highlighted in last year’s report, saw its mitigated traffic share rise to 5.0% from 3.65% in 2023. Conversely, South Korea’s share dipped slightly to 8.1%, down from 8.36% the year prior.

Bot Traffic Origins
Analysis of bot traffic sources reveals a heavy concentration. The top 10 countries accounted for 68.5% of observed bot traffic, with the United States alone responsible for half of that share—over five times that of second-place Germany. Cloud platforms remain dominant sources of bot traffic due to their low-cost, ephemeral compute resources and high-bandwidth connectivity. Amazon Web Services was the leading source network, generating 12.7% of global bot traffic, followed by Google at 7.8%. Microsoft, Hetzner, Digital Ocean, and OVH each contributed more than one percent.

Not all bot traffic is malicious; Cloudflare maintains a list of verified bots used for search engine indexing, performance testing, and availability monitoring. However, tracking bot origins helps site owners identify and block potentially harmful automated activity.


Most-Attacked Industries
The Gambling/Games industry emerged as the most targeted sector in 2024, capturing 6.6% of global mitigated traffic. This edged out Finance, which led the 2023 list and also registered at 6.6% before rounding. Attack patterns followed seasonal events: Gambling/Games sites saw peak mitigation activity in January and early February, coinciding with NFL playoffs leading into the Super Bowl. Finance organizations experienced their heaviest attacks in May, reaching 15.3% of mitigated traffic during the week of May 13—consistent with findings from the Q2 2024 DDoS threat report.
Weekly peaks varied notably by industry throughout the year. Attacks on People & Society organizations spiked to 19.6% of mitigated traffic in the first week of January. The Autos & Vehicles industry saw its highest share at 29.7% during the week of January 15, while Real Estate peaked at 27.5% in the week of August 26.

Log4j Persists as an Active Threat
Three years after its initial disclosure, the Log4j vulnerability remains a significant attack vector. Normalized daily attack activity for Log4j trended upward through 2024, with notable spikes in the first half of the year and again in October and November. Compared to other vulnerabilities, Log4j exploitation activity ranged from approximately four times to over twenty times that of Atlassian Confluence Code Injection. Against aggregated attack activity for 2024 Authentication Bypass and Remote Code Execution vulnerabilities, Log4j activity reached as much as one hundred times higher.

Continued Progress in Routing Security
Global routing security improved steadily throughout 2024, measured through Resource Public Key Infrastructure (RPKI) implementation. RPKI cryptographically signs records associating BGP route announcements with their correct originating autonomous system, helping prevent route hijacks and leaks—provided networks validate these signatures and filter invalid announcements.
Globally, valid IPv4 routes increased by 6.4 percentage points, from 43.4% to 49.8%, while valid IPv6 routes rose 3.2 percentage points to 56.9%. This trajectory suggests over half of IPv4 routes will be RPKI valid by year’s end. IP address space covered by valid routes also grew: IPv4 coverage increased 4.7 percentage points to 43.6%, and IPv6 coverage rose 3.3 percentage points to 60.9%.
Notable national improvements occurred during the year. Spain, which began 2024 with less than half of its routes RPKI valid, saw a dramatic jump on February 15 when AS12479 (Orange Espagne) signed records for 98% of its previously “unknown” prefixes. This immediately drove IPv4 validity to 76%, reaching 81% by December 1, and IPv6 to 91%, climbing to 92.9% by the same date. Cameroon experienced a significant shift when AS36912 (Orange Cameroun) signed records for all its IPv4 prefixes in late January, more than doubling covered IPv4 space from 32% to 82%.




Email Security: Malicious Traffic and Dangerous Domains
Email remains a critical business tool and a prime entry point for attackers, despite the growth of collaboration platforms. Attackers deploy targeted malicious messages that impersonate legitimate senders, lure users to deceptive links, or carry dangerous attachments. Cloudflare Email Security defends against these threats; across 2024, an average of 4.3% of analyzed emails were found to be malicious.
Weekly aggregated data showed spikes above 14% in late March, early April, and mid-May. These peaks appear linked to targeted “backscatter” attacks, where attackers flood a target with undeliverable messages that bounce to a victim whose address was set as the reply-to:.

Deceptive Links and Identity Deception Dominated Threats
Malicious emails often combine multiple attack techniques, known as threat categories. Averaged across 2024, 42.9% of malicious messages contained deceptive links, with that share reaching 70% at certain points. Activity for this category was spiky, with lows observed between March and May and a general downward trend from July through November.
Identity deception was similarly prevalent, appearing in up to 70% of analyzed emails during several weeks and averaging 35.1% across the year. Its activity pattern resembled that of deceptive links, with peaks and valleys often coinciding; at times, identity deception surpassed deceptive links in prevalence.
Extortion saw the most notable shift. After appearing in 86% of malicious emails during the first week of January, its share declined steadily throughout the year, ending November below 10%.

High-Risk Top Level Domains
Cloudflare Radar includes email security insights that identify “dangerous domains”—top level domains (TLDs) sourcing the most spam or malicious email. The analysis is based on the sending domain’s TLD from the From: header; for a message from [email protected], the sending domain is example.com and the TLD is .com.
In aggregate for 2024, the .bar, .rest, and .uno TLDs were the most dangerous, with over 99% of analyzed emails from each characterized as spam or malicious. These TLDs are at least a decade old and have between 20,000 and 60,000 registered domains each. By malicious email share specifically, Western Samoa’s .ws ccTLD led with over 90% of emails categorized as malicious. In spam share, .quest topped the list with over 88% of its emails characterized as spam.





