What Cloudflare’s 2022 Internet Data Shows
With nearly five billion people online in 2022, aggregate internet usage data reveals meaningful behavioral and technical shifts. Cloudflare’s Radar 2022 Year In Review compiles these observations into interactive charts and maps, organized around three themes: traffic, adoption, and security. The analysis builds on last year’s report with new metrics and an improved methodology, so the underlying charts are not directly comparable year-over-year.
Visualizations are presented at weekly granularity from January 2 through November 26, 2022, covering almost 200 locations. Some smaller or less populated locations were excluded due to insufficient data. Cloudflare plans to update the datasets through the end of the year in early 2023.
Traffic Patterns
The traffic section of the report examines overall request volumes and highlights notable spikes or declines. These patterns often correlate with major global events, holidays, or shifts in user behavior. The accompanying interactive charts allow exploration of traffic changes by region and over time.
Adoption Trends
Adoption metrics focus on how users and organizations embraced new protocols and services. This year’s report adds several new adoption indicators, reflecting evolving usage of internet standards. The data illustrates which technologies gained traction and where they were most widely deployed.
Security Observations
The security section highlights attack patterns, threats, and mitigation activity observed across Cloudflare’s network. Trends in attack vectors or targeted industries are visible at a regional and global level. These insights can inform decisions about threat protection and risk management.
The full findings, with the ability to filter by location and time, are available on the Radar Year In Review site. For a deeper but curated narrative of the most notable observations, the sections below provide context for the data presented there.
Global traffic holds steady through a turbulent year
Despite widespread expectations of a slowdown, Cloudflare's data shows global Internet traffic grew 23% in 2022. To measure trends, Cloudflare established a baseline using the average daily traffic volume (excluding bots) during the second full calendar week of the year (January 9–15), chosen to allow normal routines to resume after the holidays. All trend lines represent a seven-day trailing average relative to that baseline, which smooths the volatility of daily measurements.
Globally, traffic saw nominal growth around the Beijing Winter Olympics before slipping, then dipped below baseline again heading into July. From that point, traffic experienced fairly consistent growth through the latter half of the year, with a noticeable upward inflection in late November. That rise was driven by a convergence of early holiday shopping and the run-up to the FIFA World Cup in Qatar.
War and weather leave their mark
Ukraine's traffic pattern closely tracked the war's progress. After an initial dip at the start of the year, traffic fell sharply following the Russian invasion on February 24 as infrastructure was damaged. Subsequent drops in May and June correlated with significant outages, while additional disruptions in September, October, and November coincided with widespread power outages from Russian attacks.
The dependence of Internet connectivity on reliable electric power was also evident in Puerto Rico. The island suffered two multi-day outages in 2022: a fire at a power plant in April caused a three-day disruption, and Hurricane Fiona in September resulted in a rapid traffic drop with outages lasting over a week until repairs were completed.
Category popularity: a global view
Analysis of traffic to Cloudflare's customer zones reveals which content categories were most popular, filtered to exclude bots. Each domain has one or more associated categories, and a request is counted within each applicable category. Globally, Technology sites accounted for approximately one-third of traffic throughout the year, followed by Business & Economy at roughly 15%. Shopping & Auctions saw a November bump as holiday shopping began.
Several locations diverged notably from the global pattern:
- South Korea: Internet Communication was consistently the second most popular category, with Entertainment and Business & Economy close behind.
- Turkey: Technology started the year on top but faded in the back half, ending below Shopping & Auctions and Society & Lifestyle, both of which grew from September onward.
- Armenia: Entertainment was the preferred category for nearly the entire year, while Gambling — usually second — fell sharply in November and was surpassed by Shopping & Auctions and Business & Economy.
Ranking the most popular services
This year's domain rankings were computed using the improved algorithms introduced with Radar 2.0, so direct comparison with last year's results isn't possible. Rankings also group domains belonging to a single Internet service (e.g., Google's various country domains are aggregated), while treating distinctly-perceived Meta brands like Facebook and Instagram separately.
Google topped the general ranking, followed by Facebook, with Apple and TikTok tied for third. The technology sector showed notable movement beneath the top tier: FTX, which hovered around the 9th position for most of the year, dropped precipitously after its November bankruptcy filing — likely tied to reports that it disabled withdrawals. Binance and Coinbase ranked #1 and #3 among cryptocurrency exchanges and appeared unaffected by FTX's collapse.
In the metaverse space, Roblox remained the top destination throughout 2022, despite Meta's heavy investment in Oculus — which nevertheless improved from 10th to 5th in the second half of the year. In social media, Facebook kept first place all year, with TikTok and Snapchat steady in the top five. Instagram overtook Twitter for 3rd place in August. LinkedIn, Discord, and Reddit frequently shuffled among positions six through eight.
Mastodon is another noteworthy riser. While operating 400 top instances on a decentralized, open-source model, its aggregate ranking improved steadily before jumping about 60 positions in November as interest spiked — echoed by growing user adoption covered elsewhere in this report.
Bots: a third of all traffic
Bot traffic — any non-human request, including search engine crawlers and malicious actors — accounted for roughly 30–35% of global traffic throughout the year. The ecosystem is diverse and dynamic: traffic started around 35% in January, dipped by nearly a quarter by end of February, and hovered just above 30% from spring through October. A slight November decline reflects rising human activity rather than fewer bots.
Two locations notably exceeded the global average. In Ireland, bots drove just under 70% of all traffic for most of the year (with two short mid-year spikes), while Singapore's bot traffic consistently ranged between 60–70%. Both countries host multiple cloud platform regions, and attackers frequently spin up ephemeral instances there to launch high-volume assaults such as the "Mantis" DDoS attack in June. These high bot percentages are largely attributable to cloud provider traffic originating from these geographies.
Twelve other locations cracked the top ten for bot traffic share at some point during the year; Turkmenistan spent the most time in the #1 spot. The list overall skewed toward Europe and Asia.
Outages: from backhoes to bullets to blackouts
Disruptions occur for many reasons, from natural disasters to cable cuts to government directives. Radar's Outage Center now catalogs them systematically, and several outages stood out in 2022.
On July 8, Canada's Rogers Communications (AS812) experienced a near complete loss of traffic that took roughly 24 hours to recover. The outage, attributed to a failed maintenance update in the core network, affected an estimated five million users and took down phone systems, point-of-sale terminals, ATMs, and online banking.
Following the death of Mahsa Amini in Tehran, protests erupted across Iran; in response, three mobile network operators (AS44244/Irancell, AS57218/RighTel, and AS197207/MCCI) imposed daily "curfews" starting September 21, usually between 1600 and midnight local time. Over 75 million subscribers were impacted, and broader shutdowns continued through October.
The Hunga Tonga–Hunga Ha'apai eruption damaged the submarine cable connecting Tonga to Fiji, causing a 38-day outage for the nation. Only minimal traffic from satellite services was seen until Digicel announced the main island's restoration on February 22; domestic cable repairs affecting outlying islands were expected to take another six to nine months.
Ukraine's network outages continued to correlate with ground conflict. In March, war zones like Mariupol suffered outages; in late May, an extended disruption in Kherson began when that region's ISP (AS47598) rerouted via Russian network Miranda (AS201776). Widespread power outages in October hit Kharkiv, Lviv, Kyiv, and other regions. Many of these disturbances are tracked in more detail in quarterly disruption summaries and Ukraine-specific blog posts from Cloudflare.
Technology Adoption Trends in 2022

Cloudflare's visibility into traffic across millions of websites and the operation of a major public DNS resolver provides a useful vantage point for measuring how quickly new technologies and platforms gain traction. Data from 2022 showed notable growth for satellite Internet provider SpaceX Starlink, whose traffic increased 15x over the year, and for the decentralized social networking platform Mastodon, which saw a surge of interest in the final months of the year.
IPv6 adoption remained a slow-burn story, holding steady at roughly 35% globally. Meanwhile, mobile devices continued to cement their position as the primary way many people reach the Internet, with significant variation by region.
Starlink: From Emergency Connectivity to Steady Growth
Satellite Internet delivered from geostationary orbit has existed for years, but high latency and limited throughput made it a poor substitute for terrestrial broadband. Starlink's Low Earth Orbit constellation, which began launching in 2019, changed that calculus by bringing fiber-like performance to areas where wired or wireless broadband was previously unavailable or inadequate. Throughout 2022, Cloudflare tracked aggregate traffic associated with Starlink's autonomous system (AS14593) to gauge how the service was expanding.
The war in Ukraine provided an early and urgent use case. After Russia's invasion in late February, Starlink terminals were activated in the country, and Cloudflare began observing traffic within days. Volume from Ukraine grew consistently for the rest of the year, reflecting the service's role in maintaining connectivity where traditional infrastructure had been damaged.
Interest wasn't limited to conflict zones. In Romania, which was added to Starlink's service footprint in May, traffic climbed rapidly following the announcement. In the United States, where Starlink has operated since launch, traffic grew more than 10x through November. Service enhancements announced during the year — including support for moving vehicles, boats, and planes — suggest further growth is likely as the service expands its addressable use cases.



Mastodon: A Late-Year Inflection Point
Mastodon's profile rose sharply in late 2022, following months of turbulence at Twitter. To quantify this shift, Cloudflare analyzed request volume from its 1.1.1.1 resolver for domain names associated with 400 of the largest Mastodon instances. The resulting data shows that while interest existed throughout the year, it was far from evenly distributed geographically — many locations showed little or no traffic at all.
At a global level, resolver traffic for these Mastodon domains was steady through the first nine months of the year, with a noticeable uptick in late April coinciding with the announcement that Elon Musk had agreed to acquire Twitter for $44 billion. The trajectory changed more dramatically in October as the acquisition moved toward completion, with further growth in November after the deal closed. This pattern likely reflects a combination of dormant accounts reactivating and new users joining the platform.
The United States saw a similar pattern: a small base of existing users, then a sharp increase starting in late October. Interestingly, Germany — where Mastodon's core developer lives and where the project is incorporated as a not-for-profit — showed no particular home-field advantage. Query volume there stayed relatively low for most of the year before accelerating at the end of October, matching the behavior seen elsewhere.


IPv6: Stuck at a Third, With Bright Spots
IPv6 has existed for nearly a quarter-century, yet adoption remains modest even as the exhaustion of IPv4 address space and the proliferation of connected devices make the newer protocol increasingly essential. Cloudflare has supported IPv6 since 2011 and uses traffic to its network to measure adoption rates. The calculation focuses on customer zones with IPv6 enabled — "dual stacked" zones — and measures the share of requests served over IPv6 out of total IPv4 and IPv6 traffic, after filtering out bots.
Globally, IPv6 adoption hovered around 35% throughout 2022. While it's encouraging that roughly one in three requests to dual-stacked properties now travels over IPv6, the plateau suggests significant room for improvement. The rankings among leading countries remained fairly stable, though not entirely static. India held the top spot for the entire year, with adoption above 70% through July before slipping a few percentage points in late summer. A key driver is Jio, India's largest mobile operator, which began its IPv6 rollout in late 2015 and now runs much of its core network as IPv6-only, with dual-stack customer-facing connections.

More encouraging are the 60-plus locations that at least doubled their IPv6 adoption rates during the year. One of the most dramatic turnarounds was in Georgia, which grew more than 3,500% to end the year at 10% adoption, thanks to subscriber-side IPv6 support rolled out by telecom provider Magticom in February and March. Many other locations in this group saw similar step-change gains when a local provider flipped the switch.
The broader picture is more sobering. Even among the locations that doubled adoption, more than 50 ended the year below 10%, and over half of those remained under 1%. The providers that have embraced IPv6 are making real progress, but the many that haven't yet represent the next frontier for deployment.

Beyond India's clear lead, the rankings saw some jockeying. Saudi Arabia and Malaysia traded the second and third spots throughout the year, with adoption just under 60% and around 55%, respectively. Belgium was the model of consistency, holding fourth place from March through November with about 55% adoption. The United States appeared in the top 10 during the first quarter but ranked lower for the rest of the year. In total, 14 different locations appeared in the top 10 at some point during 2022.
Looking ahead, the upward movement in more than a quarter of all surveyed locations is a positive sign, but the low baseline in many of those same places underscores how much work remains.
Mobile Devices Dominate in Many Regions
For an increasing share of the world's Internet users, a mobile device isn't just one option among many — it's the only way to get online. Cloudflare classifies the device type associated with each content request and calculates the mobile share of traffic by week, after filtering out bots, to track this trend by location.
The top 10 chart for mobile usage showed Iran and Sudan occupying the top two positions for most of the year, with Yemen leading in January and Mauritania taking over in November. Below those top two spots, the rankings were highly volatile month to month, but that movement masked a fairly narrow range of values: top-ranked locations saw 80-85% of traffic from mobile devices, while those at the bottom of the top 10 saw 75-80%. The seemingly dramatic reshuffling was concentrated within a five-to-ten-percentage-point band.
The data also sheds light on the importance of mobile networks to daily life in Iran, where mobile providers were targeted by Internet shutdowns in September and October — and where the country's disappearance from the top 10 after September reflects those disruptions.

How Attacks Were Mitigated in 2022
Cloudflare’s security portfolio offers multiple ways to stop malicious traffic, and the technique used often depends on the attack. These “mitigation sources” include the Web Application Firewall (WAF), DDoS Mitigation, IP Reputation (IPR), Access Rules (AR), Bot Management (BM), and API Shield (APIS). Analysing which of these sources is applied by location reveals what kinds of attacks originate from different parts of the world.
To measure this, Cloudflare divided the total number of daily mitigated requests for each source by the total number of mitigated requests that day. Bot traffic is included, since many attacks come from bots. Where a request is mitigated by multiple techniques, the last one applied is the one counted.
Across most locations, IP Reputation, Bot Management, and Access Rules accounted for only small shares of mitigated traffic, with country-level variation. Elsewhere, these sources did more of the work, suggesting some locations had more traffic blocked outright. In several countries, DDoS-mitigated traffic jumped rapidly to 80–90% of the total in January before falling just as quickly to 10–20%. Both DDoS Mitigation and WAF shares were frequently spiky, with only occasional sustained periods of stability.
Globally, DDoS Mitigation and WAF were the two most-used techniques. DDoS Mitigation’s share peaked in mid-January at nearly 80%; WAF’s peak came in February, at almost 60%. A clear spike in Access Rules usage appears in August, matching similar jumps seen for the United States, United Arab Emirates, and Malaysia.

US-originating traffic saw Access Rules account for up to 20% of mitigations in August, but far less for the rest of the year. DDoS Mitigation handled over 80% of such traffic in the first quarter before steadily declining through August. WAF followed a complimentary path: roughly 20% of mitigations early in the year, tripling by August. The rise in Access Rules after a rapid growth and decline in WAF usage suggests targeted rules were added to supplement managed WAF rules against US-originated attacks.

German traffic was more frequently mitigated by Access Rules and IP Reputation, with Bot Management also getting more use in February, March, and June. Except for periods in February and July, DDoS Mitigation handled the bulk, generally 60–80%. WAF mitigation peaked in February at 70–80% and again in July around 60%.

For traffic from Japan, two notable Bot Management spikes stand out: one in March above 40%, another in June half that size. Access Rules held a steady ~5% share through August, tapering slightly after. WAF and DDoS Mitigation traded the top spot without a clear cycle, each reaching as high as 90% — WAF in February, DDoS Mitigation in March. DDoS Mitigation’s stretches in the lead were more sustained, lasting weeks, punctuated by brief WAF spikes.

WAF Rule Distribution
Cloudflare’s WAF applies hundreds of managed rules, grouped into over a dozen types. Looking at the distribution per location shows attack techniques in use — for example, SQL injection attempts versus exploits of a published CVE. The figures below divide weekly WAF-mitigated requests by rule type; only the last rule applied to a single request is counted. Bot traffic is included.
Worldwide, in the first months of 2022 about half of HTTP requests blocked by Managed WAF Rules contained HTTP anomalies — malformed method names, null byte characters, non-standard ports, or POST requests with zero content length. Directory Traversal and SQL Injection (SQLi) rules each covered just over 10%. Starting in May, attackers diversified: Cross Site Scripting (XSS) and File Inclusion both grew past 10%, while HTTP anomalies fell under 30%. Software Specific rules grew above 10% in July, suggesting increased attempts to exploit vendor-specific vulnerabilities. Broken Authentication and Command Injection rules also saw more activity in the last months, pointing to more attacks on login systems and command execution attempts.

Australia’s WAF-mitigated traffic used many rulesets, with the top one changing frequently in the first half of the year. HTTP Anomaly led for a single week in February, just above 30%. Otherwise, Software Specific, Directory Traversal, File Inclusion, and SQLi rules each handled roughly 25–35%. From July onward, Directory Traversal took the lead for the rest of the year. After a June peak, SQLi attacks fell sharply and stayed below 10%.
Canada showed a different pattern. HTTP Anomaly started the year at about two thirds of mitigations, but halved by the end of January and remained volatile. SQLi attacks followed the opposite trajectory: below 10% to start, then growing to 60% or more at multiple points. These SQLi waves from Canada often lasted several weeks before receding.
In Switzerland, HTTP Anomaly never led, though it stayed in the top five all year. Directory Traversal and XSS rules were most frequent, each reaching up to 40%. Directory Traversal held the top spot most consistently, though XSS was most prevalent in August. SQLi peaked in April, July/August, and again in late November. Software Specific rules saw breakout growth in September, reaching up to 20%.
Attack Targets by Industry
Applying a mitigation lens to content categories reveals which types of sites attract the most attacks as a fraction of their traffic. Cloudflare divided weekly mitigated requests for a category’s domains by total requests mapped to that category; percentages therefore do not sum to 100%. Bot traffic is included.
Globally, the leading target category shifted often. Technology sites had the largest share through January and February, at 20–30%. From there, no category held the top slot for more than a few weeks. The largest single spike hit Travel sites in mid-April, when over half of that category’s traffic was mitigated. With the start of the World Cup in late November, Gambling and Entertainment sites saw the largest mitigated shares.

United Kingdom-originated attacks on Technology sites held near 20% all year. When not the top targeted category, roughly half a dozen others took turns. Travel saw two bursts — nearly 60% of traffic mitigated in April and nearly 50% in October. Government & Politics, Real Estate, Religion, and Education each led at different times. Entertainment attacks from the UK jumped in late November, hitting 40%.
US trends mirrored the global view early: Technology sites led in January and February at 30–40%, then attackers shifted. Travel peaked in mid-April above 60%. From May, Gambling was most frequently the most-mitigated category, usually 20–40%, spiking to 70% in late October/early November.
Japan saw far smaller attack shares across categories, mostly below 10%, with brief exceptions. Government & Politics spiked to nearly 80% in late March. Travel jumped close to 70% at about the same time. Religion exceeded 60% in late June, and Gambling rose just past 40% a couple of months later — that Gambling wave receded before rising again aggressively in October.
Top Origins of Phishing Email
For customers on Cloudflare Area 1 Email Security, Cloudflare geolocates the IP addresses sending phishing emails. Rankings are based on weekly phishing volume per location, processed by Area 1 only.
The United States was the top source of observed phishing emails through nearly all of 2022, ceding the lead just once, to Germany in November. The rest of the top 10 churned considerably: 23 locations occupied a top-10 spot for at least a month during the year. These were geographically spread across the Americas, Europe, and Asia, confirming that no single region dominates email-based threats. Blocking all mail from these places is impractical, but extra scrutiny of their traffic is a reasonable precaution.
Takeaways From the 2022 Data
Looking back at a year's worth of traffic patterns across Cloudflare's network, a few themes stand out that are worth keeping in mind heading into 2023.
Security remains a top concern. Attack traffic in 2022 originated from nearly every corner of the globe, with the targets and techniques shifting constantly throughout the year. This environment demands a security provider with a broad portfolio of defenses—no single tool is sufficient to protect sites, applications, and infrastructure when the threat landscape is this varied and dynamic.
IPv6 adoption is no longer a future consideration but a present necessity. Internet service providers worldwide need to accelerate their support for the protocol. As the pool of available IPv4 addresses continues to shrink, the cost of acquiring them will only climb, making IPv6 the only sustainable path forward for network growth.
Government-imposed internet shutdowns also emerged as a defining trend of 2022, deployed with increasing frequency to sever both domestic communications and a country's connection to the outside world. This practice carries serious consequences, as the United Nations noted in a May 2022 report: "Blanket shutdowns in particular inherently impose unacceptable consequences for human rights and should never be imposed."
The full Cloudflare Radar 2022 Year In Review website offers interactive visualizations across nearly 200 locations. We encourage you to explore the trends specific to the regions and industries that matter to your organization, so you can assess how these patterns might affect your operations in the year ahead.
Questions about the data can be directed to the Cloudflare Radar team at [email protected] or via Twitter at @CloudflareRadar.



