Q1 2022 Internet Disruptions: A Global Review

Cloudflare's global network, spanning more than 250 cities in over 100 countries, offers a unique vantage point for observing Internet resilience. During the first quarter of 2022, we documented numerous disruptions to global connectivity. These events stemmed from a variety of causes, ranging from physical incidents like severed fiber cables to intentional government-directed shutdowns. The following is a review of key Internet outages observed during this period, supported by traffic data from Cloudflare Radar.

Geophysical Events: Volcanoes and Earthquakes

While errant backhoes are a common culprit for connectivity loss, the first quarter also saw disruptions from more momentous earth movement. The Hunga Tonga–Hunga Ha'apai volcanic eruption on January 14 caused significant damage to the submarine cable connecting Tonga to Fiji, isolating the island nation for 38 days. During this period, only minimal traffic from satellite services was observed. The main island’s connectivity returned on February 22 after Digicel announced the initial submarine cable repairs were complete, an event visible as an immediate traffic spike. However, repairs to the domestic cable serving outlying islands were estimated to take an additional six to nine months.

BLOG-1570 Embedded Image - ALSULI

In contrast, the impact of a 7.3 magnitude earthquake off the coast of central Japan on March 16 was notably shorter and smaller. Occurring around 1436 UTC, the quake caused power outages that led to a loss of connectivity in cities including Tokyo for several hours. This incident differed from a magnitude 8.9 earthquake eleven years earlier, which had a nominal impact on Japanese connectivity, seemingly due to subsea cable damage.

BLOG-1041 Embedded Image - QcTLks

Physical Infrastructure Failures

Internet resilience is inherently tied to the robustness of its underlying physical layer, and damage to this infrastructure frequently leads to significant outages. On January 5, the Gambia was completely isolated from the global Internet for over eight hours. A failure of the primary ACE submarine cable link prompted traffic to be routed onto two backup links through Senegal. These backup links failed concurrently, as they converged at a location that was identified as the single point of failure.

BLOG-923 Embedded Image - Wk2QxL

Around 2130 UTC on January 20, Internet traffic to Yemen dropped to near zero after ongoing airstrikes reportedly hit a telecommunications building where the FALCON undersea cable lands. The four-day outage, which primarily affected the state-owned provider YemenNet, finally recovered around 2100 on January 24.

BLOG-1041 Embedded Image - MKWFQ6

On March 1, Tasmania suffered a 6.5-hour Internet outage after two of its three submarine cables connecting it to the Australian mainland were cut. The cuts, one on the mainland end and another on the Tasmanian side, were both attributed to “third parties,” leading to a significant reduction in traffic between 0130 and 0800 UTC.

BLOG-1041 Embedded Image - mLX3oS

A reported fire at a Telecom Infrastructure Company (TIC) data center in Iran caused a four-hour disruption on March 4. TIC is the monopoly provider of telecom infrastructure in the country, and traffic dropped by approximately 20% at 0640 UTC before recovering around 1030 UTC.

BLOG-1041 Embedded Image - SBVkjm

A fiber optic cable cut on a public road in Cuba’s capital caused a disruption beginning just after 1200 UTC on March 15. The outage, reported by state telecommunications company ETECSA, lasted for over six hours.

BLOG-1041 Embedded Image - ZTPqcS
BLOG-1041 Embedded Image - DgYSIc

Similarly, a March 24 disruption in Venezuela, initially believed to be a power outage, was ultimately traced to a fiber cut. The incident caused a significant traffic drop for CANTV customers across multiple states between 1140 and 1740 UTC. VE sin Filtro reported several additional multi-hour, multi-state disruptions in Venezuela during the quarter.

BLOG-1041 Embedded Image - ePL2FK

On March 31, Internet traffic to Telenor Pakistan dropped 60% between 0600 and 0745 UTC due to multiple fiber-optic cable cuts in various locations. Services were reported as fully restored just after 1800 UTC.

BLOG-1041 Embedded Image - Dk5OTx

Power Grid Dependencies

Reliable electrical power is critical for Internet connectivity. Loss of power can take down core data centers and routers, impacting both customers and connected networks. The interconnected electrical grids of Kazakhstan, Uzbekistan, and Kyrgyzstan all suffered outages on January 24 after the North-South power line was disconnected, leading to multi-hour Internet disruptions across all three countries starting around 0600 UTC. The impact was relatively minor in Kazakhstan, while traffic declined more significantly and took longer to recover in Uzbekistan and Kyrgyzstan.

BLOG-1041 Embedded Image - YR8jtm
BLOG-1041 Embedded Image - ARef7h
BLOG-1041 Embedded Image - UAzm1g

On March 3, a power outage across multiple counties and cities in Taiwan, reportedly caused by human negligence during annual repairs at the Hsinta power plant, led to a brief Internet disruption starting around 0100 UTC.

BLOG-1041 Embedded Image - ETOeOn

Cuba also experienced a second disruption on March 24, this time due to a power failure. ETECSA reported that it caused issues with voice service, SMS, and mobile data. The disruption started around 1230 UTC and lasted for approximately 90 minutes.

BLOG-1041 Embedded Image - 1riWs2
BLOG-1041 Embedded Image - uIrZgd

Network-Targeting DDoS Attacks

While DDoS attacks often aim to knock a specific website offline, attacks that target network infrastructure can have a far more widespread effect, disrupting connectivity for all users attached to that network. Such an attack on March 14 targeted AS8867 (E-Gov - Tehila Project) in Israel. Traffic to the ASN began to decline just before 1530 UTC. Published reports noted that websites for the interior, health, justice, and welfare ministries, as well as the Prime Minister's office, were taken offline.

BLOG-1041 Embedded Image - sVg21W

Disruptions with Unspecified Causes

Not all disruptions have a clear technical or physical cause, though they often correlate with real-world political events or unrest. In Kazakhstan, an Internet disruption began on January 5 amidst mass protests against energy price increases. Traffic dropped drastically starting around 1030 UTC. While traffic returned to a normal diurnal pattern on January 11, several brief periods of connectivity appeared to align with televised speeches from the Kazakh president during the six-day period.

BLOG-1041 Embedded Image - 8Sfi0V

Early on January 23, heavy gunfire related to an army mutiny was reported in Burkina Faso. A significant drop in traffic was observed beginning around 0915 UTC, affecting major providers Orange, FasoNet, and Telecel Faso. The disruption lasted for nearly a day and a half, recovering around 2000 UTC on January 24.

BLOG-936 Embedded Image - 4hHTQi

A brief 30-minute disruption was observed in Yemen just after 2200 UTC on March 15, primarily impacting YemenNet. A published report claimed it was a deliberate act by the Houthi coup militia.

BLOG-1041 Embedded Image - QAlDC9
BLOG-1041 Embedded Image - UMLAM8

The Russian Invasion of Ukraine

Since the Russian invasion began in late February, Ukrainian technicians have worked to keep the country online, with significant success. Cloudflare Radar data shows that by the end of March, peak traffic levels were at 85-90% of pre-invasion peaks. In March, Ukrtelecom experienced three brief outages—one on March 8 lasting just over two hours, another on March 10 lasting 40 minutes, and a more substantial ~15 hour outage on March 28-29.

BLOG-1041 Embedded Image - NDAB57
BLOG-1041 Embedded Image - 1Wbpw9

The longer outage was attributed by the State Service of Special Communications to “a powerful cyberattack.” Ukrtelecom stated it temporarily limited services to the majority of users to protect its network and continue supporting Ukraine’s Armed Forces. Triolan, another major Ukrainian ISP, also suffered a significant disruption around 2100 UTC on March 9, reportedly as a result of a cyber attack, with traffic gradually returning after approximately 10 hours.

BLOG-1041 Embedded Image - 7WzNp6