Fiber cuts disrupt service on three continents

Damage to terrestrial and submarine fiber-optic cables accounted for several notable outages during the second quarter, ranging from localized incidents to a multi-country event spanning thousands of miles.

Comcast Florida

On April 25, a reported fiber cut knocked out service for Comcast subscribers in nearly 20 cities across southwestern Florida. Cloudflare traffic from the affected cities dropped to zero between 1915–2050 UTC (1515–1850 local time).

BLOG-1231 Embedded Image - xrzNYI

The incident also shifted the traffic mix across Comcast's primary autonomous system, AS7922. During the disruption, the share of traffic from mobile devices rose while desktop traffic fell; IPv4 traffic dropped as IPv6's share correspondingly increased.

BLOG-1231 Embedded Image - OsPnHm
BLOG-1231 Embedded Image - 9gL3gn

Telkom SA

Telkom SA alerted customers on the morning of May 17 to fiber cable damage detected around 8:00 am local time. Cloudflare observed the impact across three South African provinces — Gauteng, Limpopo, and North West — with traffic declining at 0600 UTC (0800 local) and recovering around 1300 UTC (1500 local). The company did not disclose the cause or location of the cut.

BLOG-1231 Embedded Image - X7xwyX
BLOG-1231 Embedded Image - XivEys

CANTV Venezuela

A suspected fiber cut on May 19 disrupted service for subscribers of Venezuela's CANTV — the latest in a series of such incidents for the provider. While multiple states were reportedly affected, the most significant impact was measured in Falcón, where traffic fell sharply at 1800 UTC (1400 local) and took roughly 24 hours to recover.

BLOG-1231 Embedded Image - XhfljI

AAE-1 and SMW-5 submarine cables

Just after 1200 UTC on June 7, cuts to the Africa-Asia-Europe-1 (AAE-1) and SEA-ME-WE-5 (SMW-5) submarine cables disrupted connectivity for millions of users across the Middle East, Africa, and Asia. The damage reportedly occurred in Egypt; both cables land at Abu Talat and Zafarana, which also serve as landing points for several other cables. The relatively short disruption window suggests the damage happened on land, after the cables came ashore.

BLOG-1211 Embedded Image - UnhnMp
BLOG-1211 Embedded Image - 14ryDB
BLOG-1231 Embedded Image - RMsEuy
BLOG-1231 Embedded Image - DaEtsl
BLOG-1211 Embedded Image - nR1sDU
BLOG-1211 Embedded Image - 53sUFZ
BLOG-1211 Embedded Image - Pmgco2

Castor canadensis, British Columbia

A beaver caused an outage on June 13 in British Columbia, Canada, by gnawing through a tree that fell on power lines and a Telus fiber optic cable. The damaged cable disrupted connectivity for customers in more than a dozen communities, including those served by CityWest (AS18988), a utility that relies on the Telus cable. Traffic from CityWest subscribers to Cloudflare was absent between 1800 UTC on June 7 and 0310 UTC on June 8 (1100–2010 local time).

BLOG-1231 Embedded Image - XPio9a

Exam-season shutdowns across the Middle East and Africa

Authoritarian governments have increasingly turned to nationwide Internet shutdowns during secondary school exams, despite estimates that the economic damage runs into the tens or hundreds of millions of US dollars. In the second quarter, Syria, Sudan, and Iraq's Kurdistan region all imposed multi-hour shutdowns, while Algeria took a more targeted approach.

Syria implemented four nationwide shutdowns between May 30 and June 12. These were asymmetric in nature — inbound traffic was disabled while egress traffic continued. During three of the four shutdowns, requests to Cloudflare's 1.1.1.1 resolver from Syrian clients spiked as DNS queries exited the country but responses could not return, triggering retry floods.

BLOG-1231 Embedded Image - zjCxuC
BLOG-1231 Embedded Image - Th1wZ6

Sudan imposed daily shutdowns from 0530–0830 UTC (0730–1030 local) between June 11 and June 22, skipping June 17. These were nationwide but not complete, as traffic did not fall to zero.

BLOG-1231 Embedded Image - GWMVHa

Algeria, which held exams June 12–16, appears to have shifted tactics. Instead of the nationwide shutdowns seen in the past — which came with an estimated cost of nearly US$388 million — the government apparently opted for content blocking. Traffic dips align closely with the two daily exam sessions, 0730–1000 UTC and 1330–1600 UTC, rather than a full outage.

BLOG-1231 Embedded Image - 5yHi9v

On June 27, the Kurdistan Regional Government in Iraq began twice-weekly (Monday and Thursday) shutdowns of 0630–1030 local time (0330–0730 UTC), expected to continue for four weeks, to prevent cheating on high school final exams. Traffic from three governorates dropped to near zero during each window.

BLOG-1231 Embedded Image - 9VlC9V

Government-ordered shutdowns for political control

Governments also used shutdowns during the quarter to limit communication around political events, including elections and protests.

Turkmenistan on April 10 implemented a near-complete Internet shutdown starting at 1400 UTC, following earlier blocking of social networks, VPN providers, and cloud platforms. The disruption, which appeared tied to criticism of the recent presidential election, lasted nearly 40 hours, with traffic returning around 0700 UTC on April 12. The impact was visible at the country level and at two major providers: Telephone Network of Ashgabat CJSC (AS51495) and TurkmenTelecom (AS20661).

BLOG-1231 Embedded Image - ZZsi6V
BLOG-1231 Embedded Image - c8a1nU
BLOG-1231 Embedded Image - zORk9B

On May 25, an Internet disruption in Pakistan coincided with protests led by the former Prime Minister. Telecom providers attributed the two-hour incident to a faulty web filtering system rather than a deliberate nationwide shutdown. The effect was a slight dip in national traffic, more clearly visible in Lahore and Karachi, and most pronounced at the network level: Cyber Internet Services (AS9541) saw a modest drop while Mobilink (AS45669) experienced a near complete outage.

BLOG-1231 Embedded Image - DaEtsl
BLOG-1231 Embedded Image - Cot7Pj
BLOG-1231 Embedded Image - HfE3jQ
BLOG-1231 Embedded Image - qvguDH

Sudan closed out the quarter with a communications blackout on June 30, imposed as protestors rallied against the military leadership. The shutdown began at 0600 UTC (0800 local) and initially lifted around 1740 UTC (1940 local). Connectivity returned for roughly three hours before traffic again dropped to near zero at approximately 2040 UTC (2240 local), with the second outage still active at day's end. The nationwide shutdown was visible in traffic losses at major providers including MTN, Sudatel, Kanartel, and Sudanese Mobile Telephone (SDN Mobitel / ZAIN).

BLOG-1231 Embedded Image - 9DC7qx
BLOG-1231 Embedded Image - AbYxip
BLOG-1231 Embedded Image - pcv0A5
BLOG-1231 Embedded Image - azphoU
BLOG-1231 Embedded Image - q2LXvV

Power and maintenance failures take their toll

Beyond cable damage, other physical infrastructure problems — fires, power failures, and maintenance work — repeatedly took networks offline in Q2.

On April 6 around 2030 local time (0030 UTC April 7), a fire at the Costa Sur generation plant, one of Puerto Rico’s largest power stations, triggered an island-wide blackout. The impact on Internet traffic was immediate: Cloudflare data shows Puerto Rican traffic dropping by more than half as power failed. The normal diurnal pattern persisted at reduced levels for three days before returning to baseline. Luma Energy, the utility, reported that power had been restored to 99.7% of its 1.5 million customers by April 10.

BLOG-1231 Embedded Image - 9cYOGy

The network-level view shows just how severe the disruption was. Traffic for Datacom Caribe/Claro (AS10396) fell by more than half instantly, while Liberty Cablevision of Puerto Rico (AS14638) saw traffic decline by roughly 85%.

BLOG-1231 Embedded Image - jN7M4t
BLOG-1231 Embedded Image - 7VVSUn

Maintenance work was to blame for a shorter incident on the evening of May 3, when Swisscom reported an Internet interruption. A published account placed the outage between 2223–2253 local time (2023–2053 UTC). Cloudflare radar shows a complete loss of traffic for 30 minutes, followed by a quick recovery. Swisscom offered no further explanation beyond citing maintenance.

BLOG-1231 Embedded Image - P0tnsQ

Disruptions and shutdowns in Iran

Iran saw a series of Internet disruptions during the quarter, some tied to protests and at least one attributed by the affected operator to a cyberattack.

On May 6, the government cut mobile data in Khuzestan province, reportedly in response to mass protests over shortages of bread and water. Fixed connectivity speeds were also significantly reduced, according to reports. Cloudflare observed a drop in traffic for mobile provider Irancell (AS44244) starting around 1000 UTC.

BLOG-1231 Embedded Image - fDaiF5

A similar Irancell disruption occurred on May 12 amid reports of ongoing protests, with lower peak traffic during the day and another drop around 1800 UTC.

BLOG-1231 Embedded Image - T4zxc6

Multiple Iranian networks experienced near-complete outages on May 9 between 1300–1440 UTC (1730–1910 local). Affected providers included Atrin Information & Communications Technology Company (AS39650), AryaSat (AS43343), Ariana Gostar Spadana (AS48309), and Pirooz Leen (AS51759). These networks share Fanaptelecom (AS24631) as an upstream provider, and Fanaptelecom was itself experiencing an outage at the time. No root cause for the Fanaptelecom failure was available.

BLOG-1231 Embedded Image - NXER0E

Mobile provider Mobinnet (AS50810) suffered a multi-hour disruption on May 14, from 1230–1530 UTC (1700–2000 local). Mobinnet attributed the outage, via tweet, to a “widespread cyberattack of foreign origin.”

BLOG-1231 Embedded Image - pWxwo4

The battle for connectivity in Ukraine

More than four months into the war, Internet access remains an active front. Two similar events in Q2 stand out, both centered on the Russian-occupied city of Kherson.

The first was a near-complete outage lasting from 1600 UTC on April 30 until 0430 UTC on May 4. Ukraine’s vice Prime-Minister Mykhailo Fedorov and the State Service of Special Communications and Information Protection attributed the disruption to “interruptions of fiber-optic trunk lines and disconnection from the power supply of equipment of operators in the region.” Cloudflare data shows effectively no traffic for Kherson for roughly 24 hours after the outage began, with only a nominal amount of traffic in the following days.

BLOG-1231 Embedded Image - YhVwMD

As that nominal traffic returned, routing for an IPv4 prefix announced by Khersontelecom (AS47598) shifted. Before the outage, the prefix reached the Internet through Ukrainian providers including AS12883, AS3326, and AS35213. After the disruption, its upstream provider was AS201776 (Miranda), a Russian network whose path also includes AS12389 (Rostelecom), described by the company itself as “the largest digital services provider in Russia.”

Peer AS

Last Update

AS Path

AS1299 (TWELVE99 Arelion, fka Telia Carrier)

5/1/2022 16:02:26

1299 12389 201776 47598

AS6777 (AMS-IX-RS)

4/28/2022 11:23:33

12883 47598

When the disruption ended on May 4, Khersontelecom’s routing path updated again, returning to non-Russian upstream providers.

Peer AS

Last Update

AS Path

AS174 (COGENT-174)

5/4/2022 05:56:27

174 3326 3326 3326 47598

AS1273 (CW Vodafone Group PLC)

5/4/2022 03:11:25

1273 12389 201776 47598

A month later, on May 30, a significant Internet disruption began in Kherson at 1435 UTC (1735 local). Khersontelecom’s routing once again shifted from Ukrainian to Russian upstream providers. As of the end of June, both the disruption and the Russian routing path remained in place, though the traffic loss was far less severe than the April/May event.

BLOG-1231 Embedded Image - A4czUH

Peer AS

Last Update

AS Path

AS4775 (Globe Telecoms)

5/30/2022 13:56:22

4775 1273 12389 201776 47598

AS9002 (RETN-AS)

5/30/2022 09:58:16

9002 3326 47598

Visibility matters

These events are not an exhaustive catalog of Q2’s outages, shutdowns, and disruptions. Some were brief or limited in scope; others occurred without any known or publicly suggested cause. Highlighting them brings visibility to what is happening, why it happened, and the impact — human, financial, or otherwise. Follow @CloudflareRadar for updates as events unfold, and consult Cloudflare Radar for the latest Internet trends.