Fiber cuts disrupt service on three continents
Damage to terrestrial and submarine fiber-optic cables accounted for several notable outages during the second quarter, ranging from localized incidents to a multi-country event spanning thousands of miles.
Comcast Florida
On April 25, a reported fiber cut knocked out service for Comcast subscribers in nearly 20 cities across southwestern Florida. Cloudflare traffic from the affected cities dropped to zero between 1915–2050 UTC (1515–1850 local time).

The incident also shifted the traffic mix across Comcast's primary autonomous system, AS7922. During the disruption, the share of traffic from mobile devices rose while desktop traffic fell; IPv4 traffic dropped as IPv6's share correspondingly increased.


Telkom SA
Telkom SA alerted customers on the morning of May 17 to fiber cable damage detected around 8:00 am local time. Cloudflare observed the impact across three South African provinces — Gauteng, Limpopo, and North West — with traffic declining at 0600 UTC (0800 local) and recovering around 1300 UTC (1500 local). The company did not disclose the cause or location of the cut.


CANTV Venezuela
A suspected fiber cut on May 19 disrupted service for subscribers of Venezuela's CANTV — the latest in a series of such incidents for the provider. While multiple states were reportedly affected, the most significant impact was measured in Falcón, where traffic fell sharply at 1800 UTC (1400 local) and took roughly 24 hours to recover.

AAE-1 and SMW-5 submarine cables
Just after 1200 UTC on June 7, cuts to the Africa-Asia-Europe-1 (AAE-1) and SEA-ME-WE-5 (SMW-5) submarine cables disrupted connectivity for millions of users across the Middle East, Africa, and Asia. The damage reportedly occurred in Egypt; both cables land at Abu Talat and Zafarana, which also serve as landing points for several other cables. The relatively short disruption window suggests the damage happened on land, after the cables came ashore.







Castor canadensis, British Columbia
A beaver caused an outage on June 13 in British Columbia, Canada, by gnawing through a tree that fell on power lines and a Telus fiber optic cable. The damaged cable disrupted connectivity for customers in more than a dozen communities, including those served by CityWest (AS18988), a utility that relies on the Telus cable. Traffic from CityWest subscribers to Cloudflare was absent between 1800 UTC on June 7 and 0310 UTC on June 8 (1100–2010 local time).

Exam-season shutdowns across the Middle East and Africa
Authoritarian governments have increasingly turned to nationwide Internet shutdowns during secondary school exams, despite estimates that the economic damage runs into the tens or hundreds of millions of US dollars. In the second quarter, Syria, Sudan, and Iraq's Kurdistan region all imposed multi-hour shutdowns, while Algeria took a more targeted approach.
Syria implemented four nationwide shutdowns between May 30 and June 12. These were asymmetric in nature — inbound traffic was disabled while egress traffic continued. During three of the four shutdowns, requests to Cloudflare's 1.1.1.1 resolver from Syrian clients spiked as DNS queries exited the country but responses could not return, triggering retry floods.


Sudan imposed daily shutdowns from 0530–0830 UTC (0730–1030 local) between June 11 and June 22, skipping June 17. These were nationwide but not complete, as traffic did not fall to zero.

Algeria, which held exams June 12–16, appears to have shifted tactics. Instead of the nationwide shutdowns seen in the past — which came with an estimated cost of nearly US$388 million — the government apparently opted for content blocking. Traffic dips align closely with the two daily exam sessions, 0730–1000 UTC and 1330–1600 UTC, rather than a full outage.

On June 27, the Kurdistan Regional Government in Iraq began twice-weekly (Monday and Thursday) shutdowns of 0630–1030 local time (0330–0730 UTC), expected to continue for four weeks, to prevent cheating on high school final exams. Traffic from three governorates dropped to near zero during each window.

Government-ordered shutdowns for political control
Governments also used shutdowns during the quarter to limit communication around political events, including elections and protests.
Turkmenistan on April 10 implemented a near-complete Internet shutdown starting at 1400 UTC, following earlier blocking of social networks, VPN providers, and cloud platforms. The disruption, which appeared tied to criticism of the recent presidential election, lasted nearly 40 hours, with traffic returning around 0700 UTC on April 12. The impact was visible at the country level and at two major providers: Telephone Network of Ashgabat CJSC (AS51495) and TurkmenTelecom (AS20661).



On May 25, an Internet disruption in Pakistan coincided with protests led by the former Prime Minister. Telecom providers attributed the two-hour incident to a faulty web filtering system rather than a deliberate nationwide shutdown. The effect was a slight dip in national traffic, more clearly visible in Lahore and Karachi, and most pronounced at the network level: Cyber Internet Services (AS9541) saw a modest drop while Mobilink (AS45669) experienced a near complete outage.




Sudan closed out the quarter with a communications blackout on June 30, imposed as protestors rallied against the military leadership. The shutdown began at 0600 UTC (0800 local) and initially lifted around 1740 UTC (1940 local). Connectivity returned for roughly three hours before traffic again dropped to near zero at approximately 2040 UTC (2240 local), with the second outage still active at day's end. The nationwide shutdown was visible in traffic losses at major providers including MTN, Sudatel, Kanartel, and Sudanese Mobile Telephone (SDN Mobitel / ZAIN).





Power and maintenance failures take their toll
Beyond cable damage, other physical infrastructure problems — fires, power failures, and maintenance work — repeatedly took networks offline in Q2.
On April 6 around 2030 local time (0030 UTC April 7), a fire at the Costa Sur generation plant, one of Puerto Rico’s largest power stations, triggered an island-wide blackout. The impact on Internet traffic was immediate: Cloudflare data shows Puerto Rican traffic dropping by more than half as power failed. The normal diurnal pattern persisted at reduced levels for three days before returning to baseline. Luma Energy, the utility, reported that power had been restored to 99.7% of its 1.5 million customers by April 10.

The network-level view shows just how severe the disruption was. Traffic for Datacom Caribe/Claro (AS10396) fell by more than half instantly, while Liberty Cablevision of Puerto Rico (AS14638) saw traffic decline by roughly 85%.


Maintenance work was to blame for a shorter incident on the evening of May 3, when Swisscom reported an Internet interruption. A published account placed the outage between 2223–2253 local time (2023–2053 UTC). Cloudflare radar shows a complete loss of traffic for 30 minutes, followed by a quick recovery. Swisscom offered no further explanation beyond citing maintenance.

Disruptions and shutdowns in Iran
Iran saw a series of Internet disruptions during the quarter, some tied to protests and at least one attributed by the affected operator to a cyberattack.
On May 6, the government cut mobile data in Khuzestan province, reportedly in response to mass protests over shortages of bread and water. Fixed connectivity speeds were also significantly reduced, according to reports. Cloudflare observed a drop in traffic for mobile provider Irancell (AS44244) starting around 1000 UTC.

A similar Irancell disruption occurred on May 12 amid reports of ongoing protests, with lower peak traffic during the day and another drop around 1800 UTC.

Multiple Iranian networks experienced near-complete outages on May 9 between 1300–1440 UTC (1730–1910 local). Affected providers included Atrin Information & Communications Technology Company (AS39650), AryaSat (AS43343), Ariana Gostar Spadana (AS48309), and Pirooz Leen (AS51759). These networks share Fanaptelecom (AS24631) as an upstream provider, and Fanaptelecom was itself experiencing an outage at the time. No root cause for the Fanaptelecom failure was available.

Mobile provider Mobinnet (AS50810) suffered a multi-hour disruption on May 14, from 1230–1530 UTC (1700–2000 local). Mobinnet attributed the outage, via tweet, to a “widespread cyberattack of foreign origin.”

The battle for connectivity in Ukraine
More than four months into the war, Internet access remains an active front. Two similar events in Q2 stand out, both centered on the Russian-occupied city of Kherson.
The first was a near-complete outage lasting from 1600 UTC on April 30 until 0430 UTC on May 4. Ukraine’s vice Prime-Minister Mykhailo Fedorov and the State Service of Special Communications and Information Protection attributed the disruption to “interruptions of fiber-optic trunk lines and disconnection from the power supply of equipment of operators in the region.” Cloudflare data shows effectively no traffic for Kherson for roughly 24 hours after the outage began, with only a nominal amount of traffic in the following days.

As that nominal traffic returned, routing for an IPv4 prefix announced by Khersontelecom (AS47598) shifted. Before the outage, the prefix reached the Internet through Ukrainian providers including AS12883, AS3326, and AS35213. After the disruption, its upstream provider was AS201776 (Miranda), a Russian network whose path also includes AS12389 (Rostelecom), described by the company itself as “the largest digital services provider in Russia.”
Peer AS | Last Update | AS Path |
|---|---|---|
AS1299 (TWELVE99 Arelion, fka Telia Carrier) | 5/1/2022 16:02:26 | 1299 12389 201776 47598 |
AS6777 (AMS-IX-RS) | 4/28/2022 11:23:33 | 12883 47598 |
When the disruption ended on May 4, Khersontelecom’s routing path updated again, returning to non-Russian upstream providers.
Peer AS | Last Update | AS Path |
|---|---|---|
AS174 (COGENT-174) | 5/4/2022 05:56:27 | 174 3326 3326 3326 47598 |
AS1273 (CW Vodafone Group PLC) | 5/4/2022 03:11:25 | 1273 12389 201776 47598 |
A month later, on May 30, a significant Internet disruption began in Kherson at 1435 UTC (1735 local). Khersontelecom’s routing once again shifted from Ukrainian to Russian upstream providers. As of the end of June, both the disruption and the Russian routing path remained in place, though the traffic loss was far less severe than the April/May event.

Peer AS | Last Update | AS Path |
|---|---|---|
AS4775 (Globe Telecoms) | 5/30/2022 13:56:22 | 4775 1273 12389 201776 47598 |
AS9002 (RETN-AS) | 5/30/2022 09:58:16 | 9002 3326 47598 |
Visibility matters
These events are not an exhaustive catalog of Q2’s outages, shutdowns, and disruptions. Some were brief or limited in scope; others occurred without any known or publicly suggested cause. Highlighting them brings visibility to what is happening, why it happened, and the impact — human, financial, or otherwise. Follow @CloudflareRadar for updates as events unfold, and consult Cloudflare Radar for the latest Internet trends.



