Ukraine’s Internet Signal: From Routine to Wartime Anomalies
Cloudflare operates network infrastructure in more than 250 cities globally, including data centers in Ukraine, Belarus, and Russia. Continuous monitoring of traffic trends, packet loss, and congestion across these locations provides a real-time view of how Internet connectivity is being used—and disrupted—during the invasion of Ukraine. All times discussed are UTC; Ukraine’s local time zone is UTC+2.
Before the conflict, Internet traffic in Ukrainian cities followed a predictable daily rhythm: low after midnight, rising through the morning, a lunchtime dip, and an evening peak. This pattern was clearly visible on the Monday through Wednesday preceding the invasion. Starting Thursday, that baseline shifted dramatically. Cloudflare measured roughly 70% of normal request volume on Thursday and about 60% on Friday. Volumes recovered to 70% over the weekend and then peaked on Monday and Tuesday as Cloudflare mitigated attacks originating from networks within Ukraine.
Geographic Disparities in Traffic Patterns
The traffic data from individual cities tells a stark geographical story. In Kyiv, the capital, traffic picked up early Thursday morning but never reached normal levels that day. Friday was even lower. However, the city has shown a gradual recovery since then.
Western cities paint a different picture. In Lviv, a smaller drop over three days was followed by a dramatic increase in traffic, suggesting an influx of people moving west toward Poland, Slovakia, and Romania. A similar pattern of growth was observed in Uzhhorod on the Slovakian border, as well as in Ternopil and Rivne. The differing days on which these western cities peaked point to the westward movement of people fleeing fighting in the capital, east, and south.
In contrast, the eastern and southern regions show severe degradation. Traffic in Kharkiv has stayed at roughly 50-60% of its usual rate since the invasion began. Cities further east, like Sumy and Izyum, have seen very low traffic levels since March 2-3. Donetsk remained mostly consistent except for a dramatic change on March 1, likely caused by an attack against a specific .ua domain.
Areas with active fighting and heavy bombardment experienced the most significant drops and outright outages. In Mariupol, traffic declined after the invasion and then dropped dramatically over the last three days of the measured period. A view of traffic from AS43554 in Mariupol indicates a total outage starting March 1 that continued through March 4. Similar large shutdowns were seen in Osypenko, Irpin, Bucha—both near Hostomel airport—and Severodonetsk. Minimal traffic was also observed from Enerhodar, site of the Zaporizhzhia NPP. Cloudflare also began detecting traffic from Starlink terminals in the country, though at very low levels.
A Parallel Cyber Front
The physical invasion has been accompanied by increased cyber activity against Ukrainian networks and domains. Just before the invasion on February 23, Cloudflare’s automated systems detected a large amount of packet loss on a major link to the Kyiv data center, caused by congestion from a large DDoS attack. The issue spanned roughly 30 minutes between 1500-1530 UTC.
Layer 7 attacks against .ua domains spiked on the first day of the war, at times accounting for almost 50% of all requests to those domains. Mitigation volumes returned to pre-invasion levels from Friday, February 25, before rising again on Tuesday, March 1. Among these threats, layer 7 DDoS attacks were the largest category, followed by requests blocked by customer firewall rules and those filtered by Cloudflare’s IP threat reputation database.
Attributing layer 3/4 DDoS traffic is more difficult, as IP addresses are shared across customers. However, network-level attacks on the Kyiv data center reached peaks of nearly 1.8 Gbps. While many of these attacks were relatively small by scale, they remain effective: a small website can be easily knocked offline, and the traffic often includes vulnerability scanning, credential stuffing, and SQL injection attempts.
Communication Shifts During Conflict
DNS traffic data shows how Ukrainians have changed their communication habits. Use of Facebook and Instagram has increased since the invasion began. TikTok initially lost traffic but has begun to recover, though not to pre-conflict levels. Twitter usage increased and has remained persistently higher.
Among messaging apps, WhatsApp traffic declined in line with the overall drop in Internet connectivity. Telegram and Messenger stayed largely unchanged until early this week, when small increases appeared. The standout change was for the end-to-end encrypted app Signal, which saw dramatic growth immediately after the invasion began, reaching 8x to 10x its normal DNS volume.



