One year of war in Ukraine: Internet trends, attacks, and resilience.

Cloudflare has documented the effects of one year of war on Ukraine's Internet infrastructure, analyzing traffic shifts, cyber attacks, and overall network resilience. The data covers distinct phases of conflict and highlights how connectivity persisted despite significant physical and digital threats.

Population Movement Reflects in Traffic Data

Network traffic patterns clearly showed the displacement of Ukrainians. Following February 24, 2022, overall country-wide traffic dropped by as much as 33 percent, while regional analysis reveals a marked shift from eastern to western parts of the country as people fled the invasion routes.

Three Phases of Network Disruption

Ukraine experienced unique connectivity challenges across different periods of the conflict, each driven by different causes:

  • Invasion phase: Initial attacks caused localized outages and a wave of application-layer cyber threats targeting Ukrainian assets.
  • Occupied territories: In Kherson, between June and October, traffic from several networks was re-routed through Russian infrastructure. This rerouting subjected local users to Russia's filtering and content restrictions.
  • Energy infrastructure strikes: Starting in October 2022, air strikes targeting power grids caused widespread Internet disruptions that continued into 2023.

Rerouting Through Russia

Despite the end of rerouting activity, the networks impacted in Kherson experienced significant outages through the end of the year. Two of those networks have yet to return online.

Escalation in Application-Layer Attacks

The conflict triggered a dramatic increase in cyber assaults on Ukrainian institutions. Measured against pre-war levels, application-layer attack volume rose by 1,300 percent in the early days of March 2022. Government administration, financial services, and media outlets registered the highest volumes of attacks targeting the country.

Why Infrastructure Endured

Ukraine's networks demonstrated notable resilience from both infrastructure and routing standpoints, thanks largely to sustained on-the-ground repair work. Local crews maintained damaged fiber optic routes and restored electrical power where feasible. This situational stability was supported by two structural advantages: Ukraine's extensive external connectivity to global networks and its dense concentration of Internet exchange points.

Satellite-based access provided a key supplement during the war. After Starlink became available in mid-March, traffic growth in Ukraine surpassed 500 percent by mid-May. Between mid-May and mid-November, it grew by nearly another 300 percent. Compared to its initial availability baseline, total usage over the period from mid-March through mid-December climbed more than 1,600 percent, experiencing only a slight decline after that point.

Traffic Fled East to West, Then Returned

The most immediate digital consequence of the invasion was a sharp decline in human Internet traffic. In the weeks following February 24, 2022, request volume dropped by as much as 33%. Recovery was steady over the following months, with notable growth in September and October as refugees returned to the country.

BLOG-1730 Embedded Image - C4WzgL

The pattern of daily usage also shifted. Pre-war traffic had a characteristic shape: a lunchtime peak, a late afternoon dip, and a main evening peak around 21:00. In the first days of the war, that profile flattened dramatically, with peak traffic moving earlier to around 19:00. By late March the 21:00 peak had returned, and the early evening drop reappeared in May.

Mobile traffic became more dominant in the immediate aftermath. Mobile devices typically accounted for about 53% of traffic, jumping to roughly 60% during the first weeks of the invasion before settling back to about 54% by late April.

BLOG-1730 Embedded Image - BlmajO

The most visible geographic shift was the movement of people and connectivity from the east to the west. While early attacks did not yet focus on energy infrastructure, they did drive an exodus of millions of refugees and massive internal displacement. A map of traffic changes in the first week after February 24 shows these movements starkly.

BLOG-1730 Embedded Image - gkQm2z

In the east and north, traffic collapsed. Kharkiv Oblast and Chernihiv both saw traffic fall by 60%, and Kyiv Oblast was down 40% by March 2. In western regions, traffic surged: Rivne was up 50%, Volyn 30%, and Lviv 28%. At the city level, several places experienced near-total outages during active conflict and occupation.

Chernihiv, north of Kyiv, had severe degradation in the first week of the war and only recovered after Russian forces withdrew in early April. Kyiv itself showed a clear disruption, while the nearby towns of Bucha and Irpin went almost dark; traffic returned only weeks after the Russian retreat at the start of April. Kharkiv saw a 50% drop on March 3, and the southern city of Enerhodar, home to the Zaporizhzhia nuclear plant, was reduced to residual traffic. In Mariupol, a weeks-long siege and near-total destruction of the city pushed traffic down to about 22% of its pre-war level by the end of April.

BLOG-1730 Embedded Image - Ys2hi6

For ISPs, disruptions were localized and mostly brief. Short outages hit AS6849 (Ukrtel) in mid-March, and AS13188 (Triolan), which serves Kyiv, Chernihiv, and Kharkiv, experienced problems after reporting a cyberattack on March 9. Notably, the country's largest ISP, AS15895 (Kyivstar), showed no clear national outage until the energy infrastructure attacks of October and November, pointing to early network resilience.

## Shifts Under Counteroffensive and Occupation

As fighting moved east and south, disruptions followed the battle lines. Lysychansk in eastern Ukraine saw traffic dwindle to near-residual levels by May amid heavy fighting and population exodus. When Ukraine launched its September counteroffensive in the Kharkiv region, Russian retaliatory airstrikes knocked out power and connectivity; Kharkiv itself experienced a near-complete 12-hour outage on September 11, followed by two more traffic drops over the next two days.

BLOG-1730 Embedded Image - pHEOvZ

Kherson Oblast saw intermittent connectivity throughout the summer, with reports that ISP workers sabotaged their own equipment in June to prevent Russian control. A more sustained disruption started around October 22, with traffic roughly 70% below previous weeks until Ukrainian forces retook Kherson city on November 11. Recovery was gradual over the following weeks.

## Energy Attacks Prove The Biggest Lever

The most widespread and durable outages came not from ground combat but from coordinated strikes on Ukraine's power grid. Following the Crimean Bridge explosion on October 8, the campaign intensified. On October 10, nationwide traffic was 35% below the previous week's level at 07:35 UTC, and took more than 24 hours to recover. Kharkiv was hit hardest, down by about 80%; Lviv dropped by 60%. By late October, Ukrainian officials estimated 30% of power stations had been destroyed, and self-imposed power cuts created further traffic drops in Kyiv and surrounding regions.

BLOG-1730 Embedded Image - ckijWV

Continued strikes through October caused more disruptions in Kyiv, with a 25% drop in traffic on October 20 that lasted 12 hours, followed by a shorter partial outage the next day. On November 23, widespread Russian strikes caused a nationwide traffic drop of nearly 50% that lasted almost a day and a half. A further round of attacks on December 16 produced a national-level drop of 13%, but heavily affected particular networks: AS13188 (Triolan) fell 70% and AS15895 (Kyivstar) fell 40%.

BLOG-1730 Embedded Image - GPThfd
BLOG-1640 Embedded Image - nblbbv

The pattern continued into 2023. In early January, another air strike in Odessa cut traffic by as much as 54% compared with the previous week during an 18-hour disruption. Across the year, the picture is consistent: Ukraine's Internet was highly resilient to direct conflict, but remained acutely vulnerable to attacks on its power infrastructure. A full year of data shows that recovery was often swift, but never guaranteed.

The Global Fallout: More Than a Regional Conflict

The war's impact rippled far beyond Ukraine's borders almost immediately. In March 2022, US cybersecurity authorities, including CISA, launched the "Shields Up" initiative, warning that the conflict could affect organizations both within and outside the region. Similar advisories were issued by governments in the UK and Japan, urging businesses and citizens to bolster their cyber defenses. Much of the ensuing attack traffic was aimed at web applications, which are typically defended by tools like a Web Application Firewall (WAF) that filters HTTP traffic at the OSI model's layer 7. In contrast, Distributed Denial of Service (DDoS) attacks are designed to overwhelm online properties and render them unreachable.

Attack Volumes Spike Dramatically

The scale of mitigation efforts required to defend Ukrainian web properties was extraordinary. An analysis of mitigated traffic showed a sharp increase following the invasion on February 24, 2022. By February 28, the number of blocked application-layer threats was already 105% higher than the previous Monday. The peak came in early March, when mitigated requests reached a staggering 1,300% above pre-war levels. Over the following year, an average of 10% of all traffic to Ukrainian websites was identified and blocked as potential attacks.

Looking at daily figures, the intensity fluctuated with the course of the war. In early March 2022, nearly a third of all traffic to Ukraine was being mitigated. After a lull, numbers spiked again in September, coinciding with the Ukrainian counteroffensive, and reached an apex on October 29, when DDoS attack traffic alone made up 39% of total traffic to Ukrainian customer sites.

BLOG-1730 Embedded Image - xMJEti

The situation was even more pronounced for websites on the .ua top-level domain. DDoS attacks comprised over 80% of all traffic to these sites by early March 2022. Following initial spikes in February, there was little respite until late November and December. Even then, attacks resumed just before Christmas. Over the entire year, an average of 13% of all traffic to .ua domains was attack mitigation.

BLOG-1730 Embedded Image - 1au1Ce

The methods used to block these attacks reveal a layered defense strategy. For .ua sites specifically, the majority of mitigations—around 57%—were handled by automated rulesets designed to detect and block HTTP DDoS attacks. Custom firewall rules (WAF) accounted for a further 31% of blocked threats, while 10% were rejected based on IP reputation databases.

BLOG-1730 Embedded Image - kILxG3

This trend of increased attack activity was not one-directional. Traffic originating from within Ukraine that required mitigation also rose considerably as the conflict began, suggesting that compromised machines within the country were being used to launch attacks elsewhere.

BLOG-1730 Embedded Image - fEeAIa

Targeting the Information Front

The focus of attackers was heavily skewed toward specific industries. Government administration, financial services, and the media were the primary targets, accounting for nearly half of all WAF mitigations throughout 2022. The DDoS data paints an even clearer picture of the attackers' intent. In the first half of the year, the top five most attacked industries in Ukraine were all in broadcasting, Internet, online media, or publishing, together absorbing almost 80% of all DDoS attacks. The goal was to silence information sources.

This pattern was visible from day one. In the initial days of the invasion, mitigation spikes were concentrated on a news service, a TV channel, a government website, and a bank. By July, the targets had broadened to include food delivery, e-commerce, auto parts, and other news services. A year later, in February 2023, the targets had shifted again to include electronics, e-commerce, IT, and education websites.

BLOG-1730 Embedded Image - X5xSF7
BLOG-1730 Embedded Image - obxvBq
BLOG-1730 Embedded Image - A2hIO7

The Network-Layer View

At the network layer, attributing attacks is more complex due to shared IP addresses. However, traffic hitting Cloudflare's Kyiv data center showed distinct peaks of DDoS activity. These were higher than pre-war levels in early March but reached far greater magnitudes in June and August. The scale of the threat was underscored by the finding that a full 12.6% of Ukraine's network-layer traffic in Q1 2022 was DDoS activity, a staggering 1,160% increase from the 1% recorded in the previous quarter.

BLOG-1730 Embedded Image - 3eKoac

The Fracturing of Connectivity in Kherson

The war's effects were not limited to cyber attacks; the physical occupation of territory caused significant shifts in fundamental Internet routing. Following the Russian capture of Kherson in March and its subsequent occupation until November 2022, the region's Internet service providers were often forced to reroute their traffic, sometimes through Russian networks.

A notable event occurred on May 1, 2022, when the Ukrainian provider AS47598 (Khersontelecom) was observed routing its traffic through the Russian network AS201776 (Miranda-Media). This made the provider's traffic subject to Russian restrictions and content filtering. The rerouting was brief, as Khersontelecom resumed connections through Ukrainian providers by May 4.

BLOG-1730 Embedded Image - 9NORqy

However, this was not an isolated incident. An analysis of 15 ASNs belonging to networks in the Kherson Oblast, using data from the University of Oregon's Route Views project, revealed a recurring pattern. During the period from February 2022 to February 2023, three Russian networks consistently appeared as upstream providers: AS201776 (Miranda-Media), AS52091 (Level-MSK Ltd.), and AS8492 (OBIT Ltd.).

BLOG-1730 Embedded Image - I8og5G

The visual analysis of routing data shows a timeline of dependence. A widespread outage on April 30 saw many providers go dark, and as they came back online, some returned via Russian routes. A more significant shift occurred on May 30, when most Kherson networks began routing traffic through Russia. This period of dependence lasted through the summer and into October. This was followed by a shift away from Russian providers, but also by extended outages. Khersontelecom has largely been offline since October, with a brief period in early November when its traffic went through Russia. While many providers restored connections via Ukrainian networks in early December, several smaller operators, including AS204485 (PE Berislav Cable Television) and AS56359 (CHP Melnikov Roman Sergeevich), have continued to depend on Miranda-Media as an upstream, experiencing intermittent outages. AS25082 (Viner Telecom) has maintained a hybrid route, using both Ukrainian and Russian networks for connectivity.

A closer look at Ukraine’s interconnection fabric

Network resilience is typically defined by three capabilities: operating in a degraded mode under damage, recovering quickly after a failure, and scaling to meet rapid or unpredictable demand. That framing has proven especially relevant in Ukraine, where repair crews have worked continuously to restore damaged fiber and mobile infrastructure throughout the conflict.

The underlying interconnection topology has also helped. As of February 2023, PeeringDB lists 25 Internet Exchange Points (IXPs) and 50 interconnection facilities in Ukraine, with an IXP potentially spanning multiple physical sites. International Autonomous Systems (ASes) are present at more than half of these IXPs. That distribution of interconnection points gives both domestic and foreign providers multiple locations for traffic exchange.

To assess the strength of those links, we classify AS-level connections as domestic (both ASes registered in Ukraine) or international (one AS registered abroad). Registration data comes from the RIPE NCC extended delegation reports; BGP data provides the observed AS-level links.

Many paths, few choke points

A March 2022 Economist analysis described Ukraine as having the world’s fourth-least-concentrated Internet market, with an unusually large number of ISPs and therefore few choke points. The registration and routing data support that view: 2,190 ASes are registered in Ukraine, and 1,574 of them appear in the BGP routing table as active.

BLOG-1730 Embedded Image - yMf7Gn

The cumulative distribution above shows how many direct international links Ukrainian ASes maintained in February 2023. Roughly 50% of domestic ASes had more than one international connection, about 10% had more than 10, and close to 2% had 100 or more. While those figures have declined modestly over the past year, they still indicate a network without centralized points of failure.

Looking at the countries associated with those international next-hop ASes, Ukraine’s connectivity in February 2023 was spread across 18 countries, mostly in Europe. In February 2022, those countries collectively accounted for 77% of international paths, with the top four each holding 7.8%. By February 2023, the top ten destinations still represented 76%, but the composition shifted significantly.

February 2022 February 2023
1 Germany 7.85% Russia 11.62%
2 Netherlands 7.85% Germany 11.43%
3 United Kingdom 7.83% Hong Kong 8.38%
4 Hong Kong 7.81% Poland 7.93%
5 Sweden 7.77% Italy 7.75%
6 Romania 7.72% Turkey 6.86%
7 Russia 7.67% Bulgaria 6.20%
8 Italy 7.64% Netherlands 5.31%
9 Poland 7.60% United Kingdom 5.30%
10 Hungary 7.54% Sweden 5.26%

Russia’s share grew by 50% year over year to 11.6%, making it the largest single next-hop country. Germany also rose to account for over 11% of paths.

Satellite traffic growth

Starlink’s presence in Ukraine, tracked via AS14593, grew rapidly through 2022. Between mid-March and mid-May, Starlink traffic from the country increased by over 530%. Growth continued from mid-May to mid-November at nearly 300% over that six-month span, bringing the total increase from mid-March to mid-December to over 1600%. Traffic then stabilized and declined modestly in January 2023.

BLOG-1730 Embedded Image - AKnnKB

From November to December 2022, Starlink accounted for between 0.22% and 0.3% of Ukraine’s traffic. That share has since fallen below 0.2%.

Resilience after a year of war

Ukraine’s Internet has faced sustained attacks, routing changes, and physical damage over the past year. It has also repeatedly recovered, thanks to a combination of distributed infrastructure, active repair work, and international connectivity that spans many providers and countries. The data shows a network that, while under constant pressure, has avoided the kind of centralized architecture that would make it easy to disable.