Government-directed shutdowns

Sudan

Traffic from Sudan dropped regularly between 12:00-15:00 UTC (14:00-17:00 local time) each day from July 7-10. The disruptions were partial at Sudatel (AS15706) but near-complete at SDN Mobitel (AS36998) and MTN Sudan (AS36972). Similar drops appeared in traffic to the 1.1.1.1 DNS resolver from these ASNs.

BLOG-2587 1

Given the timing aligns with the last four days of postponed 2024 secondary school certificate examinations, and the pattern matches short-duration disruptions repeating across multiple days, these appear to be exam-related shutdowns — consistent with previous government-directed shutdowns in Sudan in 2021 and 2022.

Syria

Our Q2 post covered Syria's exam-related shutdowns targeting cellular connectivity, which took place on June 21, 24, and 29 between 05:15-06:00 UTC (08:15-09:00 local time) for the “Basic Education Certificate.” Exams for the “Secondary Education Certificate” were scheduled between July 12 and August 3, during which we observed six additional disruptions on July 12, 17, 21, 28, 31, and August 3.

At the end of the exam period, the Syrian Ministry of Education posted a Telegram message justifying the shutdowns, claiming they uncovered organized exam cheating networks in three examination centers in Lattakia Governorate. The networks reportedly used small earphones, wireless communication devices, and mobile phones with advanced transmission technologies.

Venezuela

A different type of government-directed disruption occurred on August 18 when Venezuelan provider SuperCable (AS22313) ceased service. CONATEL, the National Commission of Telecommunications, had revoked the provider's authority to operate as of March 14, 2025, with a 60-day transition period for users to find alternatives. Subscribers received an email announcing the end of service, and connectivity was gone within half an hour. Traffic began falling at 15:00 UTC (11:00 local time) and was absent after 15:30 UTC (11:30 local time), remaining down through the end of the quarter.

Interestingly, traffic loss was not accompanied by a full loss of announced IP address space initially. However, full losses occurred between August 19-21 and briefly on September 16. Announced /24s fell from 95 to 63 on September 25, remaining at that level through quarter's end.

Iraq

Exam-related shutdowns in Iraq continued from Q2, with the main part of the country running until July 3 for preparatory school exams and through July 6 in the Kurdistan region. The Kurdistan Regional Government ordered Internet suspensions on August 23 between 03:30 and 04:45 UTC (6:30-7:45 local time), repeating every Saturday, Monday, and Wednesday until September 8 for the second round of grade 12 exams. KNET (AS206206), Newroz Telecom (AS21277), IQ Online (AS48492), and KorekTel (AS59625) were again affected.

In the main part of the country, another round of high school exam shutdowns started August 26, scheduled through September 13 between 03:00-05:00 UTC (06:00-08:00 local time). Affected networks included Earthlink (AS199739), Asiacell (AS51684), Zainas (AS59588), Halasat (AS58322), and HulumTele (AS203214).

Afghanistan

In mid-September, the Taliban ordered the shutdown of fiber optic Internet connectivity in multiple Afghan provinces — as many as 15 — as part of a drive to “prevent immorality.” This was the first such ban since the Taliban took full control in August 2021. The regional shutdowns blocked students from online classes, disrupted commerce and banking, and limited access to government services including passport offices and customs.

Less than two weeks later, on Monday, September 29, 2025, just after 11:30 UTC (16:00 local time), subscribers of wired Internet providers experienced a brief service interruption lasting until just before 12:00 UTC. Mobile providers Afghan Wireless (AS38472) and Etisalat (AS131284) remained available. But just after 12:30 UTC (17:00 local time), the Internet was completely shut down, taking the country fully offline. Connectivity was restored around 11:45 UTC (16:15 local time) on October 1.

Cable faults disrupt connectivity on three continents

Dominican Republic

On July 7, Claro (AS6400) subscribers in the Dominican Republic lost service after two fiber optic cables were damaged — one by work being done by CORAAVEGA, the local water and sewerage corporation, and another by the Dominican Electric Transmission Company. Traffic began to fall just before 16:00 UTC and dropped by roughly two-thirds compared to the prior week. Technicians located and repaired the faults quickly, and traffic recovered around 18:00 UTC.

Angola

An Internet disruption in Angola between 12:45 and 15:45 UTC on July 19 hit Unitel Angola (AS37119) particularly hard, with traffic falling as much as 95% compared to the previous week, while Connectis (AS327932) suffered a complete outage. Unitel Angola attributed the problem on X to “a disruption at our partner Angola Cables, resulting from public road works that affected the national fiber optic interconnections.”

The timing, however, coincided with protests over rising diesel fuel prices, and local NGOs disputed the explanation, claiming the disruption was a government-directed Internet shutdown. Routing analysis shows that the affected networks share Angola Cables (AS37468) as an upstream provider, lending some support to Unitel's account.

Haiti

Digicel Haiti (AS27653) experienced yet another fiber-related outage on August 26 — a recurring problem for the operator, which has suffered similar disruptions in each of the previous several quarters. Two separate cuts on its fiber infrastructure caused traffic to drop by approximately 80% between 19:30 and 23:00 UTC.

Red Sea cable cuts affect Pakistan and the UAE

The Red Sea's dense concentration of submarine cables means a single cut can ripple across multiple countries. On September 6, Pakistan Telecom (AS17557) reported on X that “submarine cable cuts have occurred in Saudi waters near Jeddah, impacting partial bandwidth capacity on SMW4 and IMEWE systems.” Later reporting corrected the location to Yemeni waters. In Pakistan, traffic dropped 25-30% in the Sindh and Punjab regions between 12:00 and 20:00 UTC.

Two UAE providers were also affected. Etisalat (AS8966) warned customers of “slowness in data services due to an interruption in the international submarine cables,” with traffic dropping as much as 28% between 11:00 and 22:00 UTC. du (AS15802) issued a similar notice; median bandwidth on its network fell from 25 Mbps to as low as 9.8 Mbps, while median latency doubled from 30 ms to over 60 ms.

Cloudflare network probes between New Delhi and London and between Bombay and Frankfurt show the regional impact of the cuts. Mean latency grew by approximately 20% for the former path and 30% for the latter, starting around 23:00 UTC on September 5.

BLOG-3034 image 2
BLOG-3034 image 3

North Texas

Fiber faults are usually caused by anchors or excavators, but on September 26, a stray bullet damaged a cable in the Dallas area, disrupting connectivity for Spectrum (AS11427) customers. Spectrum acknowledged the interruption on X and announced the issue resolved roughly four and a half hours later; news reports attributed the bullet claim to a company spokesperson. Traffic dropped less than 25% compared to the prior week during the two-hour disruption, which lasted from 18:00 to 20:00 UTC.

South Africa

Telkom (AS37457) customers in South Africa lost service on September 27 due to what the operator later described as “major cable breaks.” The operator initially acknowledged the disruption on X and later confirmed in a statement that “mobile voice and data services... have now been fully restored nationwide.” The outage lasted six hours, from 08:00 to 14:00 UTC, with traffic falling as much as 50% compared to the previous week.

Power failures take down national connectivity

Several countries saw widespread Internet disruptions in Q3 2025 that traced back to problems with electrical infrastructure. Power outages at data centers, failures in national grids, and accidental cable cuts all translated into measurable drops in online traffic.

Tanzania

A power outage at an Airtel Tanzania data center on July 1 disrupted mobile connectivity for customers. The interruption ran from 11:30 to 18:00 UTC, with traffic on Airtel Tanzania (AS37133) falling by as much as 40% compared with the previous week.

Czech Republic

On July 4, a fallen power cable triggered a major power outage across the Czech Republic. Internet traffic dropped by as much as 32%, falling just after the outage began at 10:00 UTC. Though power was nearly fully restored by 16:00 UTC, traffic did not return to expected levels until closer to 20:00 UTC; that slow recovery matched reports that tens of thousands of people remained without electricity into the evening even after the grid operator restored full functionality in the mid-afternoon.

St. Vincent and the Grenadines

St Vincent Electricity Services Limited (VINLEC) reported a system failure on August 16 that cut power to customers on mainland St. Vincent starting at approximately 11:30 local time. Power was restored to all customers just after 04:00 local time on August 17. During the roughly four-hour outage, Internet traffic dropped by as much as 80% below expected levels.

Curaçao

A power outage confirmed by Aqualectra, the island's water and power company, disrupted Internet connectivity across multiple providers in Curaçao, including Flow (AS52233) and UTS (AS11081). Traffic began dropping around 06:45 UTC and did not recover to expected levels until around 23:45 UTC. During the disruption, the country's traffic dropped by over 80% compared with the previous week, with Flow experiencing a near complete outage.

Cuba

Cuba experienced yet another collapse of its national electric power system on September 10, following the unexpected shutdown of the Antonio Guiteras Thermoelectric Power Plant (CTE) at 09:14 local time. The island's Internet traffic dropped by nearly 60% almost immediately and remained below normal for over a day. Traffic only returned to expected levels around 17:15 UTC on September 11, when the Ministerio de Energía y Minas de Cuba posted on X that the national electric system had been restored.

Gibraltar

A contractor cutting through three high voltage cables caused a nationwide power outage in Gibraltar on September 16, according to the Gibraltar government. Internet traffic was disrupted from 11:15 to 18:30 UTC, falling as low as 80% below the previous week's levels.

Earthquake hits Russian networks

A magnitude 8.8 earthquake struck the Kamchatka Peninsula in Russia at 23:24 UTC on July 29, triggering tsunami warnings for Japan, Alaska, Hawaii, Guam, and other Russian regions. Internet traffic across several regional networks dropped immediately, including Rostelecom (AS12389) and InterkamService (AS42742), where traffic fell by 75% or more. Both providers started recovering almost immediately, but Rostelecom returned to expected levels much more quickly than InterkamService.

Cyberattack targets YemenNet

A cyberattack targeting Houthi-controlled YemenNet (AS30873) on August 11 briefly disrupted connectivity across Yemen. Traffic dropped significantly at around 14:15 UTC and recovered by 15:00 UTC, aligning with the reported timing and duration of the attack, which focused on YemenNet's ADSL infrastructure.

The attack also affected YemenNet's routing. Announced IPv4 address space began to decline as the attack commenced and remained depressed for approximately an additional hour after it ended, reaching as low as 510 /24s being announced, down from a steady state of 870 /24s.

Fire disrupts Cairo telecommunications

A fire at the Ramses Central Exchange in Cairo on July 7 disrupted telecommunications services for multiple providers with infrastructure in the facility. The fire broke out in a Telecom Egypt equipment room, impacting connectivity across Etisalat (AS36992), Mobinil (AS37069), Orange Egypt (AS24863), and Vodafone Egypt (AS24835). Traffic initially dropped at 14:30 UTC, with recovery varying by provider: Etisalat recovered by July 9, Vodafone and Mobinil by July 10, and Orange Egypt on July 11. Telecom Egypt announced on July 10 that services had been restored after operations were transferred to alternative exchanges.

Technical failures and network anomalies

Starlink (AS14593) acknowledged a network outage on July 24 via a post on X. The Vice President of Network Engineering at SpaceX explained that the outage was caused by failure of key internal software services that operate the core network. Traffic initially dropped around 19:15 UTC, and the disruption lasted approximately 2.5 hours. The impact was particularly noticeable in Yemen and Sudan, where traffic dropped by approximately 50%, as well as in Zimbabwe, South Sudan, and Chad.

China

Around 16:30 UTC on August 19, anomalous Internet traffic patterns appeared in China, with a 25% drop in traffic. Analysis showed a drop in the share of IPv4 traffic and a spike in the share of HTTP traffic, indicating that HTTPS traffic share had fallen. The share of TCP connections terminated in the Post SYN stage doubled during the outage, from 39% to 78%.

A Great Firewall Report blog post identified the cause: between approximately 00:34 and 01:48 Beijing Time on August 20, the Great Firewall of China (GFW) behaved anomalously by unconditionally injecting forged TCP RST+ACK packets to disrupt all connections on TCP port 443, causing massive disruption of Internet connections between China and the rest of the world. The responsible device did not match the fingerprints of any known GFW devices, suggesting the incident was caused by either a new GFW device or a known device operating in a novel or misconfigured state.

Pakistan

Subscribers of Nayatel (AS23674) experienced an approximately 90 minute disruption on September 24 due to a reported outage at an upstream provider. Traffic dropped as much as 57% between around 09:15 and 10:45 UTC. Transworld (AS38193), one of several upstream providers to Nayatel, saw a more significant drop lasting from around 09:15 to 12:15 UTC. The Nayatel disruption was less severe than Transworld's because Transworld is upstream of only a portion of the prefixes originated by Nayatel; traffic from other Nayatel prefixes was carried by other providers that remained available.

Cloudflare Radar Q3 2025: Untangling Network Outages Without Clear Root Causes

Iran: Conflicting Explanations for a National Drop

Just weeks after a complete shutdown, Iran saw another sharp decline in internet traffic on July 5 at around 21:00 UTC. Traffic dropped by 80% compared to the prior week, but unlike many events in this series, there was no single official story.

State media cited a national disruption in international connectivity affecting most ISPs, but provided no cause. Meanwhile, civil society groups monitoring connectivity in the region suggested the drop was the result of an intentional shutdown. A separate claim, referenced and disputed on social media, attributed the event to a DDoS attack. No definitive technical explanation has emerged.

Colombia: A Brief, Unexplained Drop for Claro

Claro Colombia customers experienced a short disruption on August 6, with traffic falling by two-thirds or more between 16:45 and 17:20 UTC. The event impacted multiple ASNs operated by Claro, including AS10620, AS14080, and AS26611. Although the graphs may show historical names like Telmex Colombia and Comcel, those entities merged in 2012 and have operated under the Claro brand since. Claro did not publicly acknowledge the incident or offer any explanation.

Pakistan: A Fiber Fault, But Corroborating Data Is Thin

A near-total outage at backbone provider PTCL (AS17557) on August 19 caused traffic to drop 90% at 16:10 UTC. The company acknowledged "data connectivity challenges" on PTCL and Ufone services, and later confirmed restoration, but did not specify a cause. Media reports attributed the failure to a technical fault in PTCL's fiber optic infrastructure, which aligns with some technical observations from Cloudflare Radar.

During the outage, traffic from PTCL to Cloudflare's 1.1.1.1 DNS resolver spiked, with the share of requests over UDP rising from 94% to 99%. Routing data also showed a small drop in announced IPv4 space. While these signals are consistent with a fiber break, they don't definitively confirm that as the root cause.

South Africa: A Quick Acknowledgment, No Explanation

South African provider RSAWEB (AS37053) was quick to acknowledge an issue with FTTx and Enterprise services on September 10, but subsequent updates never disclosed the nature of the problem. The event caused a near-complete loss of traffic between 15:00 and 16:30 UTC.

Notably, routing data shows a drop of only two announced /24 blocks, from 470 to 468, coinciding with the outage. Given that RSAWEB's outbound traffic would likely require more than just 512 IPv4 addresses, this small routing change seems an unlikely sole cause for such a severe impact.

Starlink experienced another short disruption on September 15 between 04:00 and 05:00 UTC, following a brief software-related event in July. While the company often posts status updates on X, in this case, any acknowledgment was removed after the issue was resolved. Observational data does, however, provide clues: concurrent with the traffic drop, there was a decline in announced IPv4 space and a spike in BGP announcements, likely withdrawals. This pattern suggests a network-related issue rather than a software fault.

Conclusion: More Tools, More Questions

The addition of regional traffic insights to Radar provides a deeper perspective for investigating anomalies. Analysts can now examine events not just at a country level, but drill down by network, and review impacts on DNS traffic, bandwidth, latency, TCP tampering, and announced IP space. The underlying data is accessible through a rich API for custom monitoring and analysis, and an MCP server allows integration with AI-based tools.

Internet disruptions are a constant reality, and the Cloudflare Radar team continues to track and document them. Their findings are published on the Cloudflare Radar Outage Center, via social media, and on the Cloudflare blog. More often than not, the community is left with observable data and unanswered questions about the root causes of these events.