Russian ISPs Throttling Cloudflare Connections
Since June 9, 2025, Internet users in Russia connecting to web services protected by Cloudflare have been throttled by local Internet Service Providers (ISPs). Because the throttling is applied at the ISP level, it falls outside Cloudflare's control, and the company states it cannot lawfully restore reliable access to its products or protected websites for Russian users at this time.
Internal data analysis suggests the throttling limits users to loading only the first 16 kilobytes of any web asset, rendering most navigation unusable. Cloudflare reports it has not received formal outreach from Russian government entities explaining the action. The behavior is consistent with longstanding Russian efforts to isolate its domestic internet and reduce reliance on Western technology. External reports corroborate the analysis and indicate other providers, including Hetzner, DigitalOcean, and OVH, may also be affected by throttling or similar disruptions.
Scope and Mechanism of Disruption
Cloudflare is observing disruptions on connections originating from inside Russia, even when those connections reach servers outside the country. This points to interference occurring within Russian ISPs, close to the end user.
ISPs confirmed to be implementing the disruptive actions include Rostelecom, Megafon, Vimpelcom, MTS, and MGTS. Observed mechanisms include injected packets that halt connections and blocking packets that cause timeouts. A new tactic beginning June 9 limits content served to 16 KB. The throttling affects all connection methods and protocols, including HTTP/1.1 and HTTP/2 over TCP and TLS, as well as HTTP/3 over QUIC.
Evidence from Network Data
Cloudflare Radar data shows a high rate of connectivity errors across its data centers, resulting in an overall decrease in traffic served to Russian users:

Client-side reporting via the W3C-defined Network Error Logging (NEL) feature shows an increase in TCP connections being reset prematurely. A significant growth in h3.protocol.error reports indicates QUIC connections have been heavily affected:

Internal tooling also shows elevated packet loss to Russian data centers:

High packet loss alone is not conclusive evidence of throttling. However, two additional data points support the conclusion. First, public reports indicate "throttling" here means blocking connections after 16 KB is transmitted, which typically requires 10 to 14 packets. Second, Cloudflare's "Resets and Timeouts" tooling captures anomalous TCP behavior occurring within the first 10 packets.
Since 10 packets can carry 16 KB of data, connections blocked near that threshold are visible at the "Post PSH" stage in Radar data. In TCP, the PSH message indicates Cloudflare received the initial request and data transfer has begun. If the connection is blocked at this stage, many sent packets will be lost. Radar data focused on the Post-PSH stage shows a dip followed by an immediate and proportionally large increase before June 11, closely matching the packet loss pattern:

Guidance for Site Operators
For operators using Cloudflare to protect sites serving Russian users, Cloudflare states it currently cannot restore connectivity for Russia-based users. The company advises reaching out to Russian entities to request the lifting of throttling measures. Enterprise customers are directed to contact their account teams for further assistance.
Cloudflare condemns any attempt to prevent Russian citizens from accessing a free and open Internet.



