A Quarter of Shutdowns and Grid Failures
Cloudflare’s network spans more than 330 cities across over 125 countries, interconnected with more than 13,000 network providers. This breadth offers a unique perspective on Internet resilience, allowing observation of disruptions at local, national, and network levels. The following is a summary of observed and confirmed disruptions for Q2 2025, drawn from traffic anomaly detection available in the Cloudflare Radar Outage Center. This overview is not exhaustive; both bytes-based and request-based traffic graphs illustrate impacts, with metric choice based on which better demonstrates the disruption.
Unlike Q1 2025, which saw no government-directed shutdowns, the second quarter exhibited a regression. Shutdowns were observed in Libya, Iran, Iraq, Syria, and Panama. The quarter also underscored the Internet’s dependence on stable electrical grids, with a major power outage in Spain and Portugal disrupting regional connectivity.
Government-Directed Shutdowns
Multiple countries implemented intentional Internet restrictions during the quarter, targeting various services and regions for different durations and purposes.
Libya: Social Media Blocking
Late in the quarter, Libya blocked access to Facebook, Instagram, TikTok, and Messenger. Traffic to these platforms dropped to near zero on major Libyan networks, including Libya Telecom & Technology and Libya Alhadeth. The block appeared to correspond with the anniversary of the 2011 revolution, with the stated goal of preventing the spread of “malicious content.”
Iran: Nationwide Platform Blocks
Iran blocked access to WhatsApp and Google services for approximately one week, following widespread protests. The government cited “illegal gatherings” and “insecurity” as reasons for the restriction. Nationwide, traffic to WhatsApp dropped significantly to ISPs including Mobile Communication Company of Iran (MCI) and Rightel. Google services, including Gmail and YouTube, also saw substantial traffic declines during this period.
Iraq: Regional Internet Shutdown
A nationwide internet blackout in Iraq lasted between 6 and 9 hours during a government-mandated census. Traffic on major providers like Earthlink, Mobitel, and Fastlink collapsed to near zero across both mobile and fixed-line networks, with connectivity resuming only after the census period ended.
Syria: Service-Specific and Regional Disruptions
Syria experienced multiple disruptions during the quarter. In June, the government blocked Telegram to prevent “leaks” and “distortion” related to recent events. The block lasted approximately 21 hours across providers like Syrian Telecom. A week later, authorities shut down internet access in several governorates for a military operation, affecting connectivity for roughly 4 hours.
Panama: Nationwide Block
Following disputed elections and resulting protests, Panama’s government enacted a nationwide internet block to prevent the use of social media to incite violence, looting, and vandalism. Traffic on national ISPs such as Cable Onda and Liberty Networks dropped nearly to zero for approximately 3 hours during the shutdown.
Power Outages Lead to Internet Outages
A significant power outage in Spain and Portugal caused widespread Internet disruption in both countries. Reports suggested a malfunction at a nuclear power station in Spain triggered the blackout. Traffic on major Spanish ISPs, including MasMovil, Vodafone Spain, Telefonica, and Digi, dropped dramatically for nearly 20 minutes before recovering. Portuguese providers like MEO and NOS saw similar prolonged traffic drops.
Fiber Optic Cable Damage
Physical infrastructure damage led to outages in several regions during the quarter.
- Malawi: A fiber optic cable cut caused nationwide Internet outages for most of a day. Traffic drops were observed on
TNM,Airtel Malawi, andAccess Communications. - Haiti: The destruction of a fiber optic cable by arsonists severely degraded Internet services, particularly affecting the
Natcom Haitimobile operator. - Somalia: A cable cut disrupted service for four operators for a couple of days, though affected users may have been able to route around the issue.
- Romania: A regional fiber optic cable was cut twice within ten days, causing intermittent national-level impacts.
Technical Problems and Cyberattacks
Technical issues, including hardware failures and software configuration errors, disrupted service for several major providers in North America and Europe.
- T-Mobile US: A nationwide service disruption harmed mobile services for several hours.
- Comcast: Xfinity Internet customers experienced a multi-hour service disruption.
- CenturyLink / Lumen & Rogers Communications: Both providers experienced disruptions attributed to configuration errors, lasting 1-3 hours on a single day each.
- Swisscom & Sunrise: Swiss Internet users faced intermittent issues with fixed-line and mobile services due to technical failures.
Meanwhile, a Russian provider, Miralogic, was knocked offline by a significant cyberattack. The network, primarily serving Moscow and central Russia, dropped to near-zero traffic levels following the attack’s onset. While the provider had recovered by the following day, traffic volumes remained well below normal baseline levels.
Unexplained Disruptions
Several notable Internet outages during the quarter lacked official attribution for their root causes.
- Belarus: Nationwide disruption lasted most of a day, affecting four mobile operators and the national ISP
Beltelecom. While a similar event in November 2024 was attributed to a DDoS attack, no cause was provided at the time. - Indonesia: Nationwide degradation for about half a day impacted four major operators, likely due to technical issues.
- South Africa: A national disruption affected three major ISPs, possibly linked to a submarine cable problem, though no official statement was released.
- Côte d'Ivoire: A nationwide outage lasting roughly 3 hours impacted four major mobile operators. The timing of the disruption correlated with political tensions, but no official reason was given.
- Qatar: A major provider,
Vodafone Qatar, experienced nationally visible impacts for over half a day, with no official attribution.
State-directed disruptions in Q2 2025 covered a familiar territory of protests, national security concerns, and examination periods.
Protest and conflict-related shutdowns
In Libya, connectivity was cut on May 16 in response to protests against the Government of National Unity. Starting at 13:30 UTC, traffic dropped by more than 50% compared to the prior week across several major providers, including Libyan International Company for Technology (AS329129), Giga Communication (AS328539), and Aljeel Aljadeed for Technology (AS37284). Awal Telecom (AS328733) saw a complete outage. Traffic volumes returned to near-normal within an hour of midnight UTC, though Giga Communication suffered a second disruption on May 17 between 02:00 and 11:30 UTC.
Iran experienced a series of shutdowns in June following attacks on the country's nuclear sites. The first, on June 13, lasted from 07:15 to 09:45 UTC. Iran’s Ministry of Communications formally announced the measure, stating that temporary restrictions had been imposed "in light of the country's special circumstances" and would be lifted once normal conditions returned. The impact was felt across FanapTelecom (AS24631), Rasana (AS205647 and AS31549), MCCI (AS197207), and TCI (AS58224), among others.
A second round began on June 17 at 14:00 UTC. A government spokesperson said the move was intended to "ward off cyber attacks." Recovery was staggered by provider: FanapTelecom and Pars Online (AS16322) restored service around 15:30 UTC, MCCI and IranCell (AS44244) by 20:00 UTC, RighTel (AS57218) by 22:00 UTC on June 17, and Rasana only by 06:00 UTC on June 18. During both of these early restrictions, inbound international traffic was reportedly blocked, with user access limited to Iran’s domestic National Information Network.
A third, much longer shutdown ran from 12:50 UTC on June 18 through 05:00 UTC on June 25. Citing cyberattacks on critical infrastructure, banks, and even a hacked cryptocurrency exchange, a spokesperson noted the government had decided to impose Internet restrictions as a security measure. Traffic dropped to near zero through June 21, when partial recovery was observed. Volumes then settled into a consistent, lower-than-normal cycle for several days, returning to expected levels only on June 25. The same set of network providers was affected.
In Panama, authorities in the province of Bocas del Toro ordered a suspension of mobile telephony and residential Internet services starting June 21. The measure, announced by the telecom regulator ASEP and tied to protests over Social Security Fund reforms, was initially set to end June 25 but was extended to June 29. Traffic from Cable Onda (AS18809) effectively dropped around 03:30 UTC on June 21 and recovered only around 06:00 UTC on June 30, per ASEP's confirmation that services were restored at 12:01 a.m. local time that day.

Exam-related disruptions
Iraq continued its years-long practice of cutting Internet access during national exams. Shutdowns in the main part of the country ran from May 20 to June 4 for middle school exams and from June 14 to July 3 for preparatory school exams, occurring daily between 03:00 and 05:00 UTC. Providers implementing the restrictions included Earthlink (AS199739), Asiacell (AS51684), Zainas (AS59588), Halasat (AS58322), and HulumTele (AS203214).
In the Kurdistan region, measures ran from June 1 through July 6, but only on Wednesdays and Sundays, between 03:30 and 04:30 UTC. This affected IQ Online (AS48492), KorekTel (AS59625), Newroz Telecom (AS21277), and KNET (AS206206).
Syria also follows this annual pattern, but with a change in 2025. Rather than a nationwide cutoff, the government ordered a targeted "temporary cellular communications blackout" in areas near examination centers. The statement emphasized the measure was limited to the narrowest possible geographical area and time frame while students were in exam halls. Shutdowns tied to the Basic Education Certificate occurred on June 21, 24, and 29 between 05:15 and 06:00 UTC. Because only mobile networks were affected, announced IP address space dropped only partially, in contrast to the near-complete losses seen in prior years. Secondary Education Certificate exams are scheduled from July 12 to August 3.
When the lights go out, so does the Internet
Power grid failures continued to be a major driver of Internet outages during Q2 2025. The most significant event was the large-scale outage affecting Portugal and Spain on April 28, detailed extensively in Cloudflare’s own analysis of the event. In Portugal, traffic plunged roughly 50% immediately as the grid failed, and within five hours was down about 90% compared to the previous week. Spain saw a similar pattern, with an immediate drop of around 60%, falling to approximately 80% below normal within the next five hours. Both countries returned to expected traffic levels around 01:00 local time (midnight UTC) on April 29.


The Iberian outage even rippled across the Mediterranean. Moroccan provider Orange Maroc posted on X that Internet traffic had been disrupted “following a massive power outage in Spain and Portugal, which is affecting international connections.” Traffic for the network (AS36925) fell sharply around 12:00 UTC, about 90 minutes after the power outage began, with a full outage starting around 15:00 UTC. Service returned to normal around 23:30 UTC on April 28.
Puerto Rico also experienced a major power event on April 16, when Genera PR reported “a massive power outage across the island due to the unexpected shutdown of all generating plants.” Luma Energy, responsible for transmission and distribution, said service was affected island-wide as of approximately 12:40pm. While described as massive, the impact on Internet traffic was comparatively contained — dropping initially by about 40%. Recovery was fairly quick: by 15:00 UTC on April 18, traffic was back to expected levels, aligning with Luma’s update that it had restored power to 98.8% of customers in less than 38 hours. The outage did cause some disturbance to announced IP address space, however.
Smaller power-related disruptions also appeared around the world:
- Saint Kitts and Nevis: SKELEC reported a fault at its Needsmust Power Plant on May 9, causing an island-wide outage with restoration estimated at two hours. Traffic dropped about 30 minutes before the 17:31 UTC post, and began recovering around 17:45 UTC, though it didn’t fully normalize until 20:15 UTC.
- North Macedonia: A voltage spike in the regional 400 kV network on May 18 caused a brief outage, with supply normalized within an hour, per state-owned MEPSO. The short disruption (roughly 03:00 – 04:45 UTC) still cut Internet traffic by nearly 60% versus the prior week.
- Maldives: A widespread outage in the Greater Malé region on June 1 led providers Ooredoo and Dhiraagu to warn of fixed and mobile broadband interruptions. Country-level traffic was disrupted between 07:30 – 13:00 UTC, dropping by about half. Announced IPv4 address space saw a nominal dip (355 to 350 /24s) before recovering.
- Curaçao: Provider Flow Curaçao (AS52233) suffered a near-complete outage starting 18:00 UTC on June 14. Recovery began about 11:00 UTC on June 15, with fuller restoration around 14:00 UTC. Flow Barbados later attributed the issue to a commercial power outage at a key regional network facility in Curaçao, which drew demands from the local telecom regulator.
Cable damage sets off network outages
Physical damage to fiber infrastructure caused complete outages for two providers this quarter. In Haiti, Digicel Haiti (AS27653) went fully offline as of 21:00 UTC on May 28 after two instances of fiber optic damage. Announced IPv4 and IPv6 address space dropped to zero, and the network didn’t recover until 00:45 UTC on May 29.
Airtel Malawi (AS37440) faced a shorter, 90-minute outage on June 24, attributed by the company to “ongoing vandalism on their fiber network.” While traffic effectively vanished between 12:30 – 14:00 UTC, some IPv4 address space remained announced, indicating partial connectivity. Announced IPv6 space, however, fell to zero for the duration.
Technical glitches: routers and DNS
Not all disruptions stem from power or physical damage. Bell Canada (AS577) customers in Ontario and Quebec lost service on May 21 after a faulty router update. Traffic dropped around 13:15 UTC, falling as much as 70% versus the prior week, and was accompanied by a significant decline in requests to Cloudflare’s 1.1.1.1 DNS Resolver. The provider rolled back the update quickly, with traffic returning to normal within about an hour and full restoration confirmed by 15:00 UTC. Only a negligible decline in announced IPv4 space was observed.
A more widespread U.S. disruption hit Lumen/CenturyLink (AS209) on June 19. Traffic dropped by over 50% from around 21:45 UTC, recovering by midnight. Subscriber reports pointed to a DNS issue: those who switched their resolver to Cloudflare’s 1.1.1.1 could get back online. Indeed, traffic to 1.1.1.1 from the network spiked above the prior week’s levels during the disruption and stayed elevated into June 20 — a pattern consistent with a broken ISP DNS resolver making it appear as though the entire Internet was down.
DDoS fallout in Russia
Russian ISP ASVT (AS8752) suffered a major DDoS attack that knocked it offline for days. The assault, which peaked at 70.07 Gbps and 6.92 million packets per second, drove traffic to near zero around 05:00 UTC on May 28. Service began returning roughly ten hours later but stayed below normal levels for the following week. The incident came on the heels of a similar attack against Russian provider Nodex (AS29329) in March.
Notably, query volume to Cloudflare's 1.1.1.1 DNS resolver from ASVT spiked sharply as traffic recovered and stayed elevated through the disruption. It's unclear whether the increase stemmed from problems with ASVT's native DNS resolver during the attack, pushing users to alternatives, or from subscribers seeking workarounds for the damage.
Outages without explanation
Telia Finland
Telia Finland (AS1759) acknowledged a "widespread disruption" to mobile data and fixed broadband on April 1, causing a near-complete outage between 06:30 and 07:15 UTC. The cause was never disclosed. The incident visibly hit IPv4 connectivity, with announced IPv4 address space dropping while IPv6 announcements stayed steady. Accordingly, the share of Telia traffic carried over IPv6 — normally under 5% — spiked above 30% during the event. DNS query volume to 1.1.1.1 from the network also rose concurrently.
SkyCable
Philippine provider SkyCable (AS23944) went dark around 19:15 UTC on May 7. Both traffic and announced IPv4 address space fell to zero, with connectivity restored about eight hours later, at 03:00 UTC on May 8. The company published no information about the cause.
TrueMove H
Thai mobile carrier TrueMove H (AS132061) experienced a nationwide outage on May 22. Traffic dropped by over 80% relative to the prior week at 03:00 UTC, recovering gradually to expected levels around 08:00 UTC. A brief partial drop in announced IPv4 address space was observed during the first hour. The provider apologized but gave no official explanation; local press attributed the issue to "technical errors on True's computer servers," while others suggested a fault in True's DNS servers.
Digicel Haiti
Just two days after a cable-damage outage, Digicel Haiti (AS27653) lost connectivity again on May 30. This time the network disappeared entirely at 14:15 UTC, with traffic and announced IP space (both IPv4 and IPv6) dropping to zero. Unlike the earlier incident, no social media statements were issued. Services returned nearly three hours later, around 17:00 UTC.
Syria
On June 10, a two-hour outage hit Syria's ADSL landline network across multiple provinces. Traffic fell by as much as two-thirds below the prior week's levels at 08:15 UTC, with announced IPv4 address space also declining — a potential sign of infrastructure trouble. At the same time, DNS query volume from Syria to 1.1.1.1 was elevated, a pattern previously observed during government-directed shutdowns where traffic can leave the country but not return. There was no other indication of an intentional shutdown, and no official explanation emerged.
Quarterly takeaways
Government-directed shutdowns returned with force in Q2 and have continued into Q3, though the more recent ones have been tied to exams rather than protests. Meanwhile, the massive power-outage-driven disruption across Spain and Portugal on April 28 underscored how interconnected electrical infrastructure is across borders — a reminder that a problem in one country can readily spill over into its neighbors.



