Connectivity Under Pressure: A Look at Q1 2026 Internet Disruptions
The first quarter of 2026 saw a wide range of events disrupt Internet connectivity across the globe, from government-imposed shutdowns and military strikes to power failures and severe weather. Government-directed shutdowns were particularly prominent, marking a notable shift from the same period a year earlier, during which none were observed. Several of these shutdowns were prolonged, lasting weeks or even months.
This review covers confirmed disruptions observed during the quarter and is not exhaustive. The data and traffic graphs referenced here illustrate the impact of these events, selected based on which metric—bytes or requests—best demonstrates the disruption.
State-Ordered Internet Blackouts
Election-Related Shutdowns in Uganda and Republic of Congo
In the days leading up to Uganda's January 15 presidential election, the Uganda Communications Commission (UCC) ordered mobile network operators to suspend public Internet access, effective 18:00 local time on January 13, citing a need to curb "misinformation, disinformation, electoral fraud and related risks." The action was drastic: traffic at the Uganda Internet Exchange Point dropped from approximately 72 Gbps to 1 Gbps, and Cloudflare data shows a near-complete loss of traffic from the country.
Connectivity remained effectively at zero until January 17, when a partial restoration occurred after incumbent President Yoweri Museveni was declared the winner of a seventh term. The UCC announced a full restoration on January 26, with MTN Uganda and Airtel Uganda confirming the lifting of restrictions. The outage was notable given authorities' repeated assurances in early January that rumors of a shutdown were "false and misleading." The 2026 action drew lawsuits against the UCC and telecoms from civil society groups like CIPESA. Uganda also blocked Internet access during its 2021 election.
Similarly, the Republic of Congo experienced a near-complete Internet shutdown on March 15, as the country held a presidential election expected to extend President Denis Sassou Nguesso's 42-year rule. Traffic plummeted around 06:30 local time and remained near zero for approximately 60 hours. Recovery began on March 17 at 18:20 local time, with traffic rebounding to pre-shutdown levels. Authorities offered no explanation, though similar shutdowns occurred during the 2021 and 2016 elections.
Iran: A Quarter of Severe Restrictions
Iranian citizens faced two significant nationwide Internet shutdowns during the quarter, spending much of the first two months of 2026 either entirely offline or with heavily restricted connectivity. The first began around 20:00 local time on January 8. Traffic from the country remained near zero until a small amount returned on January 21, only to disappear about 24 hours later. Similar brief restorations occurred on January 25 before a more sustained recovery began on January 27.
A notable detail was the near-complete loss of announced IPv6 address space that began several hours before this first traffic drop. The single largest contributor was Asiatech (AS43754), which lost 4.46 million /48-equivalents, representing roughly 9.4% of Iran's total IPv6 space loss. RASANA (AS31549) was the second-largest, losing 4.19 million /48-equivalents. Given the timing gap, this IPv6 de-announcement was likely a leading indicator of the shutdown, but not its direct cause. Announced IPv4 address space remained fairly consistent, suggesting the shutdown was implemented through other means, such as traffic filtering.
As military strikes on Iran escalated, a second nationwide shutdown began on February 28. Cloudflare Radar observed a sharp drop in traffic beginning around 10:30 local time, with levels falling to well under 1% of previous traffic. Only small amounts of Web and DNS traffic continued to egress the country. Unlike the first shutdown, there were no significant shifts in announced IP address space, pointing again to aggressive filtering. Reports of "whitelists" and "white SIM cards"—which restricted access to only approved sites for selected users—support this theory.
Iran remained effectively offline through the end of the quarter and into late April, rendering this one of the longest sustained Internet disruptions in recent years.
Conflict and Collateral Damage
Strikes on Ukrainian Infrastructure
Military action continued to cause disruptions in Ukraine. A Russian attack on energy infrastructure on January 7-8 led to power outages that disrupted connectivity in Dnipropetrovsk and surrounding regions. Cloudflare Radar observed a nearly 50% drop in traffic relative to the prior week's levels, starting around 22:45 local time on January 7. Recovery began approximately 07:15 hours later, at 06:00 local time on January 8.
Another attack on January 26, this time involving drones and missiles targeting energy infrastructure in Kharkiv, led to an approximately 50% drop in regional traffic beginning around 19:15 local time. Power was restored gradually through January 27, leading to a slow recovery phase.
Physical Attacks on AWS Data Centers
One of the most unusual disruptions was physical damage to Amazon Web Services data centers in the Middle East from drone strikes linked to the regional conflict. On the morning of March 1 (UTC), Amazon reported a fire at a UAE data center after it was hit by an object. The following day, the company confirmed that two facilities in the UAE (the me-central-1 region) were directly struck by drones, and that a facility in Bahrain (the me-south-1 region) was taken offline after being damaged by a nearby strike.
Cloudflare's Cloud Observatory data showed elevated connection failure rates for both the me-central-1 and me-south-1 regions beginning March 1-2 and persisting for multiple days. These connection failures occur when Cloudflare cannot successfully connect to an origin server to retrieve uncacheable or expired content.
In an AWS Health Dashboard status post, Amazon acknowledged that the strikes caused structural damage, disrupted power delivery, and triggered fire suppression activities, leading to additional water damage. The company warned that instability in the region could make operations "unpredictable" and advised customers to back up data or migrate workloads to other regions. For the rest of Q1 2026, other regions saw no similar disruptions either from other conflicts or from DNS issues. However, the AWS me-south-1 region in Bahrain suffered an additional disruption on March 23 following further drone activity.
Other Notable Outages
Beyond these events, the quarter saw a variety of other disruptions. Cuba experienced three separate collapses of its national electrical grid, disrupting connectivity. Severe weather knocked out Internet in Portugal, while cable damage affected the Republic of Congo. A technical problem impacted Verizon Wireless customers in the United States, and unknown issues briefly disrupted connectivity for customers of providers in Guinea and the United Kingdom.
Grid failures and connectivity loss
Argentina and Paraguay
A heat-wave power cut in Buenos Aires on January 15 briefly slowed Internet traffic for several local providers, including Telecom Argentina (AS7303), Telecentro (AS27747), and IPLAN (AS16814). Cloudflare Radar observed reduced traffic between roughly 17:30 and 19:30 local time (20:30–22:30 UTC), with service returning to normal about two hours after the outage began.
A more severe event hit Paraguay on February 18, when key transmission lines failed and triggered widespread blackouts. The National Electricity Administration (ANDE) documented the incident and restoration work on X. Internet traffic from the country fell as much as 72% below the prior week's levels, starting around 15:15 local time (18:15 UTC) and recovering near 18:30 local time (21:30 UTC) — a disruption lasting roughly three hours.
Moldova and Ukraine
An emergency shutdown of Ukraine's electricity grid on January 31 had cross-border consequences. A technical malfunction at 10:42 local time (08:42 UTC) simultaneously took down a 400 kV line connecting Romania and Moldova and a 750 kV line between western and central Ukraine, according to the Ukrainian Energy Minister. Widespread power cuts followed in Moldova and in Ukrainian regions including Kyiv and Kharkiv. Cloudflare Radar traffic for these areas began dropping at the time of the malfunction, reaching as much as 46% below the prior week, with recovery by around 14:00 local time (12:00 UTC).
Dominican Republic and the U.S. Virgin Islands
A major failure in the Dominican Republic's Interconnected National Electric System (SENI) on February 23 caused a country-wide blackout. The state-owned transmission company ETED posted updates on X describing the failure and restoration work. Internet traffic from the country dropped sharply from about 10:50 local time (14:50 UTC) and did not fully recover until around midnight local time (04:00 UTC on February 24), matching ETED's confirmation that the SENI was restored to 100% at 11:53 p.m. that Monday.
A more localized outage hit the U.S. Virgin Islands on March 24. The Virgin Islands Water and Power Authority (WAPA) reported a loss of generation at the Richmond Power Plant combined with damage to an underground cable, affecting St. Croix and St. Thomas. Traffic from VI Powernet (AS14434), the territory's primary ISP, dropped to near zero starting around 12:15 local time (16:15 UTC) and recovered by approximately 14:45 local time (18:45 UTC). Because other providers were present, St. Thomas traffic only fell by about 60% and St. Croix by about 40%.
Cuba
Cuba's National Electric System (SEN) collapsed three separate times in March, each causing significant Internet disruption and underscoring the severe deterioration of the country's electrical infrastructure. (Similar outages also disrupted Cuban connectivity in March and September 2025 and October 2024.)
The first collapse came on March 4, when a disconnection cascaded from Camagüey to Pinar del Río, cutting power to the western half of the island, including Havana. OSDE/UNE, Cuba's Electric Union, confirmed the failure on social media. Cloudflare Radar showed island-wide traffic dropping by nearly half from around 12:15 local time (17:15 UTC), with recovery by roughly 05:01 local time (10:01 UTC) on March 5.
The second collapse occurred on March 16, when the entire national power system was disconnected. EnergíaMinas Cuba posted updates on X. Traffic from Cuba fell approximately 65% beginning around 13:35 local time (17:35 UTC) on March 16 and did not return to expected levels until about 20:00 local time on March 17 (00:00 UTC on March 18) — a disruption lasting over 30 hours.
The third collapse, the second in a week, struck on March 21–22. EnergíaMinas Cuba and OSDE/UNE again provided updates via X. Cloudflare Radar observed another significant traffic loss beginning around 18:30 local time (22:30 UTC) on March 21, falling as much as 77% compared to the previous week. Traffic recovered around 21:39 local time on March 22 (01:39 UTC on March 23).
Weather and infrastructure damage
Storm Kristin in Portugal
Storm Kristin made landfall in Portugal on January 28, causing widespread damage and power outages. Civil Protection registered approximately 1,500 incidents between midnight and 08:00 local time (00:00–08:00 UTC), with the districts of Leiria and Coimbra hardest hit. By 07:00 local time, over 850,000 E-Redes customers were without electricity.
Internet connectivity suffered accordingly. Cloudflare Radar observed traffic drops primarily in Leiria, Santarém, and Coimbra beginning around 04:10 local time (04:10 UTC) on January 28, with traffic falling as much as 70% in Leiria and 52% in Coimbra. Recovery was slow: more than 290,000 customers remained without power as late as January 30, and Cloudflare continued tracking gradual regional traffic recovery over the following weeks. Coimbra returned to expected levels within the first several days after the storm, but more than three weeks on, over 6,000 customers in Leiria reportedly still had no electricity.
Cable faults and technical outages
Republic of Congo
Just after the New Year, Internet connectivity in the Republic of Congo was disrupted by an incident on the WACS (West Africa Cable System) submarine cable. Congo Telecom (AS37451) posted on X announcing "an international incident on the WACS cable" and stated that backup solutions had been activated. Cloudflare Radar observed a significant drop in traffic from the country beginning around 00:00 local time on January 2 (23:00 UTC on January 1), falling to 82% below expected levels. A follow-up post from Congo Telecom confirmed that repairs were ongoing and that users might experience slowdowns during peak hours. Traffic returned to expected levels by approximately 15:00 local time (14:00 UTC) on January 4.
Verizon Wireless (United States)
A software issue on January 14 impacted voice and data services for Verizon Wireless (AS6167) customers across the United States. Verizon published an official statement acknowledging the outage started that day and had been resolved by 22:15 ET (03:15 UTC on January 15), with multiple updates from @VerizonNews on X throughout the evening. Cloudflare Radar data shows a minor traffic drop beginning around 12:30 ET (17:30 UTC) on January 14, consistent with the reported onset.
Grenada
Customers of Flow Grenada (AS46650), the primary Internet provider in Grenada, experienced an island-wide service disruption on February 9–10 lasting approximately 12 hours. The provider acknowledged the disruption on Facebook but gave no root cause. Cloudflare Radar data shows traffic from the network initially dropping around 11:30 local time (15:30 UTC) on February 9, disappearing completely around 20:00 local time (midnight UTC on February 10), and recovering by approximately 23:30 local time (03:30 UTC on February 10). Routing data shows a complete loss of announced IPv4 space at the same time traffic dropped to zero. Major spikes in BGP announcements around the time the disruption initially started, and bookending the complete outage, suggest that the whole event may have been routing-related.
January disruptions with unresolved causes
Two incidents in the first quarter of 2026 stand out for the lack of clarity surrounding their origins, even after services were restored.
In Guinea, Orange Guinée (AS37461) customers began reporting issues with phone calls and Internet access around 10:45 local time (10:45 UTC) on January 6. The operator later confirmed an "exceptional breakdown" caused by a technical incident, saying teams had been mobilized to fix it. Connectivity was back by approximately 14:00 local time (14:00 UTC) the same day, but the company never disclosed further specifics on what went wrong.
A similar situation played out in the UK on March 25 for TalkTalk (AS13285). The provider acknowledged a major service outage on X but offered no root cause. Cloudflare Radar data showed traffic from the ISP drop nearly 50% compared with the previous week, starting around 07:00 local time (07:00 UTC). Service was restored by approximately 08:15 local time (08:15 UTC), leaving the cause of the disruption unexplained.
A quarter of compounding pressure
The broader trend across Q1 2026 is the sheer scale and duration of connectivity failures. Government-ordered network shutdowns were a recurring theme, with Uganda and Iran experiencing prolonged blackouts that illustrate how Internet access is increasingly used as an instrument of political control.
Infrastructure vulnerability was just as visible elsewhere. Cuba saw three separate national grid collapses within a single month, each with direct consequences for connectivity across the island. Meanwhile, in the Middle East, drone strikes on AWS data centers marked a worrying first: active military conflict physically damaging major cloud infrastructure at scale, with severe knock-on effects for the websites and applications hosted on those systems.
The Cloudflare Radar team continues to monitor for these and other disruptions, publishing findings on the Cloudflare Radar Outage Center, via social media, and in posts on blog.cloudflare.com. Follow along on @CloudflareRadar (X), noc.social/@cloudflareradar (Mastodon), and radar.cloudflare.com (Bluesky), or reach the team via email.



