Ten Months of War: What Ukraine’s Internet Traffic Reveals
When Russia invaded Ukraine on February 24, 2022, Cloudflare moved to shield Ukrainian government and civilian infrastructure from cyberattacks while keeping global traffic flowing. Nearly ten months later, the patterns of attack, outage, and recovery offer a detailed picture of how the Internet itself has become a battleground.
Attack Waves Against .ua
Ukrainian websites have faced sustained pressure since the invasion began. Application-layer firewall mitigations—blocking malicious HTTP requests such as L7 DDoS, vulnerability scanning, and brute-force login attempts—spiked sharply in March 2022 and again in mid-September. Compared with Q4 2021, the daily average percentage of mitigated requests on Ukrainian sites has risen significantly.

Nor have the assaults let up over time. While firewall mitigations have ebbed, DDoS spikes have continued through the autumn. On multiple occasions in September and October, DDoS traffic exceeded 80 percent of all traffic directed at sites on the .ua top-level domain.

Cloudflare's support program currently protects roughly 130 Ukrainian domains operated by more than 50 government agencies and companies. The nonprofit sector has also been a target. Since the invasion, 54 organizations in Ukraine have been onboarded to Project Galileo, Cloudflare's initiative providing free services to vulnerable nonprofits and human rights defenders. In total, Cloudflare protects 79 organizations inside Ukraine and 130 across the wider region, with 77 of those onboarded during the crisis.
Physical Threats Reshape Security Models
As Russian forces advanced, the physical safety of Internet infrastructure became as urgent as its digital defense. Data centers and companies in Ukraine had to plan for power outages, bombing damage, and the possibility that Russian troops might gain physical access to servers and offices. That reality forced new thinking about both security and data destruction.
Cloudflare configured its machines in the region to brick themselves if they lost power or connectivity, monitored local activity closely, and moved customer key material out of its Kyiv data centers. Services have continued operating in the region using Keyless SSL.
The conflict highlighted the value of defense architectures that extend beyond national borders. Ukrainian agencies and enterprises migrated data to public clouds across Europe to keep it safe from physical threats. Running on a global network meant attacks could be mitigated where they originated, rather than overwhelming infrastructure inside Ukraine.
Concerns about lateral movement in the event of a breach—and the need for reliable VPN access—also drove a surge in demand for zero-trust solutions. The ability to rapidly revoke access for personnel still in the region became a critical operational requirement.
Outages and Routing as Weapons
Internet shutdowns in contested areas have disrupted critical communications, making it harder for civilians to check on loved ones and for information about events on the ground to reach the outside world. Cloudflare has tracked dozens of outages since the invasion began, many stemming from power loss or Russian attacks, and continues to document them in the Cloudflare Radar Outages Center.
Some outages raise pointed questions. On September 1, 2022—the day International Atomic Energy Agency (IAEA) inspectors arrived at the Zaporizhzhia Nuclear Power Plant—Internet service went down for two local ISPs serving the area. Connectivity remained offline until September 10.


In occupied territories, Russian forces manipulated Internet access directly. In multiple instances, they took control of local telecoms, rerouting traffic through Russia or switching it entirely to a Russian ISP. Between May 1 and September 1, 2022, Cloudflare tracked more than 20 networks whose routing was changed to a Russian provider. Eleven of those networks had routes altered between May 29 and May 31, 2022, just as Ukraine announced its counteroffensive in Kherson. The effect was to subject the affected areas to the same controls, surveillance, and censorship as the Russian Internet, giving Moscow significant power over the local information environment.
Staying the Course
No one can say how long the war will last. What is clear is that the need for a secure, reliable Internet in Ukraine is as pressing as ever. The work of protecting critical services, hardening security for those operating in the region, and documenting what is happening to the Internet there continues.



