A quarter defined by fiber cuts and grid failures

Cloudflare Radar counted more than 180 Internet disruptions across 2025, with causes ranging from brief technical glitches to multi-day national blackouts. The fourth quarter was relatively quiet on the government-directed shutdown front — only one was recorded — but submarine cable faults and electrical grid failures dominated the period.

BLOG-3118 1

The following is a summary of confirmed and observed anomalies, not an exhaustive list of every issue that occurred. Detection is based on significant deviations from expected traffic patterns in Cloudflare's network; the Radar Outage Center maintains the full catalog of verified incidents.

The lone government-directed shutdown came on October 29, when Tanzania cut Internet access during violent protests tied to the presidential election. Traffic began falling around 12:30 local time (09:30 UTC) and dropped more than 90% below the previous week's levels. The outage lasted roughly 26 hours, with traffic returning around 14:30 local time (11:30 UTC) on October 30 — but that restoration held for only about two hours before another near-complete drop began at approximately 16:15 local time (13:15 UTC).

This second outage persisted until November 3, when traffic surged back after 17:00 local time (14:00 UTC). Announced IPv4 and IPv6 address space dipped during the shutdown, but the country never fully disconnected from the Internet, as routing announcements were never entirely withdrawn. Tanzania's president later expressed sympathy to diplomats and foreign residents affected by the shutdown. The country also restricted Internet and social media services ahead of its 2020 general elections.

Submarine cable cuts hit multiple markets

Digicel Haiti: two fiber cuts in six weeks

Digicel Haiti (AS27653) saw two separate cable-cut incidents during the quarter. On October 16, traffic began dropping at 14:30 local time (18:30 UTC), reaching near zero by 16:00 local time (20:00 UTC). The company's Director General posted on X that two cuts had occurred on its international fiber optic infrastructure. Traffic started recovering after 17:00 local time (21:00 UTC), and a follow-up post confirmed the first fiber had been repaired and service restored.

A second incident on November 25 involved a cut to the provider's international optical fiber on National Road 1. Traffic had begun dropping about an hour before the company's public notice, with a complete outage observed between 02:00 and 08:00 local time (07:00-13:00 UTC). All services were reported restored by 08:22 local time (13:22 UTC).

PEACE cable damage in Pakistan

On October 20 at 17:30 local time (12:30 UTC), Cybernet/StormFiber (AS9541) traffic dropped sharply to roughly 50% of the prior week's level, with announced IPv4 address space falling by more than a third. The cause was a cut to the PEACE submarine cable in the Red Sea near Sudan. PEACE is one of several cable systems, including IMEWE and SEA-ME-WE-4, carrying international traffic for Pakistani providers.

The provider pledged full restoration by October 27, but traffic and announced IPv4 address space had already recovered to near-expected levels by around 02:00 local time on October 21 (21:00 UTC on October 20).

WACS incident disrupts West and Central Africa

Multiple Cameroonian providers — Camtel, MTN Cameroon, and Orange Cameroun — saw unusual traffic patterns on October 23, reportedly due to problems on the WACS (West Africa Cable System) submarine cable linking West Africa to Portugal. MTN told subscribers that service was temporarily disrupted following an incident on the WACS fiber, while Orange cited an incident on the international access fiber. Camtel publicly stated that a technical incident involving WACS cable equipment in Batoke (Limbe) occurred in the early hours of October 23, causing nationwide connectivity disruptions.

Traffic across the affected providers began falling around 05:00 local time (04:00 UTC) and recovered to expected levels around 22:00 local time (21:00 UTC), though it was highly volatile during the day, dropping 90-99% at times. The spikiness may reflect attempts to shift traffic to other submarine cable systems serving Cameroon. Announced IP address space from MTN Cameroon and Orange Cameroon also dropped during this window, while Camtel's did not change. The Central African Republic and Republic of Congo also reported connectivity impacts from the WACS issues.

Claro Dominicana fiber outages

Traffic from Claro Dominicana (AS6400) in the Dominican Republic dropped sharply around 12:15 local time (16:15 UTC) on December 9, fell again around 14:15 local time (18:15 UTC), and bottomed out 77% below the previous week's level before recovering quickly. The provider attributed the disruption to two fiber optic outages causing "intermittency and slowness in some services." A subsequent post confirmed technicians had restored nationwide Internet service by repairing the severed cables.

Nationwide blackouts ripple into connectivity

Dominican Republic grid collapse

A transmission line outage caused an electrical service interruption across the Dominican Republic on November 11, according to Empresa de Transmisión Eléctrica Dominicana (ETED). The power loss cut national Internet traffic by nearly 50% compared to the prior week, starting at 13:15 local time (17:15 UTC). Traffic stayed depressed until approximately 02:00 local time (06:00 UTC) on December 12, when ETED reported completing recovery of the national electrical system and supplying 96% of demand.

A subsequent technical report found the blackout began at the 138 kV San Pedro de Macorís I substation, where a live line was manually disconnected, triggering a high-intensity short circuit. Protection systems responded, but several nearby lines disconnected, separating 575 MW of generation in the eastern region from the rest of the grid. The imbalance caused major power plants to trip automatically as part of their built-in safety mechanisms.

Kenya regional power outage

A major power outage struck multiple regions across Kenya on December 9. Kenya Power said the outage was "triggered by an incident on the regional Kenya-Uganda interconnected power network, which caused a disturbance on the Kenyan side of the system" and claimed most affected areas had power restored within about 30 minutes. Internet connectivity impacts, however, lasted nearly four hours, between 19:15 and 23:00 local time (16:15-20:00 UTC). National traffic dropped as much as 18%, with the shifts most visible in Nakuru County and Kaimbu County.

Drone strikes disrupt Odesa connectivity

Russian drone strikes on Ukraine's Odesa region on December 12 damaged warehouses and energy infrastructure, causing power outages in parts of the region. Those outages disrupted Internet connectivity, with traffic dropping by as much as 57% compared to the prior week. The initial drop occurred at midnight on December 13 (22:00 UTC on December 12), and traffic recovered gradually over the following several days, returning to expected levels around 14:30 local time (12:30 UTC) on December 16.

Weather-driven outages

Jamaica

Hurricane Melissa made landfall in Jamaica on October 28, bringing power outages and infrastructure damage that cut Internet traffic sharply. Connectivity began dropping around 06:15 local time (11:15 UTC), with traffic ultimately falling to about 70% below the previous week's levels. Recovery was slow: traffic stayed well under normal levels for days and only began making meaningful progress toward expected levels on the morning of November 4. The lag is typical after major storms, since power restoration often happens within days but physical network infrastructure repairs take considerably longer.

Sri Lanka and Indonesia

Cyclone Senyar struck Sri Lanka and Indonesia on November 26, causing catastrophic floods and landslides that killed over 1,000 people and damaged telecommunications and power infrastructure. The damage disrupted Internet connectivity across multiple regions in both countries.

In Sri Lanka, provinces outside the main Western Province were hit hardest. Traffic in North Western, Southern, Uva, Eastern, Northern, North Central, and Sabaragamuwa provinces dropped between 80% and 95% compared with the prior week.

In Indonesia, Aceh and the Sumatra regions saw the largest disruptions. Aceh's traffic initially fell more than 75% week over week. Among Sumatra's provinces, North Sumatra was the most affected, with an early drop of 30% compared with the prior week before recovering more actively the following week.

Technical failures and outages

Smartfren (Indonesia)

Subscribers of Indonesian provider Smartfren (AS18004) experienced a service disruption on October 3. The company acknowledged the issue in an X post, saying (in translation): “Currently, telephone, SMS and data services are experiencing problems in several areas.” Traffic fell as much as 84% starting around 09:00 local time (02:00 UTC) and returned to expected levels roughly eight hours later, around 17:00 local time (10:00 UTC). Smartfren did not disclose what caused the problems.

Vodafone UK

Vodafone UK (AS5378 and AS25135) suffered a brief outage on October 23. At 15:00 local time (14:00 UTC), traffic on both ASNs dropped to zero. Announced IPv4 address space from AS5378 fell by 75%, while announced IPv4 address space from AS25135 disappeared entirely. Traffic and address space both recovered about two hours later, returning to expected levels around 17:00 local time (16:00 UTC). Vodafone did not comment on the cause on social media, and its network status checker page was also unavailable during the outage.

Fastweb (Italy)

A DNS resolution issue disrupted Internet services for customers of Italian provider Fastweb (AS12874) on October 22, according to a published report. Observed traffic volumes dropped by over 75%. Fastweb acknowledged the issue, which affected wired Internet customers between 09:30 and 13:00 local time (08:30 to 12:00 UTC).

DNS resolution failures are not connectivity outages, but their effect on Internet traffic is very similar. When a provider's DNS resolver has problems, switching to a public resolver such as Cloudflare's 1.1.1.1 often restores connectivity.

SBIN, MTN Benin, Etisalat Benin

On December 7, traffic dropped concurrently across three Beninese networks: SBIN (AS28683), MTN Benin (AS37424), and Etisalat Benin (AS37136). Between 18:30 and 19:30 local time (17:30 to 18:30 UTC), country-level traffic fell as much as 80% compared with the prior week, with drops of nearly 100% at Etisalat and MTN and over 80% at SBIN.

An attempted coup had occurred earlier in the day, but it is unclear whether the Internet disruption was related. All three affected networks share Cogent (AS174) as an upstream provider, so a localized issue at Cogent may have contributed to the brief outage.

Cellcom Israel

Israeli provider Cellcom (AS1680) announced on December 18 that “a malfunction affecting Internet connectivity is impacting some of our customers.” Traffic dropped nearly 70% compared with the prior week between 09:30 and 11:00 local time (07:30 to 09:00 UTC). A published report suggested the malfunction may have been a DNS failure.

Partner Communications (Israel)

On December 30, a major technical failure at Israeli provider Partner Communications (AS12400) disrupted mobile, TV, and Internet services across the country. Internet traffic fell by two-thirds compared with the previous week between 14:00 and 15:00 local time (12:00 to 13:00 UTC). During the outage, queries to Cloudflare's 1.1.1.1 public DNS resolver spiked, suggesting the problem may have been related to Partner's DNS infrastructure. The provider did not publicly confirm the cause.

Tracking Cloud Platform Disruptions

Cloudflare Radar added a new Cloud Observatory page in the fourth quarter, providing region-level visibility into the availability and performance of major hyperscalers: Amazon Web Services, Microsoft Azure, Google Cloud Platform, and Oracle Cloud Infrastructure.

AWS us-east-1

On October 20, AWS us-east-1 in Northern Virginia reported increased error rates and latencies affecting multiple services. This impacted public-facing sites and applications hosted in the region, as well as Cloudflare customers relying on origins there.

Cloudflare observed the first signs around 06:30 UTC as the share of 5xx-class responses climbed, peaking at about 17% around 08:00 UTC. Connection failures to origins in the region later topped out near 12:00 UTC.

Network performance metrics remained degraded through the incident. Both TCP and TLS handshake durations worsened progressively, and the time to receive response headers from origin servers increased significantly in the first hours before recovering. Metrics returned to normal around 23:00 UTC.

Microsoft Azure Front Door

On October 29, an incident struck Azure Front Door. Azure attributed the cause to "a specific sequence of customer configuration changes, performed across two different control plane build versions," which generated incompatible metadata. When deployed to edge servers, this exposed a latent bug that triggered crashes during asynchronous processing in the data plane.

Azure logged the start at 15:41 UTC, but Cloudflare data shows failed connection attempts rising about 45 minutes earlier. Handshake metrics became volatile during the period, with TCP handshakes taking over 50% longer at times and TLS handshakes nearly 200% longer at peak. Conditions improved after 20:00 UTC, with Microsoft marking the end at 00:05 UTC on October 30.

Cloudflare’s Own Q4 Incidents

Cloudflare itself faced two disruptions in the quarter. Though not internet-wide outages, they briefly blocked access to sites and applications delivered through Cloudflare.

  • November 18: A change to database permissions caused the database to write multiple entries into a "feature file" used by the Bot Management system, triggering a software failure. Full details are in the post-mortem.
  • December 5: Changes to request body parsing logic—made to detect a newly disclosed React Server Components vulnerability—affected a subset of customers serving roughly 28% of all HTTP traffic on the platform. The incident report includes a root cause analysis and timeline.

Cloudflare has outlined its resilience strategy under the "Code Orange: Fail Small" initiative, aimed at preventing recurrence of such incidents.

Observations and Data Access

The quarter’s outages—from government-ordered shutdowns to configuration-driven failures—reinforce the need for real-time telemetry. Cloudflare continues to publish these observations via the Radar Outage Center, social media, and blog.cloudflare.com.

Readers can dig into the underlying data directly: it is available through the Cloudflare Radar API, and the Radar MCP server allows integration of Radar data into AI tools for local analysis and monitoring.