Cloudflare’s response to the invasion of Ukraine

Cloudflare has publicly detailed the steps it is taking in response to Russia’s invasion of Ukraine. Its actions span four areas: protecting Ukrainian institutions from cyberattacks, securing customer data, complying with international sanctions, and maintaining Internet services inside Russia.

Free protection for Ukrainian organizations

Cyberattacks against Ukrainian Internet infrastructure began before the invasion and have continued as a steady stream of DDoS attacks. In response, Cloudflare extended its services at no cost to Ukrainian government and telecommunications organizations so they can continue operating and delivering critical information to citizens and the wider world.

Under its Project Galileo program, Cloudflare is also expediting onboarding for any Ukrainian entity seeking the full suite of protections. More than sixty organizations in Ukraine and the region are currently receiving assistance, with roughly 25% of them joining during the current crisis. Many of the new organizations are groups coordinating refugee support, sharing vital information, or Ukrainian diaspora members in neighboring countries organizing aid. Any Ukrainian organization facing attack can apply for free protection at www.cloudflare.com/galileo, with review and approval expedited.

Protecting customer data in the conflict zone

To preserve the integrity of customer data, Cloudflare moved customer encryption key material out of its data centers in Ukraine, Russia, and Belarus. Services in those regions continue to operate using Keyless SSL technology, which allows encryption sessions to be terminated in a secure data center away from areas where compromise may be a risk.

If any Cloudflare facilities or servers in Ukraine, Belarus, or Russia lose power or Internet connectivity, they are configured to brick themselves. All data on disk is encrypted with keys that are not stored on site, and bricked machines cannot be booted without entering a secure, machine-specific key that is also not stored on site.

Cloudflare continues to monitor Internet patterns across Ukraine. Although usage has declined over the past ten days, the company says the Internet remains accessible in most locations and its services will continue to operate as long as connectivity out of the country exists.

Learning from attacks to protect all customers

The attacks on Ukrainian customers and telecoms are part of a broader cyber threat landscape. Governments worldwide have warned organizations to prepare for disruptive cyber activity; the US Cybersecurity and Infrastructure Security Agency (CISA) has recommended that all organizations go “Shields Up,” and the UK’s National Cyber Security Centre has encouraged organizations to improve their cyber resilience.

Cloudflare says careful monitoring of attacks in Ukraine benefits customers globally by informing product improvements. When wiper malware was identified in Ukraine, for example, the company adapted its Zero Trust products to protect customers. Cloudflare continues to offer free cybersecurity services and encourages organizations to take advantage of them during this heightened threat period.

Sanctions compliance and service in Russia

The unprecedented scope and frequency of new sanctions issued by multiple governments have required rapid compliance measures. Sanctions target Russia’s top financial institutions, the breakaway territories of Donetsk and Luhansk including their residents, state-owned enterprises, elite families, and leaders of intelligence-directed disinformation outlets.

Cloudflare says it has developed a comprehensive sanctions compliance program over the past several years, combining an internal compliance team, outside counsel, and third-party tools to flag potential matches or partial ownership by sanctioned parties. The company has also worked with government experts to identify connections between sanctioned entities and Cloudflare accounts.

As new sanctions were announced, Cloudflare has:

  • Closed off paid access to its network and systems in comprehensively-sanctioned regions
  • Terminated any customers tied to sanctions, including those related to Russian financial institutions, influence campaigns, and the Russian-affiliated Donetsk and Luhansk governments
  • Prevented the company from making any payments for taxes or fees to the Russian government, having never maintained offices or employees in Russia

Cloudflare expects additional sanctions and says it will continue to move quickly to comply with new requirements.

Why Cloudflare keeps services running in Russia

Cloudflare has received calls to terminate all of its services inside Russia. After consulting with government and civil society experts, the company concluded that Russia needs more Internet access, not less.

Since the conflict began, Cloudflare has observed a dramatic increase in requests from Russian networks to worldwide media, reflecting a desire by ordinary Russian citizens to access world news beyond what is provided within Russia. At the same time, there has been an increase in Russian blocking and throttling efforts, alongside a new “fake news” law aimed at controlling media content.

Cloudflare notes that the Russian government has threatened over the past several years to block certain Cloudflare services and customers. Indiscriminately terminating service would do little to harm the Russian government, but would limit access to information outside the country and make more vulnerable those who have used Cloudflare to shield themselves while criticizing the government.

The company believes the Russian government would welcome a Cloudflare shutdown in Russia. While it appreciates the spirit of requests from Ukrainians for tech companies to terminate services in Russia, Cloudflare maintains that shutting down its services entirely would be a mistake when what it fundamentally provides is a more open, private, and secure Internet.