Cloudflare · OFFICIAL ARTICLE

自然灾害与政府干预:剖析 2026 年第二季度重大互联网中断事件

Cloudflare Radar 追踪了过去一个季度由自然灾害、政府强制关停以及 DNSSEC 密钥轮换引发的互联网中断。本文通过流量遥测数据,分析这些事件如何影响全球连通性。

来源:Cloudflare
ORIGINAL · 官方原文

Natural disasters and government interference: examining Q2 2026’s major Internet disruption events

详细说明

Blog AWS Internet Shutdown Internet Traffic +3 Show 3 more tags

6 Tags Show 6 tags

Internet Trends Outage Radar

AWS Internet Shutdown Internet Traffic Internet Trends Outage Radar

July 28, 2026

  • Selected Tags
  • AWS Internet Shutdown Internet Traffic Internet Trends Outage Radar
  • All tags
  • Matching tags
  • No tags found
  • 1.1.1.1
  • 2FA
  • Abuse
  • Access
  • Access Control Lists (ACLs)
  • Accessibility
  • Account Takeover
  • Acquisitions
  • Addressing
  • Advanced Certificate Manager
  • Advanced DDoS
  • Advertising
  • Aegis
  • Africa
  • Afroflare
  • Agent Readiness
  • Agents
  • Agents Week
  • AI
  • AI Bots
  • AI Gateway
  • AI Search
  • AI-SPM
  • AI WAF
  • AI Week
  • Alertmanager
  • Always Online
  • AMD
  • AMP
  • Analytics
  • Anonymous
  • Anti Malware
  • Anycast
  • API
  • API Gateway
  • API Security
  • API Shield
  • APJC
  • Apple
  • Application Security
  • Application Services
  • Area 1 Security
  • Argo Smart Routing
  • ASCII
  • Asia
  • Athenian Project
  • Atlassian
  • Attacks
  • Audit Logs
  • Austin
  • Australia
  • Authentication
  • Authy
  • Automatic HTTPS
  • Automatic Platform Optimization
  • Automation
  • AutoMinify
  • Auto Rag
  • Awards
  • AWS
  • Baidu
  • Bandwidth Alliance
  • Bandwidth Costs
  • Best Practices
  • Beta
  • Better Internet
  • BGP
  • Birthday Week
  • Blackbird
  • Black Friday
  • Bot Fight Mode
  • Bot Management
  • Botnet
  • Bots
  • BPF
  • Brand
  • Brand Protection
  • Brazil
  • Browser Insights
  • Browser Rendering
  • Browser Run
  • Bug Bounty
  • Bugs
  • BYOIP
  • Cache
  • Cache Purge
  • Cache Reserve
  • Cache Rules
  • California
  • Canada
  • Cap'n Proto
  • CAPTCHA
  • Careers
  • CASB
  • Categories
  • CDN
  • CDNJS
  • Certificate Authority
  • Certificate Pinning
  • Certificate Transparency
  • Certification
  • CFSSL
  • Challenge Page
  • ChatGPT
  • China
  • China Network
  • Christmas
  • Chrome
  • CIO Week
  • CISA
  • Claire
  • CLI
  • ClickHouse
  • Clientless
  • Clientless Web Isolation
  • Cloud Connector
  • Cloud Email Security
  • Cloudflare Access
  • Cloudflare Apps
  • Cloudflare Area 1
  • Cloudflare Calls
  • Cloudflare Email Service
  • Cloudflare for Campaigns
  • Cloudflare for SaaS
  • Cloudflare for Startups
  • Cloudflare Gateway
  • Cloudflare History
  • Cloudflare Images
  • Cloudflare Media Platform
  • Cloudflare Meetups
  • Cloudflare Network
  • Cloudflare One
  • Cloudflare One Client
  • Cloudflare One User Risk Score
  • Cloudflare One Week
  • Cloudflare Pages
  • Cloudflare Polish
  • Cloudflare Queues
  • Cloudflare Realtime
  • Cloudflare Stream
  • Cloudflare Tunnel
  • Cloudflare TV
  • Cloudflare Workers
  • Cloudflare Workers KV
  • Cloudflare Workers KV (ES)
  • Cloudflare Workers (PT)
  • Cloudflare Zero Trust
  • Cloudforce One
  • Cloudy
  • Code Orange
  • Coinbase
  • Colombia
  • Community
  • Compliance
  • Compression
  • Config Rules
  • Configuration Management
  • Congestion Control
  • Connectivity
  • Connectivity Cloud
  • Consumer Services
  • Containers
  • Content Independence Day
  • Content Scanning
  • Context
  • Core
  • COVID-19
  • Crawler Hints
  • CrowdStrike
  • Cryptography
  • Crypto Week
  • CSAM Reporting
  • Customers
  • Customer Success
  • Customer Zero
  • CVE
  • CVE-2023-50387
  • Cyber Readiness
  • Cybersecurity
  • D1
  • Dashboard
  • Data
  • Database
  • Data Catalog
  • Data Center
  • Data Localization
  • Data Localization Suite
  • Data Loss
  • Data Loss Prevention
  • Data Platform
  • Data Privacy Day
  • Data Protection
  • Data Sovereignty
  • Data Transfer Bucket
  • DDoS
  • DDoS Alerts
  • DDoS Reports
  • Debugging
  • Deep Dive
  • Descaler
  • Design
  • Deskope
  • Developer Documentation
  • Developer Platform
  • Developers
  • Developer Spotlight
  • Developers Storage
  • Developer Week
  • Device Security
  • DevOps
  • DEX
  • Digital Experience Monitoring
  • Digital Forensics
  • Disrupt
  • Distributed
  • Distributed Systems
  • Distributed Web
  • Diversity
  • DLP
  • DMARC
  • DNS
  • DNS Filtering
  • DNS Flood
  • DNSSEC
  • DNS Security
  • Dogfooding
  • DoH
  • Domain Rankings
  • Domain Scoped Roles
  • dosd
  • Drupal
  • Due Process
  • Durable Execution
  • Durable Objects
  • Early Hints
  • Earth Day
  • eBPF
  • EC2
  • eCommerce
  • Edge
  • Edge Computing
  • Edge Database
  • Edge Rules
  • Education
  • Egress
  • Elastic
  • Elections
  • Election Security
  • Elliptic Curves
  • Email
  • Email Routing
  • Email Security
  • Email Workers
  • EmDash
  • Emissions
  • Employee Resource Groups
  • Encrypted SNI
  • Encryption
  • Engineering
  • Enterprise
  • Entropy
  • EPYC
  • Ethereum
  • Europe
  • European Union
  • Events
  • Exploit
  • Facebook
  • Fancy Bear
  • Fast Fonts
  • FCC
  • Feature Flags
  • FedRAMP
  • FedRAMP High
  • FedRAMP Moderate
  • Firefox
  • Firewall
  • Firmware
  • Florida
  • Football
  • Formal Methods
  • Forrester
  • Fortran
  • Foundation DNS
  • Founders' Letter
  • France
  • Fraud
  • Free
  • Freedom of Speech
  • Front End
  • Full Stack
  • Full Stack Week
  • Fun
  • Gartner
  • Gatebot
  • GA Week
  • GDPR
  • General Availability
  • Generative AI
  • Gen X
  • Geo Key Manager
  • Germany
  • GitHub
  • Go
  • Google
  • Google Analytics
  • Google Cloud
  • Google Workspace
  • Government Innovation
  • Grace Hopper
  • Grafana
  • GraphQL
  • Green
  • Grinch
  • Growth
  • gRPC
  • Guest Post
  • Hackathon
  • Halloween
  • Hardware
  • HashiCorp
  • Hertzbleed
  • Heuristics
  • History
  • Holidays
  • Holocaust
  • Hong Kong
  • Hosting Con
  • Hostnames
  • HTTP2
  • HTTP3
  • HTTPS
  • Human Rights
  • Hurricane
  • Hybrid Cloud
  • Hyperdrive
  • IBM
  • ICANN
  • iCloud Private Relay
  • Identity
  • IETF
  • IL4
  • Image Optimization
  • Image Recognition
  • Image Resizing
  • Image Storage
  • Impact
  • Impact Week
  • I'm Under Attack Mode
  • Incident Report
  • Incident Response
  • India
  • Indicators of Compromise
  • Indonesian
  • Infrastructure
  • Infrastructure as Code
  • Insights
  • Intel
  • Interconnection
  • Internal DNS
  • Internet Performance
  • Internet Quality
  • Internet Regulation
  • Internet Shutdown
  • Internet Summit
  • Internet Traffic
  • Internet Trends
  • Internship Experience
  • Intrusion Detection
  • Investors
  • IoCs
  • iOS
  • IoT
  • IPFS
  • IPsec
  • IPv4
  • IPv6
  • IRAP
  • Israel
  • Italy
  • IWD
  • JAMstack
  • Japan
  • JavaScript
  • Jengo
  • Jengo Policy
  • Joomla
  • Judeoflare
  • Kafka
  • Kernel
  • Keyless SSL
  • KeyTrap
  • Key Value
  • Killnet
  • Korea
  • Kubernetes
  • LangChain
  • Latency
  • Latin America
  • Latinflare
  • LavaRand
  • Lazarus group
  • Leaked Credential Checks
  • Legal
  • Legal Patents Sable
  • LGBTQIA+
  • Life at Cloudflare
  • Linux
  • Lisbon
  • Live Streaming
  • Llama
  • LLM
  • Load Balancing
  • Localization
  • Log4J
  • Log4Shell
  • Logging
  • Log Push
  • Logs
  • LUA
  • Machine Learning
  • Magecart
  • Magic Firewall
  • Magic Network Monitoring
  • Magic Transit
  • Magic WAN
  • Magic WAN Connector
  • Malicious JavaScript
  • Malware
  • Managed Components
  • Managed Rules
  • March of Cloudflare
  • MASQUE
  • MCP
  • Meerkat
  • MeetUp
  • Meris
  • Message Protocol
  • Mexico
  • Micro-frontends
  • Microsoft
  • Microsoft 365
  • Microsoft Azure
  • Middle East
  • Migration Hub
  • Milestones
  • Miniflare
  • Mirage
  • Mirai
  • Mitel
  • Mitigation
  • Mixed Content Errors
  • MLops
  • Mobile
  • Mobile SDK
  • Model Context Protocol
  • Moldova
  • Monitoring
  • Multi-Cloud
  • Multi-User
  • MySQL
  • NaaS
  • Net Neutrality
  • Network
  • Networking
  • Network Interconnect
  • Network Performance Update
  • Network Protection
  • Network Services
  • New Year
  • NGINX
  • Ninjas
  • NIST
  • Node.js
  • North America
  • Notebooks
  • Notifications
  • NSEC3
  • OAuth
  • Observability
  • Oceania
  • OCSP
  • Offices
  • Okta
  • Olympics
  • Onboarding
  • OpenAI
  • Open API
  • OpenBMC
  • OpenDNS
  • Open Source
  • OpenSSL
  • OpenTelemetry
  • Optimization
  • Origin Rules
  • Outage
  • Oxy
  • Pacific Northwest
  • Page Rules
  • Page Shield
  • Parallels
  • Partners
  • Partnership
  • Password-reuse
  • Passwords
  • Passwords (PT)
  • Patents
  • PAYGO
  • Payments
  • Pay Per Crawl
  • PCI Certified
  • Peering
  • Performance
  • Phishing
  • php
  • Phython
  • Pingora
  • Pipelines
  • PlanetScale
  • Plans
  • Platform Engineering
  • Platform Week
  • Plesk
  • Policy & Legal
  • Politics
  • Portugal
  • Postgres
  • Post Mortem
  • Post-Quantum
  • Precursor
  • Prepared Statements
  • Prisma
  • Privacy
  • Privacy Pass
  • Privacy Week
  • Private IP
  • Private Network
  • Product Design
  • Product News
  • Programming
  • Programming (PT)
  • Project Fair Shot
  • Project Galileo
  • Project Honey Pot
  • Project Pangea
  • Project Safekeeping
  • Project Turpentine
  • Prometheus
  • Protocols
  • Proudflare
  • Proxying
  • Public Sector
  • Python
  • Queues
  • QUIC
  • QUICHE
  • Quicksilver
  • R2
  • R2 Super Slurper
  • Radar
  • Radar Alerts
  • Radar API
  • Radar Maps
  • Railgun
  • Randomness
  • Ransom Attacks
  • Rapid Reset
  • Raspberry Pi
  • Rate Limiting
  • RC4
  • RDDoS
  • React
  • Reading List
  • Real-time
  • Recruiting
  • Regional Services
  • Registrar
  • Reliability
  • Remote Browser Isolation
  • Remote Desktop Protocol
  • Remote Work
  • Replication
  • Research
  • Resolver
  • Restreaming
  • Retreat
  • Reverse Engineering
  • REvil
  • Risk Management
  • Road to Zero Trust
  • Rocket Loader
  • RocksDB
  • Routing
  • Routing Security
  • RPKI
  • RRDNS
  • RSA
  • Russia
  • Rust
  • Rust Workers
  • SaaS
  • SAAS Security
  • Sable
  • Salt
  • Sampling
  • Sandbox
  • SASE
  • Save The Web
  • SDK
  • Search Engine
  • Secrets Store
  • Secure Web Gateway
  • Security
  • Security Analytics
  • Security Center
  • Security Posture
  • Security Posture Management
  • Security Service Edge
  • security.txt
  • Security Week
  • SEO
  • Serverless
  • Serverless AI
  • Serverless (PT)
  • Serverless Week
  • Server Push
  • Servers
  • SIEM
  • Signed Exchanges (SXG)
  • SIM
  • Singapore
  • Single Sign On (SSO)
  • Smart Placement
  • Smart Shield
  • Snippets
  • SOC as a Service
  • South Africa
  • South America
  • Spain
  • spdy
  • Spectrum
  • Speed
  • Speed Brain
  • Speed & Reliability
  • Speed Week
  • Spoofing
  • Sports
  • SQL
  • SRE
  • SSE
  • SSH
  • SSL
  • Standards
  • Startup Enterprise Plan
  • Statistics
  • StopTheHacker
  • Storage
  • Sumo Logic
  • Super Bowl
  • Supercloud
  • Supply Chain Attacks
  • Support
  • Sustainability
  • SWAG
  • SWG
  • Swift
  • Switzerland
  • SXSW
  • SYN
  • SYN Flood
  • Syria
  • TCP
  • Team
  • Teams Dashboard
  • TechCrunch
  • Technical Writing
  • Tech Talks
  • Terraform
  • Testimonials
  • Testing
  • Texas
  • Thanksgiving
  • The Serverlist Newsletter
  • Threat Data
  • Threat Feeds
  • Threat Intelligence
  • Threat Operations
  • Threats
  • Tiered Cache
  • TikTok
  • TLS
  • TLS 1.3
  • Tools
  • Tor
  • Tracing
  • Traffic
  • Transform Rules
  • Transparency
  • Trends
  • Trust & Safety
  • TTFB
  • TTL
  • TURN
  • TURN Server
  • Turnstile
  • TypeScript
  • UDP
  • Ukraine
  • United Kingdom
  • Universal SSL
  • URL Scanner
  • USA
  • User Research
  • VDI
  • Vectorize
  • Vetflare
  • Video
  • Visibility
  • Vite
  • VoIP
  • VPC
  • VPN
  • Vulnerabilities
  • WAF
  • WAF Attack Score
  • WAF Rules
  • Waiting Room
  • WARP
  • WARP Connector
  • WASM
  • Web3
  • Web Application Firewall
  • WebAssembly
  • Web Asset Discovery
  • Webinars
  • WebP
  • WebRTC
  • WebSockets
  • Wildebeest
  • Womenflare
  • WordPress
  • Workers AI
  • Workers Launchpad
  • Workers Logs
  • Workers Observability
  • Workers Sites
  • Workers Unbound
  • Workers VPC
  • Workflows
  • World IPv6 Day
  • Wrangler
  • x402
  • Year in Review
  • Z3
  • Zaraz
  • Zero Day Threats
  • Zero Trust
  • Zero Trust Week
  • Zone Versioning

Natural disasters and government interference: examining Q2 2026’s major Internet disruption events

Lai Yi Ohlsen

8 minute read

COPY URL

Like most infrastructure, the Internet's fragility is easy to overlook — as long as it's working. When it fails, its complexity comes into full view. Cloudflare is in a unique position to detect and document the moments when one of the interrelated systems the Internet depends on breaks down and connectivity suffers as a result. Each quarter, we summarize the disruptions we detect and annotate on Cloudflare Radar .

In Q2 2026, Super Typhoon Sinlaku just north of Guam caused the longest outage, while government-mandated shutdowns during exam periods in Sudan were the most frequent. Iran restored national Internet access, reconnecting its citizens to the global network after an 88-day blackout, even as damage from drone strikes continued to disrupt AWS infrastructure elsewhere in the region. Finally, a cable cut in Saint Lucia and the distribution of faulty DNSSEC signatures in Germany underscored the fragility of Internet infrastructure, but also the remarkable stability these regional and global systems maintain when operating normally.

Here we will walk through the most significant Internet disruptions we observed in the second quarter of 2026, drawing on traffic data from Cloudflare Radar to show how each unfolded and what it meant for users on the ground. As always, this is a summary of notable, confirmed disruptions rather than an exhaustive list; a fuller view of detected traffic anomalies is available in the Cloudflare Radar Outage Center .

Natural disasters and electricity cause disruptions in Guam, Venezuela, and Tanzania

Super Typhoon Sinlaku, the strongest storm of the 2026 Pacific typhoon season so far, tracked through the Mariana Islands in mid-April, passing just north of Guam. Though the island was spared a direct hit, the storm brought tropical-storm-force winds, knocking out power across Guam and disrupting water systems, which had a direct impact on Internet connectivity. Traffic from the territory fell as much as 80% below expected levels from April 13 to 14.

Two months later, on June 24, two major earthquakes struck northern Venezuela within about a minute of each other, in Yumare and San Felipe, followed by an aftershock near the coast outside of Caracas. The first 7.5 magnitude earthquake took place at roughly 22:04 UTC (18:04 local time). The immediate impact of these events can be seen in Radar, which shows a sharp decrease in both HTTP bytes transferred at the same time as the earthquakes. This decrease can be seen particularly well in Fibex Telecom, which, according to APNIC data , has 1.6 million estimated users. The drop is also visible for CANTV , the state-owned incumbent, and VNET , a slightly smaller regional ISP.

Across the Atlantic just a few days later, a power outage in Tanzania on June 27 caused a sharp drop in HTTP traffic there that lasted for at least five hours. While distinct in cause from the country's election-related blackout in October 2025 (a deliberate government action rather than an infrastructure failure) the resulting telemetry and user impact were nearly identical: a drastic loss of connectivity that left residents unable to communicate with loved ones or access critical news.

It is striking how such fundamentally different events leave such similar footprints in the data and user experience. Taken together, these weather-related and power-driven disruptions demonstrate the immense impact the physical world can have on the digital, and the importance of Internet resilience and of building networks with enough redundancy in power, routing, and physical paths to withstand inevitable shocks.

Governments and geopolitics impact connectivity in Iran, UAE, Iraq and Sudan

Starting on May 26, Radar began seeing signs of Iran's previously announced Internet restoration, the tentative end of an 88-day shutdown that had left the country almost entirely offline since it began on February

Meanwhile, HTTP traffic to me-central-1, an AWS cloud region located in the United Arab Emirates, has remained low , aligning with AWS service reports on April 30 that the region "has suffered damage as a result of the conflict in the Middle East and is currently unable to reliably support customer applications." This update follows the reports on March 3 that facilities in both UAE and Bahrain “have experienced physical impacts to infrastructure as a result of drone strikes.” In the UAE, two facilities were “directly struck” and in Bahrain a drone strike near the facility caused “physical impact” to their infrastructure. The decreased traffic is the downstream signature of physical damage to the underlying data center infrastructure rather than a network fault, and it continues to affect the websites and applications hosted in that region, regardless of their own availability.

The second quarter of 2026 also included three government-mandated shutdowns in Iraq (on June 2 , June 11 , and June 28 ) as well as 10 in Sudan between April 13 and 23, all of which were imposed to prevent cheating on national exams — a seasonal pattern we have documented across multiple prior quarters in both countries. The outages in Sudan followed a consistent rhythm, each lasting approximately 3.5 hours from 11:45 to 15:15 UTC (13:45 to 17:15 local time), timed to the exam window. In Iraq the outages were shorter, lasting about 90 minutes each, and likewise scheduled around the hours in which exams were administered.

Each of these examples, whether a restoration or a disruption, illustrates the significant control governments exert over their national connectivity, and the ease with which access can be switched off, throttled, or selectively reintroduced as a matter of policy rather than infrastructure.

  • On May 27, Radar reported that traffic had been restored to 40% of its pre-outage levels, a partial reopening consistent with reports that access was being reintroduced selectively rather than all at once. Since then, we have seen HTTP bytes climb to as high as 90% before settling back to roughly 59% of pre-shutdown levels. This volume is consistent with the traffic we observed in February, a window between this recent shutdown and a previous one in January, suggesting that connectivity has returned to something like its most recent pre-shutdown baseline rather than fully normalizing. In our 2026 World Cup analysis , Iran stood out as a solo outlier: While traffic in most participating countries rose and fell with match schedules, Iran's readings were dominated instead by the contrast between its post-restoration levels and the near-complete loss of connectivity that had preceded them.

Infrastructure vulnerabilities affect users in Germany and Saint Lucia

On May 5, a DNSSEC key rollover at DENIC, the registry for Germany's .de domain, started producing invalid signatures . These key rollovers are the periodic replacement of the cryptographic keys used to sign a zone's DNS records; they are a routine but crucial piece of maintenance, as resolvers that validate DNSSEC will only trust answers whose signatures match the current published keys. In other words, if the digital signatures don't match expected values, the resolver assumes the site has been tampered with and cuts off access. When invalid signatures started being produced, validating resolvers worldwide rejected every request for a .de website and returned SERVFAIL errors until normal operation was restored at 23:15 UTC (01:15 local time on May 6).

Cloudflare Radar observed worldwide .de query volume rise during the outage. While perhaps initially counterintuitive, this is because failed answers are effectively uncacheable, so lookups normally served silently from cache instead had to be re-resolved and retried repeatedly, causing a sharp increase in queries.

From a user's perspective, the incident was experienced not as a DNS or cryptographic failure but simply as a wave of .de websites and services suddenly becoming unreachable. Though users were still able to access sites that did not use the .de TLD, the experience included pages failing to load, email bouncing, and apps timing out, all of which can mirror the experience of an outage. You can read more about DNSSEC and the impact of the events on our blog .

In the Caribbean, an infrastructure failure caused a similar drop in availability. On June 21, HTTP request traffic from Karib Cable’s network fell to essentially zero by around 21:00 UTC (17:00 local time), and remained flat for the better part of a day before recovering to expected levels around 17:00 UTC on June 22 (13:00 local time). The outage was reportedly caused by a fiber cut near the island, a familiar hazard for Caribbean networks that depend on a few terrestrial and submarine paths to reach the wider Internet, meaning a single break can sever a disproportionate amount of capacity. Because Karib Cable is one of the largest providers, the loss was also visible at the country level, with Saint Lucia's overall traffic dropping approximately 60% against the prior week for the duration of the cut.

Radar continues to monitor disruptions

The second quarter of 2026 saw Internet disruptions arise from a wide range of causes, including severe weather, an earthquake, power outages, government-directed shutdowns, damage to cloud infrastructure, cable cuts, and a DNSSEC misconfiguration. As these events demonstrate, the Internet depends on a complex set of interrelated systems, and a failure in any one of them can result in a loss of connectivity.

The Cloudflare Radar team is constantly monitoring for Internet disruptions, sharing our observations on the Cloudflare Radar Outage Center , via social media, and in posts on blog.cloudflare.com . Follow us on social media at @CloudflareRadar (X), noc.social/@cloudflareradar (Mastodon), and radar.cloudflare.com (Bluesky).

Related tags

AWS Internet Shutdown Internet Traffic Internet Trends Outage Radar

Follow on Social Media

  • Cloudflare