Cloudflare's Q2 outage data traces connectivity failure from Guam's typhoon to a broken German signing key

Cloudflare's Q2 2026 Internet Disruptions Report, issued on Monday, recorded the quarter's longest single outage in Guam, where Super Typhoon Sinlaku pushed traffic as much as 80% below expected levels across 13 and 14 April, and its most frequent in Sudan, where 10 government-mandated shutdowns between 13 and 23 April each ran for approximately 3.5 hours in a window timed to national examinations. Sudan and Iraq together imposed 13 examination-related shutdowns over the three months. The quarter also closed one of the longest national blackouts on record, with Iran beginning a selective restoration on 26 May after 88 days offline.

The spread of causes is the substantive finding for anyone running distributed infrastructure. Weather, seismic activity, electricity supply, state policy, kinetic conflict, a severed submarine cable and a software defect in a domain registry's signing system all produced comparable telemetry signatures and comparable user experiences, which suggests that resilience planning organised around any single threat category will leave most of the surface uncovered. Cloudflare said the findings “underscore the Internet's growing dependence on resilient physical and digital infrastructure”, and the company drew particular attention to the concentration of consequential events across the Middle East and Africa during the period.

Physical infrastructure still sets the ceiling on digital resilience

Sinlaku tracked through the Mariana Islands in mid-April as the strongest storm of the 2026 Pacific typhoon season to date. Guam avoided a direct hit, though tropical-storm-force winds removed power across the territory and disrupted water systems, with connectivity following the power grid down. Two months later, on 24 June, two major earthquakes struck northern Venezuela roughly a minute apart at Yumare and San Felipe, the first measuring 7.5 magnitude at approximately 22:04 UTC, followed by an aftershock near the coast outside Caracas. Cloudflare Radar registered an immediate decline in HTTP bytes transferred at Fibex Telecom, which APNIC data credits with an estimated 1.6 million users, alongside state-owned incumbent CANTV and the regional operator VNET.

Tanzania supplied the quarter's cleanest illustration of cause becoming irrelevant to consequence. A power outage on 27 June produced a sharp fall in HTTP traffic lasting at least five hours, and the telemetry closely resembled the country's deliberate election-related blackout of October 2025 despite one being an infrastructure failure and the other a policy decision. For residents unable to reach family or read the news, the two events were indistinguishable, which is the operative point for any organisation modelling availability by root cause rather than by observed impact.

Governments now treat national connectivity as an adjustable policy instrument

Iran's restoration began on 26 May, ending a shutdown that had run since 28 February. Traffic reached 40% of pre-outage levels within a day, consistent with reports of access being reintroduced selectively rather than all at once, and Cloudflare has characterised the recovery as one of the most significant connectivity restorations of the quarter. Progress since then has been uneven, and Lai Yi Ohlsen, Senior Product Manager at Cloudflare, said the company had watched HTTP bytes climb “to as high as 90% before settling back to roughly 59% of pre-shutdown levels”, a figure that matches February readings taken between the current shutdown and a previous one in January. Iran also stood out in Cloudflare's 2026 World Cup traffic analysis, where its readings tracked the contrast between restoration and near-total disconnection rather than the match schedule that shaped every other participating country.

Iraq imposed three shutdowns during the quarter, on 2, 11 and 28 June, each lasting around 90 minutes and scheduled around examination hours, while Sudan's 10 outages ran from 11:45 to 15:15 UTC on each affected day. Both patterns have recurred across multiple consecutive quarters, and their regularity has turned them into something closer to a published timetable than an emergency measure. For multinational operators, that predictability is the useful part, since scheduled state interference can be planned around in a way that seismic activity cannot.

HTTP traffic to me-central-1, the AWS region in the United Arab Emirates, remained significantly below normal throughout the quarter. AWS reported on 30 April that the region had sustained damage from the conflict in the Middle East and was “currently unable to reliably support customer applications”, following earlier disclosures on 3 March that facilities in both the UAE and Bahrain had taken physical impacts from drone strikes, with two UAE facilities struck directly and a strike near the Bahrain site damaging infrastructure there.

The traffic decline is the downstream signature of damage to data centre buildings rather than a routing or network fault, and it continues to degrade services hosted in the region irrespective of their own health. Enterprises with single-region deployments in the Gulf inherit that damage wholesale, and the episode establishes that armed conflict now belongs in cloud region selection criteria alongside latency, cost and data residency.

A single cryptographic defect can withdraw an entire national namespace

On 5 May, a routine DNSSEC key rollover at DENIC, the registry operator for Germany's .de domain, began producing invalid signatures at approximately 19:30 UTC. Validating resolvers worldwide, including Cloudflare's 1.1.1.1, were obliged by specification to reject the records and return SERVFAIL until normal operation resumed at 23:15 UTC. DENIC's final report attributed the incident to “an error in the software code of an in-house development”, introduced during improvements to a third-generation signing system that had been deployed in April, tested in advance and externally audited, with the defect escaping both test scenarios and parallel operation before go-live.

Radar recorded .de query volume rising during the outage, because failed answers cannot be cached and lookups normally served silently had to be re-resolved repeatedly. Users experienced none of that machinery, encountering instead a wave of German sites failing to load, email bouncing and applications timing out. Cloudflare noted in its incident analysis that a failure at that position in the DNS hierarchy has the potential to “make millions of domains unreachable”, and .de carries 17.9 million registered domains, making it one of the two largest country-code top-level domains in operation.

Route diversity determines how far a single cable cut travels

In the Caribbean, HTTP request traffic from Karib Cable's network fell to effectively zero by around 21:00 UTC on 21 June and stayed flat for the better part of a day, recovering around 17:00 UTC on 22 June. A submarine cable cut near the island was reported as the cause, and Saint Lucia's national traffic dropped approximately 60% against the prior week for the duration.

Caribbean networks depend on a small number of terrestrial and submarine paths to reach the wider Internet, which concentrates capacity such that one break severs a disproportionate share of it. The same geometry applies to any market served by limited routes, and the Saint Lucia outage demonstrates why path diversity is a commercial concern for operators serving small island economies rather than an engineering nicety. Cloudflare said its Radar team continues to monitor and annotate disruptions through the Radar Outage Center, where a fuller record of detected traffic anomalies is maintained.

Sindhu V Kashyap

Global Technology Journalist & Multimedia Storyteller | Covering Founders, Investors & Leaders Reshaping Tech | Writer · Interviewer · Moderator · Editor

Previous
Previous

Enterprises have deployed AI agents into core systems and left the identity layer ungoverned

Next
Next

Check Point converts installed firewalls into AI enforcement points as shadow AI spreads across enterprise networks