Cloudflare shows how a single failure can wipe an entire country off the internet
"These incidents underscore the fragility of internet infrastructure, but also the remarkable stability global systems maintain when operating normally."
It’s no secret that human civilisation becomes more fragile as our critical systems grow more complex
Cloudflare's latest review of major internet disruptions during the second quarter of 2026 provides a startling reminder of this fact, showing how small events can trigger major outages.
As Cloudflare put it: "Like most infrastructure, the internet's fragility is easy to overlook - as long as it's working.
"When it fails, its complexity comes into full view."
Here are some of the most notable outages of the past quarter from a company in a "unique position to detect and document the moments when one of the interrelated systems the internet depends on breaks down".
Germany's internet goes kaput
For Germany, a national blackout began with routine maintenance.
On May 5, DENIC, the registry responsible for Germany’s .de domain, began producing invalid DNSSEC signatures during a cryptographic key rollover.
DNSSEC allows resolvers to verify that a DNS response is authentic rather than forged. If the signature does not match the expected key, a validating resolver is supposed to reject it.
That security property worked exactly as designed. Unfortunately, the signatures were wrong.
As cached records expired, fresh requests for .de domains started to fail validation. Then websites stopped loading, emails bounced and applications timed out.
Cloudflare said the failure had the potential to make millions of domains unreachable. Its resolver continued serving some previously cached answers beyond their normal expiry time, cushioning the impact while DENIC corrected the problem. Normal operation was restored later that evening. Without that fallback, the disruption would have been considerably worse.
Cloudflare also observed a rise in .de query traffic during the outage. The increase did not mean more people were successfully reaching German sites. Failed responses could not be cached normally, so devices and applications repeatedly tried the same lookups.
A single maintenance error had created a feedback loop: the less the system worked, the more work it generated.
This incident "underscored the fragility of internet infrastructure, but also the remarkable stability regional and global systems maintain when operating normally," Cloudflare wrote.
No outage is an island
Another "crisis level" incident took place in Saint Lucia.
At around 5 pm local time on June 21, traffic across Karib Cable’s network fell to almost zero. It remained there for most of the following day, recovering at around 1 pm on June 22.
The reported cause was a fibre cut near the island - an ordinary infrastructure failure with extraordinary consequences.
READ MORE: Stablecoins could become a systemic risk to global financial stability, central banks warn
Caribbean networks rely on a limited number of terrestrial and submarine routes to reach the wider internet. When the failure did not remain confined to one company, it became a national incident. Cloudflare recorded an approximately 60% fall in traffic across the country.
Saint Lucia was not completely disconnected, but a single broken physical connection was enough to remove most of its normal internet activity.
The incident demonstrates the difference between theoretical and actual redundancy. A network may have multiple providers and routes on paper while still depending on the same small number of physical paths underneath.
Forecasting a failure
The longest disruption Cloudflare recorded during the quarter followed Super Typhoon Sinlaku, which passed just north of Guam in April.
The island escaped a direct strike, but tropical-storm-force winds caused widespread power failures and disrupted water systems. Internet traffic fell as much as 80% below expected levels between April 13 and 14.
Venezuela also suffered a major outage after two major earthquakes struck within approximately a minute of each other, followed by an aftershock near the coast outside Caracas.
READ MORE: The Silicon Age Collapse: Systemic risks that could derail digital civilization
The first, a magnitude 7.5 earthquake near Yumare, was immediately followed by a sharp decline in data volume across several networks. The drop was particularly visible on one network, which has an estimated 1.6 million users, but also affected a state-owned provider and regional operator.
Three days after the Venezuelan earthquakes, a power outage caused internet traffic in Tanzania to fall sharply for at least five hours.
The cause was different from the government-directed blackout imposed during Tanzania’s October 2025 election. The technical footprint and the experience of users were much the same.
Drone attacks on the cloud
Cloud services are often treated as though they exist outside geography. Events in the Middle East demonstrated otherwise.
Cloudflare is still recording persistently low HTTP traffic to Amazon Web Services’ me-central-1 region in the United Arab Emirates after drone attacks on infrastructure in March.
AWS said two of its facilities in the UAE were directly struck, significantly impairing two of the region’s three Availability Zones. In Bahrain, a drone strike close to another AWS facility caused physical damage to its infrastructure. The strikes caused structural damage and disrupted power, while fire-suppression work produced additional water damage in some locations.
By the end of April, AWS said the UAE region was “unable to reliably support customer applications”. It advised customers to move accessible resources into other regions and restore inaccessible workloads from remote backups. Some workloads continued operating, but services without effective geographic redundancy remained exposed to damage at the facilities beneath them.
READ MORE: Agentic AI demands an upgrade to financial system resilience, Bank of England warns
Elsewhere in the Middle East, Cloudflare recorded the opposite of an outage.
Not every change Cloudflare recorded was a new outage. On May 26, its systems began detecting signs that Iran was restoring internet access after an 88-day national shutdown.
Traffic initially returned to around 40% of its previous level. It later rose as high as 90% before settling at roughly 59%. Cloudflare said that level resembled the limited connectivity seen between Iran’s recent shutdowns rather than a complete return to normal.
Iraq and Sudan also experienced a very controled kind of internet blackout: scheduled shutdowns imposed to prevent cheating in national examinations.
Cloudflare recorded three shutdowns in Iraq during June. Each lasted approximately 90 minutes and was timed around an examination period.
Sudan imposed ten shutdowns between April 13 and 23. Each followed a consistent schedule, lasting approximately three and a half hours from 1.45pm to 5.15pm local time.
Taken together, all these outages show just how vulnerable our critical infrastructure is to both human and natural disruptions.
Cloudflare wrote: "The second quarter of 2026 saw Internet disruptions arise from a wide range of causes, including severe weather, an earthquake, power outages, government-directed shutdowns, damage to cloud infrastructure, cable cuts, and a DNSSEC misconfiguration.
"As these events demonstrate, the Internet depends on a complex set of interrelated systems, and a failure in any one of them can result in a loss of connectivity."