Consumer Tech

What Broke the Internet in Q2 2026: Storms, Drones, DNSSEC

What Broke the Internet in Q2 2026: Storms, Drones, DNSSEC

Cloudflare blog cover graphic for the Q2 2026 Internet disruptions report

The internet’s fragility only becomes visible when it fails — and in the second quarter of 2026, it failed in almost every way it can. Cloudflare’s Q2 2026 Internet disruptions report, published Tuesday, catalogs a quarter in which a super typhoon, twin earthquakes, drone strikes on cloud data centers, thirteen government-ordered shutdowns and a single cryptographic misconfiguration each managed to knock meaningful chunks of the world offline.

The report, drawn from traffic telemetry on Cloudflare Radar, is the closest thing the industry has to a quarterly black-box recording of global connectivity. This quarter’s edition is worth reading less for any single incident than for the pattern: the causes could not be more different, yet the user experience on the ground — pages that won’t load, apps timing out, families unable to reach each other — is nearly identical every time.

The physical world keeps winning

The longest outage of the quarter came from weather. Super Typhoon Sinlaku, the strongest storm of the 2026 Pacific season so far, tracked just north of Guam in mid-April. The island avoided a direct hit, but tropical-storm-force winds knocked out power and water systems, and traffic from the territory fell as much as 80% below expected levels across April 13–14.

Two months later, on June 24, two major earthquakes — the first at magnitude 7.5 — struck northern Venezuela within about a minute of each other, followed by a coastal aftershock near Caracas. Radar registered a sharp, immediate drop in HTTP traffic at the moment of the quakes, clearest in Fibex Telecom’s network, which APNIC data estimates serves 1.6 million users, and also visible at state-owned CANTV. Days later, a June 27 power outage in Tanzania cut HTTP traffic sharply for at least five hours.

Cloudflare’s analysts make a quietly unsettling observation about that Tanzania event: its telemetry signature was nearly indistinguishable from the country’s deliberate election-related blackout of October 2025. An infrastructure failure and a government kill-switch leave almost the same footprint in the data — and the same residents cut off from news and each other.

Drone strikes are now an internet-weather category

The report’s most consequential thread for businesses is in the Middle East. HTTP traffic to me-central-1, the AWS cloud region in the United Arab Emirates, remained depressed all quarter — the downstream signature of physical damage, after AWS reported in March that facilities in the UAE and Bahrain “have experienced physical impacts to infrastructure as a result of drone strikes,” with two UAE facilities directly struck. By April 30, AWS said the region “has suffered damage as a result of the conflict in the Middle East and is currently unable to reliably support customer applications.”

That sentence should be pinned above every cloud architecture diagram. Applications hosted in that region stayed degraded regardless of their own engineering quality — no amount of application-level redundancy saves you when the data center itself has been hit. Multi-region failover has usually been sold as insurance against software faults and fiber cuts; Q2 2026 made the case that it is also insurance against ordnance.

Meanwhile, the quarter’s most repeated disruptions were entirely intentional. Iraq ordered three nationwide shutdowns in June and Sudan imposed ten between April 13 and 23 — all to prevent cheating on national exams, a seasonal pattern Cloudflare has now documented across multiple years. And in the quarter’s one genuinely hopeful data point, Iran’s 88-day national blackout ended: restoration began May 26, traffic reached 40% of pre-outage levels within a day, and has since settled around 59% — back to its pre-shutdown baseline, though far from fully normalized.

One bad key rollover, one national TLD down

The most instructive incident of the quarter needed no storm and no government order. On May 5, a DNSSEC key rollover at DENIC — the registry for Germany’s .de domain — began producing invalid signatures. Validating resolvers worldwide did exactly what they are designed to do when signatures don’t match published keys: they assumed tampering and returned SERVFAIL for every .de lookup until normal operation was restored at 23:15 UTC.

The counterintuitive detail is what Radar saw during the outage: worldwide .de query volume went up, not down. Failed answers are effectively uncacheable, so lookups normally served silently from cache had to be re-resolved and retried over and over. For users, a cryptographic maintenance error was indistinguishable from half of Germany’s web vanishing — pages failing, email bouncing, apps timing out.

A June 21 fiber cut near Saint Lucia rounded out the quarter, flattening Karib Cable’s traffic to essentially zero for the better part of a day and dropping the country’s overall traffic by roughly 60% — a reminder that entire Caribbean nations still hang off a small number of physical paths.

The takeaway for anyone running infrastructure

Severe weather, earthquakes, power failures, state shutdowns, drone damage, cable cuts and a botched key ceremony: seven unrelated failure modes, one shared lesson. The internet is a stack of interdependent systems, and resilience budgets tend to be spent on the layers engineers can see — application code, load balancers, CDNs — while the quarter’s actual outages came from power grids, submarine fiber, registry cryptography and geopolitics. The full anomaly feed is available in the Cloudflare Radar Outage Center, which is worth adding to your monitoring rotation if your users live anywhere the map can surprise you.

Editorially independent: we accept no payment for coverage and currently use no affiliate links. Read our Editorial Standards and Corrections Policy. Published: Jul 28, 2026.
Jinultimate

Editor of ZBrandCo and the person accountable for what we publish — setting our sourcing standards, fact-checking claims against primary sources, and issuing corrections promptly across AI, open source, and gaming. Reach the desk at editorial@zbrandco.com.