CSIDB logo
Incident

Cloudflare

Incident posture

Attack window
2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 11:34

Linked entities

Victim
Cloudflare
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Cloudflare was among the cloud infrastructure providers affected by a series of major outages alongside Amazon Web Services and Azure, which triggered widespread global disruption and cascading service failures across SaaS organizations and customer-facing platforms. The incidents highlighted the systemic risk associated with the concentration of cloud services, demonstrating how outages at major providers can ripple across the broader digital ecosystem.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

Cloudflare was named in the Tokio Marine HCC International (TMHCCI) sixth annual cyber incidents report as part of a series of major outages in 2025 that also affected Amazon Web Services and Microsoft Azure. The report, compiled by TMHCCI's Cyber Security team and released in January 2026, grouped these cloud infrastructure outages together as a single entry among the ten most significant cyber incidents of the year. The outages were selected for inclusion because of their operational disruption, financial impact, and broader implications for the global digital ecosystem, with the report emphasizing that technology supply-chain compromise and cloud infrastructure concentration continue to drive systemic cyber risk for organisations worldwide.

According to the TMHCCI report, the cloud outages caused widespread global disruption across online services and customer-facing platforms. The authors highlighted the systemic risk of cloud concentration, noting that the failures triggered cascading service failures across Software-as-a-Service (SaaS) organisations that depended on the affected providers. The report did not specify the dates, root causes, or duration of the individual outages involving AWS, Azure, or Cloudflare, nor did it provide details on which specific services or customers were impacted. The lack of further technical detail in the source material means that any specific chronology, method of disruption, or attribution to threat actors cannot be determined from the available evidence. The TMHCCI report framed the outages primarily as an illustration of concentration risk rather than as a malicious cyberattack, distinguishing them from other entries on the list such as ransomware incidents, supply-chain compromises, and the AI-orchestrated espionage campaign attributed to a state-sponsored group.

In the broader context of the TMHCCI report, the cloud outage incident was included alongside other major 2025 events such as the Marks & Spencer ransomware incident, which caused an estimated £300 million impact to operating profit and triggered broader sector-wide effects across UK retail, and the Jaguar Land Rover ransomware attack, which the report described as the most economically damaging cyber incident to hit the UK, resulting in a £1.9 billion financial loss following the shutdown of vehicle production. Other incidents on the list included the Salesforce/Drift OAuth large-scale data breach, which exposed the records and contact details of millions of customers through compromised OAuth tokens; the Npm Ecosystem supply-chain attack, which compromised widely used JavaScript packages; and an alleged Oracle Corporation Cloud Platform supply-chain breach affecting over 140,000 tenants. The report also featured the first documented case of an AI-orchestrated espionage campaign, in which a state-sponsored cyber-espionage company used Claude AI to lead a large-scale autonomous attack targeting around 30 global organisations with 80–90 percent of the campaign automated. Additional incidents included a SK Telecom cybersecurity breach exposing the data of nearly 27 million users, an attack on Kering Group affecting fashion brands including Gucci, Balenciaga, and Alexander McQueen, and a cyberattack on Asahi Group Holdings that forced the suspension of key operational systems in Japan.

TMHCCI officials commented on the changing threat landscape, with Xavier Marguinaud, head of Cyber at Tokio Marine HCC International, stating that the past year marked a turning point as AI evolved from a theoretical risk to an active threat. Isaac Guasch, cyber security leader and author of the report, noted that from financial losses to widespread cloud outages, the pace of change over the past 12 months had been striking, and that tracking these incidents year-on-year helps the market stay ahead of emerging cyber threats and provide the best protection for the insured. Tokio Marine HCC is a member of the Tokio Marine Group, a global company founded in 1879 with a market capitalization of $81 billion as of September 30, 2025, and is headquartered in Houston, Texas, with offices in the United States, Mexico, the United Kingdom, and Continental Europe.

Because the only available source discussing Cloudflare in the context of this incident is the TMHCCI annual report summary, and that source treats the cloud outages as a combined entry without providing specific details about Cloudflare's individual outage events, the available factual information is limited to the fact that Cloudflare experienced a major outage in 2025 that contributed to widespread global disruption and cascading failures across SaaS organisations. The specific date or dates, technical causes, duration, affected services, and response actions taken by Cloudflare during the outage are not available in the provided source material, and therefore any further narrative detail would require speculation beyond what the evidence supports.

Sources

Sources available to members: 1 source.

CSIDB