Published
2025-11-18
Duration
7:13
Type
Video explainer

Why This Matters

When one network provider stumbles, businesses that assumed the internet just works discover they had no plan B. Restoration contractors live on phones, dispatch, and review platforms — all internet-dependent — so a cloud outage is a field-ops problem. Dependency and resilience, not blame.

What Happened

  • 11:20 UTC, November 18, 2025: Cloudflare’s network began failing to deliver core network traffic. Users saw error pages indicating a failure within Cloudflare’s network.
  • Not an attack: Cloudflare stated the issue was not caused, directly or indirectly, by a cyber attack or malicious activity of any kind.
  • Trigger: A bot-detection database permissions change produced duplicate entries in a Bot Management feature file, roughly doubling its size. Traffic-routing proxy software hit a hardcoded size limit below that new size and failed after the oversized file had already propagated across the network.
  • Blast radius: X, ChatGPT, Shopify, Canva, and Spotify went down or degraded for about five and a half hours, recovering later that afternoon UTC. Same-day video explainer.

Key Takeaways

  • One provider sat under a huge share of the modern web; when it stumbled, X, ChatGPT, Shopify, Canva, and Spotify felt it together.
  • Cloudflare confirmed this was not an attack — peacetime config and size-limit bugs can still cause multi-hour, multi-platform outages.
  • Provider-side error pages mean your servers may be fine while customers still experience you as down.
  • If dispatch, payments, reviews, and your site share one vendor path, a cloud outage becomes a same-day contractor ops outage.
  • Resilience means knowing your dependencies, having a customer communication plan, and not letting one vendor own your customer-facing presence.

When the Internet Goes Down: A Small-Business Playbook

  1. Map dependencies. List every tool you need to take a job, get paid, or reach a customer — hosting, CDN, DNS, phone/SMS, dispatch, payments, reviews — and who runs each.
  2. Status page and customer comms. Decide where you post a reachable channel when the site or chat dies, and who sends that message.
  3. Offline fallbacks for dispatch and payments. Paper tickets, a printed phone tree, and a card or invoice path independent of primary SaaS.
  4. Vendor diversification. Split DNS, email, and one outbound channel so one provider cannot silence every customer-facing surface.
  5. Rehearse once. Drill site-unreachable booking and notify paths before a real outage.

Expert Context

November 18, 2025 showed that “the internet” is often a short list of shared providers. Cloudflare’s postmortem described a bot-management feature-file failure that hit proxy software with a hardcoded size limit — not malice, not patchable from outside. Contractors can control concentration risk: if every customer-facing surface rides the same path, provider trouble means silent phones and stalled bookings.

Frequently Asked Questions

What caused the November 18, 2025 Cloudflare outage?

A change to database permissions in Cloudflare’s bot-detection systems caused duplicate entries in a Bot Management feature file, roughly doubling its size. Proxy software that routes traffic had a hardcoded size limit below that new size, so it failed after the oversized file had already propagated across the network.

Was the outage a cyberattack?

No. Cloudflare stated explicitly that the issue was not caused, directly or indirectly, by a cyber attack or malicious activity of any kind.

How long did the outage last, and what was affected?

About five and a half hours, with recovery later that afternoon UTC. Major sites went down or degraded, including X, ChatGPT, Shopify, Canva, and Spotify. Users saw error pages indicating a failure within Cloudflare’s network.

What is the “feature file” that triggered the outage?

A Bot Management data file generated from bot-detection databases and read by Cloudflare’s traffic-routing proxy. On November 18, 2025, duplicate database entries inflated it past a hardcoded proxy size limit, and the software failed.

What should a small business do when the internet itself goes down?

Map which vendors own your customer-facing presence, keep a status page or outbound message ready, and maintain offline fallbacks for dispatch and payments so one provider outage does not strand your whole operation.