Cloudflare, Inc., is an American company that provides
content delivery network
A content delivery network (CDN) or content distribution network is a geographically distributed network of proxy servers and their data centers. The goal is to provide high availability and performance ("speed") by distributing the service spat ...
services,
cybersecurity
Computer security (also cybersecurity, digital security, or information technology (IT) security) is a subdiscipline within the field of information security. It consists of the protection of computer software, systems and networks from thr ...
,
DDoS mitigation,
wide area network services,
reverse proxies,
Domain Name Service,
ICANN
The Internet Corporation for Assigned Names and Numbers (ICANN ) is a global multistakeholder group and nonprofit organization headquartered in the United States responsible for coordinating the maintenance and procedures of several dat ...
-accredited
domain registration, and other services.
Cloudflare's headquarters are in San Francisco, California.
According to W3Techs, Cloudflare is used by around 19.3% of all websites on the Internet for its web security services,
History
Cloudflare was founded in July 2009 by
Matthew Prince, Lee Holloway, and
Michelle Zatlyn.
Prince and Holloway had previously collaborated on
Project Honey Pot, a product of Unspam Technologies that served as some inspiration for the basis of Cloudflare. From 2009, the company was venture-capital funded. On August 15, 2019, Cloudflare submitted its
S-1 filing for an
initial public offering
An initial public offering (IPO) or stock launch is a public offering in which shares of a company are sold to institutional investors and usually also to retail (individual) investors. An IPO is typically underwritten by one or more investm ...
on the
New York Stock Exchange
The New York Stock Exchange (NYSE, nicknamed "The Big Board") is an American stock exchange in the Financial District, Manhattan, Financial District of Lower Manhattan in New York City. It is the List of stock exchanges, largest stock excha ...
under the stock ticker NET. It opened for public trading on September 13, 2019, at $15 per share.
In 2020, Cloudflare co-founder and COO
Michelle Zatlyn was named president, making her one of the few female presidents of a publicly traded technology company in the U.S.
Cloudflare has acquired web-services and security companies, including StopTheHacker (February 2014), CryptoSeal (June 2014), Eager Platform Co. (December 2016), Neumob (November 2017),
S2 Systems (January 2020), Linc (December 2020),
Zaraz (December 2021), Vectrix (February 2022),
Area 1 Security (February 2022), Nefeli Networks (March 2024), BastionZero (May 2024), and Kivera (October 2024).
Since at least 2017, Cloudflare has been using a wall of
lava lamps in their San Francisco headquarters as a
source of randomness for encryption keys, alongside
double pendulums in its London offices and a
geiger counter in its Singapore offices.
The lava lamp installation implements the
Lavarand method, where a camera transforms the unpredictable shapes of the "lava" blobs into a digital image.
Cloudflare provided paid services to 162,086 customers.
Products
Cloudflare provides network and security products for consumers and businesses, utilizing edge computing,
reverse proxies for
web traffic
Web traffic is the data sent and received by visitors to a website. Since the mid-1990s, web traffic has been the largest portion of Internet traffic. Sites monitor the incoming and outgoing traffic to see which parts or pages of their site are ...
, data center interconnects, and a
content distribution network to serve content across its network of servers. It supports
transport layer
In computer networking, the transport layer is a conceptual division of methods in the layered architecture of protocols in the network stack in the Internet protocol suite and the OSI model. The protocols of this layer provide end-to-end c ...
protocols
TCP,
UDP,
QUIC, and many
application layer
An application layer is an abstraction layer that specifies the shared communication protocols and interface methods used by hosts in a communications network. An ''application layer'' abstraction is specified in both the Internet Protocol Su ...
protocols such as
DNS over HTTPS,
SMTP
The Simple Mail Transfer Protocol (SMTP) is an Internet standard communication protocol for electronic mail transmission. Mail servers and other message transfer agents use SMTP to send and receive mail messages. User-level email clients typi ...
, and
HTTP/2
HTTP/2 (originally named HTTP/2.0) is a major revision of the HTTP network protocol used by the World Wide Web. It was derived from the earlier experimental SPDY protocol, originally developed by Google. HTTP/2 was developed by the HTTP Working ...
with support for
HTTP/2 Server Push. Cloudflare handles an average of 45 million HTTP requests per second.
As of 2024, Cloudflare servers are powered by
AMD
Advanced Micro Devices, Inc. (AMD) is an American multinational corporation and technology company headquartered in Santa Clara, California and maintains significant operations in Austin, Texas. AMD is a hardware and fabless company that de ...
EPYC
Epyc (stylized as EPYC) is a brand of multi-core x86-64 microprocessors designed and sold by AMD, based on the company's Zen microarchitecture. Introduced in June 2017, they are specifically targeted for the server and embedded system market ...
9684X processors.
Cloudflare also provides analysis and reports on large-scale outages, including
Verizon
Verizon Communications Inc. ( ), is an American telecommunications company headquartered in New York City. It is the world's second-largest telecommunications company by revenue and its mobile network is the largest wireless carrier in the ...
’s October 2024 outage.
Artificial intelligence
In 2023, Cloudflare launched Workers AI, a framework allowing for use of
Nvidia
Nvidia Corporation ( ) is an American multinational corporation and technology company headquartered in Santa Clara, California, and incorporated in Delaware. Founded in 1993 by Jensen Huang (president and CEO), Chris Malachowsky, and Curti ...
GPU's within Cloudflare's network.
In 2024, Cloudflare launched a tool that prevents bots from scraping websites. To build automatic bot detector models, the company analyzed AI bots and crawler traffic.The company also launched an AI assistant to generate charts based on queries by leveraging Workers AI.Cloudflare announced plans in September 2024 to launch a marketplace where website owners can sell AI model providers access to scrape their site’s content.Cloudflare also launched AI Audit, which provides analytics on AI models scraping their sites (along with the ability to block them altogether).
DDoS mitigation
Cloudflare provides free and paid
DDoS mitigation services that protect customers from distributed
denial of service
In computing, a denial-of-service attack (DoS attack) is a cyberattack in which the perpetrator seeks to make a machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a host co ...
(DDoS) attacks. Cloudflare received media attention in June 2011 for providing DDoS mitigation for the website of
LulzSec
LulzSec (a contraction for Lulz Security) is a Grey hat, grey hat computer hacking group that claimed responsibility for several high profile attacks, including the 2011 PlayStation Network outage, compromise of user accounts from PlayStation N ...
, a
black hat hacking group.
In March 2013,
The Spamhaus Project
The Spamhaus Project is an international organisation based in the Principality of Andorra, founded in 1998 by Steve Linford to track email spammers and spam-related activity. The name ''spamhaus'', a pseudo-German expression, was coined by Li ...
was targeted by a DDoS attack that Cloudflare reported exceeded 300
gigabits per second (Gbit/s). Patrick Gilmore, of
Akamai, stated that at the time it was "the largest publicly announced DDoS attack in the history of the Internet". While trying to defend Spamhaus against the DDoS attacks, Cloudflare ended up being attacked as well; Google and other companies eventually came to Spamhaus' defense and helped it to absorb the unprecedented amount of attack traffic.
In 2014, Cloudflare began providing free DDoS mitigation for artists, activists, journalists, and human rights groups under the name "Project Galileo".
In 2017, they extended the service to electoral infrastructure and political campaigns under the name "Athenian Project". By 2020, more than 1,000 users and organizations were participating in Project Galileo, including 31 US states.
In February 2014, Cloudflare claimed to have mitigated an
NTP reflection attack against an unnamed European customer, which they stated peaked at 400 Gbit/s. In November 2014, it reported a 500 Gbit/s DDoS attack in Hong Kong. In July 2021, the company claimed to have absorbed a DDoS attack three times larger than any they'd previously recorded, which their corporate blog implied was over 1.2
Tbit/s in total. In February 2023, Cloudflare reported blocking a 71 million request-per-second DDoS attack which "the company says was the largest HTTP DDoS attack on record".
Cloudflare blocked the largest publicly-recorded DDoS attack in October 2024, with volumetric attacks peaking at 5.6
terabits per second.
Edge computing
In 2017, Cloudflare launched Cloudflare Workers, a
serverless computing
Serverless computing is "a cloud service category in which the customer can use different cloud capability types without the customer having to provision, deploy and manage either hardware or software resources, other than providing customer appli ...
platform for creating new applications, augmenting existing ones, without configuring or maintaining infrastructure. It has expanded to include Workers KV, a low-latency
key-value data store; Cron Triggers, for scheduling
Cron
The cron command-line utility is a job scheduler on Unix-like operating systems. Users who set up and maintain software environments use cron to schedule jobs (commands or shell scripts), also known as cron jobs, to run periodically at fixed t ...
jobs; and additional tooling for developers to deploy and scale their code across the globe.
In 2020, Cloudflare released a
JAMstack platform for developers to deploy websites on Cloudflare's Edge infrastructure, under the name "Pages".
In 2022, Cloudflare announced an Edge
SQL database, D1, which is built on
SQLite.
In August 2023, Cloudflare and
IBM
International Business Machines Corporation (using the trademark IBM), nicknamed Big Blue, is an American Multinational corporation, multinational technology company headquartered in Armonk, New York, and present in over 175 countries. It is ...
announced a partnership providing bot management capabilities to protect IBM Cloud customers from malicious bots and automated threats.
Also in August 2023, Cloudflare was hired by
SpaceX
Space Exploration Technologies Corp., commonly referred to as SpaceX, is an America, American space technology company headquartered at the SpaceX Starbase, Starbase development site in Starbase, Texas. Since its founding in 2002, the compa ...
to boost the performance of
Starlink, and in September launched Cloudflare Fonts as a competitor to
Google Fonts.
Internet security
In April 2020, Cloudflare announced it was moving away from using
reCAPTCHA
reCAPTCHA Inc. is a CAPTCHA system owned by Google. It enables web hosts to distinguish between human and automated access to websites. The original version asked users to decipher hard-to-read text or match images. Version 2 also asked users ...
in favor of
hCaptcha. In September 2022, Cloudflare began to test Turnstile – an alternative to
CAPTCHA
Completely Automated Public Turing Test to tell Computers and Humans Apart (CAPTCHA) ( ) is a type of challenge–response authentication, challenge–response turing test used in computing to determine whether the user is human in order to de ...
. The product, instead of presenting a visual CAPTCHA for the user to solve, automatizes the verification process by conducting JavaScript-based checks inside the browser to determine whether the user is a real person or an automated entity. The algorithm reportedly uses machine learning to optimize the process. Turnstile is
GDPR-compliant, offering a more private alternative to Google's
reCAPTCHA
reCAPTCHA Inc. is a CAPTCHA system owned by Google. It enables web hosts to distinguish between human and automated access to websites. The original version asked users to decipher hard-to-read text or match images. Version 2 also asked users ...
, which has been scrutinized for its data collection.
Through a contract with the
Cybersecurity and Infrastructure Security Agency, Cloudflare provides registry and authoritative DNS services to the .gov
top-level domain
A top-level domain (TLD) is one of the domain name, domains at the highest level in the hierarchical Domain Name System of the Internet after the root domain. The top-level domain names are installed in the DNS root zone, root zone of the nam ...
.
In November 2020, Cloudflare announced Cloudflare for Teams, consisting of a DNS resolver and web gateway called "Gateway", and a
zero-trust authentication service called "Access".
Cloudflare announced a partnership with
PhonePe in January 2023 to secure its mobile payment system. In February, Cloudflare launched Wildebeest to allow
Mastodon
A mastodon, from Ancient Greek μαστός (''mastós''), meaning "breast", and ὀδούς (''odoús'') "tooth", is a member of the genus ''Mammut'' (German for 'mammoth'), which was endemic to North America and lived from the late Miocene to ...
users to set up and run their own instances on Cloudflare's infrastructure.
In August 2023, Cloudflare started the Project Cybersafe Schools program as part of a $20 million grant program from
Amazon Web Services
Amazon Web Services, Inc. (AWS) is a subsidiary of Amazon.com, Amazon that provides Software as a service, on-demand cloud computing computing platform, platforms and Application programming interface, APIs to individuals, companies, and gover ...
, making 70 percent of public school districts in the United States eligible for no-cost cybersecurity services.
In March 2024, they announced Firewall for AI to defend applications running
large language models (LLMs).In September, Cloudflare announced Ephemeral IDs, which identifies fraudulent activity by linking behavior to a client through a short-lived, generated ID, rather than the traditional means of using an IP address.The same month, the company also announced all ISP and equipment manufacturers could use their DNS resolvers for free.
Cloudflare introduced the Cloudforce One threat events platform in March 2025, offering real-time insights into cyberattacks using data gathered from Cloudflare's network.
SASE
Cloudflare One, the company's overarching
SASE platform, debuted in October 2020.
Cloudflare One announced the acquisition of
Area 1 Security in February 2022, a company who developed a product designed to combat phishing email attacks.
Cloudflare One announced the acquisition of Nefeli Networks in March 2024, a cloud networking company, co-founded by computer scientist
Sylvia Ratnasamy.
VPN
In 2019, Cloudflare released a
VPN service called
WARP,
and open sourced the custom underlying
WireGuard implementation written in
Rust
Rust is an iron oxide, a usually reddish-brown oxide formed by the reaction of iron and oxygen in the catalytic presence of water or air moisture. Rust consists of hydrous iron(III) oxides (Fe2O3·nH2O) and iron(III) oxide-hydroxide (FeO(OH) ...
.
Other services
In January 2021, the company began providing its "Waiting Room" digital queue product for free for COVID-19 vaccination scheduling under the title "Project Fair Shot". Project Fair Shot later won a
Webby People's Choice Award in 2022 for Event Management under the Apps & Software category.
In March 2023, Cloudflare announced
post-quantum cryptography
Post-quantum cryptography (PQC), sometimes referred to as quantum-proof, quantum-safe, or quantum-resistant, is the development of cryptographic algorithms (usually public-key algorithms) that are currently thought to be secure against a crypt ...
will be made freely and forever available to
cloud services, applications and Internet connections.
In 2024, Cloudflare announced plans to launch a new payment method, called
Stripe Link, which went into beta in the fall.
Security and privacy issues
Intrusions
On June 1, 2012, the hacker group
UGNazi compromised some of Cloudflare CEO Matthew Prince's accounts and redirected visitors of the website
4chan to a Twitter account belonging to UGNazi. They allegedly used
social engineering to trick AT&T support staff into giving them access to Prince's voicemail, then exploited a vulnerability in Cloudflare's use of Google's two-factor authentication system. Once in control of Prince's email account, UGNazi was able to redirect the 4chan domain through Cloudflare's database.
2016-2017 data leak
From September 2016 until February 2017, a major Cloudflare bug nicknamed
Cloudbleed leaked sensitive data, including passwords and authentication tokens, from customer websites by sending extra data in response to web requests.
Controversies
Cloudflare has said that it has a content neutrality policy and that it opposes the policing of its customers on
free speech
Freedom of speech is a principle that supports the freedom of an individual or a community to articulate their opinions and ideas without fear of retaliation, censorship, or legal sanction. The right to freedom of expression has been recognise ...
grounds, except in cases where the customers break the law.
The company has faced criticism for not banning hate speech websites and websites allegedly connected to terrorism groups,
but Cloudflare has maintained that no law enforcement agency has asked the company to discontinue these services and it closely monitors its obligations under U.S. laws.
In 2022, a research paper by
Stanford University
Leland Stanford Junior University, commonly referred to as Stanford University, is a Private university, private research university in Stanford, California, United States. It was founded in 1885 by railroad magnate Leland Stanford (the eighth ...
found that Cloudflare was a prominent CDN provider among several other providers that are disproportionately responsible for serving misinformation websites. Cloudflare has come under pressure on multiple occasions due to its services being utilized to access
far-right content.
Service terminations
''The Daily Stormer''
Cloudflare provided DNS routing and DDoS protection for the
white supremacist
White supremacy is the belief that white people are superior to those of other races. The belief favors the maintenance and defense of any power and privilege held by white people. White supremacy has roots in the now-discredited doctrine ...
and
neo-Nazi
Neo-Nazism comprises the post–World War II militant, social, and political movements that seek to revive and reinstate Nazism, Nazi ideology. Neo-Nazis employ their ideology to promote hatred and Supremacism#Racial, racial supremacy (ofte ...
website, ''
The Daily Stormer.'' In 2017 Cloudflare
stopped providing its services to ''The Daily Stormer'' after an announcement on the website asserted that the upper echelons of Cloudflare were "secretly supporters of their ideology".
[ ]
Previously, Cloudflare had refused to take any action regarding ''The Daily Stormer''.
Founder Matthew Prince said he found the website's content "vile", but regretted he alone could "decide its fate".
He told ''
Business Insider
''Business Insider'' (stylized in all caps: BUSINESS INSIDER; known from 2021 to 2023 as INSIDER) is a New York City–based multinational financial and business news website founded in 2007. Since 2015, a majority stake in ''Business Inside ...
'': "The ability of somebody to single-handedly choose to knock content offline doesn’t align with core ideas of due process or justice. Whether that’s a national government launching attacks or an individual launching attacks."
As a self-described "free speech absolutist", Prince claimed he did not want to repeat the decision, and sought out protections for the company should they be faced with a similar situation in the future.
Prince further addressed the dangers of large companies deciding what is allowed to stay online, a concern that is shared by a number of civil liberties groups and privacy experts. The
Electronic Frontier Foundation
The Electronic Frontier Foundation (EFF) is an American international non-profit digital rights group based in San Francisco, California. It was founded in 1990 to promote Internet civil liberties.
It provides funds for legal defense in court, ...
, a US digital rights group, said that services such as Cloudflare "should not be adjudicating what speech is acceptable", adding that "when illegal activity, like inciting violence or defamation, occurs, the proper channel to deal with it is the legal system".
Mass shootings and 8chan
In 2019, Cloudflare was criticized for providing services to the far-right
discussion and imageboard
8chan. The message board has been linked to mass shootings in the United States and the
Christchurch mosque shootings in New Zealand.
In addition, a number of news organizations including ''
The Washington Post
''The Washington Post'', locally known as ''The'' ''Post'' and, informally, ''WaPo'' or ''WP'', is an American daily newspaper published in Washington, D.C., the national capital. It is the most widely circulated newspaper in the Washington m ...
'' and ''
The Daily Dot
''The Daily Dot'' is a digital media company covering the culture of the Internet and the World Wide Web. It was founded by Nicholas White in 2011, and is headquartered in Austin, Texas.
The site, conceived as the Internet's "hometown newsp ...
'' have reported on the existence of
child pornography
Child pornography (also abbreviated as CP, also called child porn or kiddie porn, and child sexual abuse material, known by the acronym CSAM (underscoring that children can not be deemed willing participants under law)), is Eroticism, erotic ma ...
and
child sexual abuse
Child sexual abuse (CSA), also called child molestation, is a form of child abuse in which an adult or older adolescent uses a child for sexual stimulation. Forms of child sexual abuse include engaging in Human sexual activity, sexual activit ...
discussion boards.
A Cloudflare representative said that the platform "does not host the referenced websites, cannot block websites, and is not in the business of hiding companies that host illegal content". Cloudflare did not terminate service to
8chan until public and legal pressure mounted in the wake of the
2019 El Paso shooting, in which the associated manifesto was published to 8chan.
In an interview with ''
The Guardian
''The Guardian'' is a British daily newspaper. It was founded in Manchester in 1821 as ''The Manchester Guardian'' and changed its name in 1959, followed by a move to London. Along with its sister paper, ''The Guardian Weekly'', ''The Guardi ...
'' immediately after the shooting, CEO Matthew Prince defended Cloudflare's support of 8chan, saying that he had a "moral obligation" to keep 8chan online.
On August 5, 2019, Cloudflare terminated service to 8chan. Following this, 8chan moved its forums from the
clearnet to the
dark web
The dark web is the World Wide Web content that exists on darknets ( overlay networks) that use the Internet but require specific software, configurations, or authorization to access. Through the dark web, private computer networks can communica ...
. Cloudflare explained that 8chan "have proven themselves to be lawless and that lawlessness has caused multiple tragic deaths. Even if 8chan may not have violated the letter of the law in refusing to moderate their hate-filled community, they have created an environment that revels in violating its spirit." Prince said that what happened in El Paso was "abhorrent in every possible way", removing 8chan from the Internet was "the right thing to do".
Kiwi Farms
Cloudflare provided
DDoS mitigation and acted as a
reverse proxy for
Kiwi Farms, a far-right Internet forum dedicated to discussion and
trolling
In slang, a troll is a person who posts deliberately offensive or provocative messages online (such as in social media, a newsgroup, a internet forum, forum, a chat room, an Multiplayer video game, online video game) or who performs similar be ...
of online figures or communities. The site often engages in harassment and
doxxing of targets
and has been implicated in the
suicides of at least three people.
Kiwi Farms also has a reputation for
transphobic content, and its users have been accused of
swatting vulnerable individuals.
Although Cloudflare was not the primary website host, they did perform critical services to keep Kiwi Farms on-line, both protecting the site from
denial-of-service attacks and
optimizing content delivery.
In 2022, a campaign was launched by
transgender
A transgender (often shortened to trans) person has a gender identity different from that typically associated with the sex they were sex assignment, assigned at birth.
The opposite of ''transgender'' is ''cisgender'', which describes perso ...
activist
Clara Sorrenti, who has previously been targeted by the forum, to pressure Cloudflare into terminating service for Kiwi Farms.
Cloudflare responded by issuing a statement on its abuse policies and saying it didn't want to set precedent for speech on the internet with its "extraordinary" decision.
The company also released a blog post and likened their services to that of a public utility, emphasizing that they do not believe in shutting down security services based on content they find objectionable. They acknowledged that while it might be more popular to remove sites that the Cloudflare team finds offensive, they stood by their decision not to do so. The company also defended their decision by saying that they donated all earnings from anti-
LGBTIQ+ sites to an organization that advocated for LGBTIQ+ rights.
The blog post mentioned Cloudflare's terms of use agreement, which allows them to terminate service due to "content that discloses sensitive personal information,
ndincites or exploits violence against people" but, according to ''
The Guardian
''The Guardian'' is a British daily newspaper. It was founded in Manchester in 1821 as ''The Manchester Guardian'' and changed its name in 1959, followed by a move to London. Along with its sister paper, ''The Guardian Weekly'', ''The Guardi ...
'', the statement did not address how Kiwi Farms users' doxxing behavior did not violate these terms.
On September 3, 2022, Cloudflare blocked Kiwi Farms, citing urgent escalating rhetoric against targets of Kiwi Farms, stating that there is an "unprecedented emergency and immediate threat to human life". According to ''The Washington Post'', there was a "surge in credible violent threats stemming from the site" and CEO Matthew Prince said that Cloudflare believes "there is an imminent danger, and the pace at which law enforcement is able to respond to those threats we don't think is fast enough to keep up".
Switter
Switter was a social media network for the
sex worker
A sex worker is a person who provides sex work, either on a regular or occasional basis. The term is used in reference to those who work in all areas of the sex industry.Oxford English Dictionary, "sex worker" According to one view, sex work is ...
community, built by Australia-based company Assembly Four on
Mastodon
A mastodon, from Ancient Greek μαστός (''mastós''), meaning "breast", and ὀδούς (''odoús'') "tooth", is a member of the genus ''Mammut'' (German for 'mammoth'), which was endemic to North America and lived from the late Miocene to ...
's open-source software, before Cloudflare dropped Switter as a client and ceased services in April 2018, citing terms of service violations.
This occurred shortly after the passage of
FOSTA/SESTA, a set of bills criminalizing websites that facilitate or support
sex trafficking
Sex trafficking is human trafficking for the purpose of sexual exploitation. Perpetrators of the crime are called sex traffickers or pimps—people who manipulate victims to engage in various forms of commercial sex with paying customers. Se ...
in 2018. SESTA
weakened protections for Internet infrastructure companies and was
criticized on free speech grounds due to concerns about disproportionate impact and disruptions to the lives of sex workers.
Cloudflare said the move was "related to our attempts to understand
FOSTA, which is a very bad law and
etsa very dangerous precedent". Assembly Four said that "Given Cloudflare's previous stances of privacy and freedom, as well as fighting alongside the
EFF, we had hoped they would take a stand against FOSTA/SESTA".
Terrorism
In 2015, testimony to the
United States House Committee on Foreign Affairs, it was reported that two of the top three online chat forums and nearly forty other web sites belonging to the
Islamic State of Iraq and the Levant
The Islamic State (IS), also known as the Islamic State of Iraq and the Levant (ISIL), the Islamic State of Iraq and Syria (ISIS) and Daesh, is a transnational Salafi jihadist organization and unrecognized quasi-state. IS occupied signi ...
(ISIL) were guarded by Cloudflare.
In 2018,
''The Huffington Post'' documented that Cloudflare provided services for "at least 7 terrorist groups", as designated by the
United States Department of State
The United States Department of State (DOS), or simply the State Department, is an United States federal executive departments, executive department of the U.S. federal government responsible for the country's foreign policy of the United State ...
including
Al-Shabaab, the
Taliban
, leader1_title = Supreme Leader of Afghanistan, Supreme leaders
, leader1_name = {{indented plainlist,
* Mullah Omar{{Natural Causes{{nbsp(1994–2013)
* Akhtar Mansour{{Assassinated (2015–2016)
* Hibatullah Akhundzada (2016–present) ...
, the
Popular Front for the Liberation of Palestine
The Popular Front for the Liberation of Palestine (PFLP; ) is a secular Palestinian Marxist–Leninist organization founded in 1967 by George Habash. It has consistently been the second-largest of the groups forming the Palestine Liberation ...
, the
al-Quds Brigades, the
Kurdistan Workers' Party
The Kurdistan Workers' Party, or the PKK, isDespite the PKK's 12th Congress announcing plans for total organisational dissolution, the PKK has not yet been dissolved de facto or de jure. a Kurds, Kurdish militant political organization and armed ...
(PKK), the
al-Aqsa Martyrs' Brigades, and
Hamas
The Islamic Resistance Movement, abbreviated Hamas (the Arabic acronym from ), is a Palestinian nationalist Sunni Islam, Sunni Islamism, Islamist political organisation with a military wing, the Qassam Brigades. It has Gaza Strip under Hama ...
.
At the time, Cloudflare's general counsel, Doug Kramer, told The Huffington Post that he couldn't comment on specific cases in which Cloudflare was told about possible terrorist organizations using its services, but that Cloudflare does work with government agencies to be in compliance with its legal obligations.
In September 2019, Cloudflare reported in their
Form S-1
Form S-1 is an SEC filing used by companies planning on going public to register their securities with the U.S. Securities and Exchange Commission (SEC) as the "registration statement by the Securities Act of 1933". The S-1 contains the basic ...
filing that their technology was "used by, or for the benefit of, certain individuals or entities" that were blacklisted due to United States economic and trade sanctions regulations", including "entities identified in OFAC’s counter-terrorism and counter-narcotics trafficking sanctions programs, or affiliated with governments currently subject to comprehensive U.S. sanctions".
Crime
Cloudflare has been cited in reports by
The Spamhaus Project
The Spamhaus Project is an international organisation based in the Principality of Andorra, founded in 1998 by Steve Linford to track email spammers and spam-related activity. The name ''spamhaus'', a pseudo-German expression, was coined by Li ...
, an international
spam
Spam most often refers to:
* Spam (food), a consumer brand product of canned processed pork of the Hormel Foods Corporation
* Spamming, unsolicited or undesired electronic messages
** Email spam, unsolicited, undesired, or illegal email messages
...
tracking organization, for the high numbers of cybercriminal botnet operations hosted by Cloudflare.
An October 2015 report found that Cloudflare provisioned 40% of the
SSL certificates used by
typosquatting phishing
Phishing is a form of social engineering and a scam where attackers deceive people into revealing sensitive information or installing malware such as viruses, worms, adware, or ransomware. Phishing attacks have become increasingly sophisticate ...
sites, which use deceptive domain names resembling those of banks and payment processors to compromise Internet users' banking and other transactions. Cloudflare has been criticized for having a
conflict of interest
A conflict of interest (COI) is a situation in which a person or organization is involved in multiple wikt:interest#Noun, interests, financial or otherwise, and serving one interest could involve working against another. Typically, this relates t ...
by providing DDoS protection to both the operators and victims of "
stresser" services.
In 2018, Cloudflare was identified by the European Union's Counterfeit and Piracy Watch List as a "
notorious market" which engages in, facilitates, or benefits from counterfeiting and piracy. The report noted that Cloudflare hides and anonymizes the operators of 40% of the world's pirate sites, and 62% of the 500 largest such sites, and "does not follow due diligence when opening accounts for websites to prevent illegal sites from using its services".
In 2020, an Italian court ruled Cloudflare had to block current and future domain names and IP addresses of the pirate IPTV service "IPTV THE BEST" for infringing on Lega
Serie A
The Serie A (), officially known as Serie A Enilive in Italy and Serie A Made in Italy abroad for sponsorship reasons, is a professional association football league in Italy and the highest tier of the Italian football league system. Establish ...
intellectual property. At the time, Cloudflare was already blocking 22 domain names in Italy. German courts have similarly found that "Cloudflare and its anonymization services attract structurally copyright infringing websites."
Following the December 2024 court ruling, the Spanish
LaLiga requested that telephone operators block Cloudflare's IP address ranges in February 2025. Cloudflare hosted websites that illegally broadcast soccer matches. As a result, the pirate platform DuckVision was shut down before the derby between Real Madrid and Atlético Madrid. The platform had 200,000 users and was backed by Cloudflare. The blocks affected major websites, including X,
Vimeo
Vimeo ( ) is an American Online video platform, video hosting, sharing, and services provider founded in 2004 and headquartered in New York City. Vimeo focuses on the delivery of high-definition video across a range of devices and operates on a ...
,
Steam
Steam is water vapor, often mixed with air or an aerosol of liquid water droplets. This may occur due to evaporation or due to boiling, where heat is applied until water reaches the enthalpy of vaporization. Saturated or superheated steam is inv ...
,
GitHub
GitHub () is a Proprietary software, proprietary developer platform that allows developers to create, store, manage, and share their code. It uses Git to provide distributed version control and GitHub itself provides access control, bug trackin ...
, and the Real Academia de la Lengua Española.
Response to the Russian invasion of Ukraine
After
Russia invaded Ukraine in late February 2022,
Ukrainian Vice Prime Minister, Minister of Digital Transformation
Mykhailo Fedorov and others called on Cloudflare to stop providing its services in the
Russia
Russia, or the Russian Federation, is a country spanning Eastern Europe and North Asia. It is the list of countries and dependencies by area, largest country in the world, and extends across Time in Russia, eleven time zones, sharing Borders ...
n market amidst reports that Russia-linked websites spreading disinformation were using the company's content delivery network services. Cloudflare CEO Matthew Prince responded that the company decided to remain providing services to Russian people to counter Russia's attempts to raise a 'digital iron curtain'. Prince shared that "Indiscriminately terminating service would do little to harm the Russian government but would both limit
ussian citizens'access to information outside the country and make significantly more vulnerable those who have used us to shield themselves as they have criticized the government."
The company later said it had minimal sales and commercial activity in Russia and had "terminated any customers we have identified as tied to sanctioned entities".
Cloudflare's Project Galileo, launched in 2014, offers
DDoS protection to
NGOs for free. In 2022, they extended free protection to
Ukrainian government and telecoms.
References
External links
*
*
{{Authority control
*
2009 establishments in California
2019 initial public offerings
American companies established in 2009
Companies based in San Francisco
Companies listed on the New York Stock Exchange
Content delivery networks
Cloud computing
DDoS mitigation companies
Domain name registrars
Freedom of speech in the United States
Internet properties established in 2009
Internet security
Internet technology companies of the United States
Networking companies of the United States
Reverse proxy
Technology companies based in the San Francisco Bay Area
Virtual private network services