how NetBlocks detects internet shutdown
“Confirmed: Network data indicate a subnational internet disruption in northern Ethiopia corresponding to reports of a telecoms blackout in Tigray.” NetBlocks published that finding on Friday, September 25, 2026. The sentence was carefully limited, but technically important: an outside observatory had seen enough change in network behavior to corroborate reports that Tigray was losing connectivity.
The finding did not mean NetBlocks could see every disconnected phone. It did not identify a switch flipped by a government, a severed fiber line or a failed power system. It meant that measurements collected from outside and, where available, inside the affected network had departed sharply enough from normal patterns to register as a regional disruption. Understanding that distinction is the key to understanding how internet shutdowns are measured.
The technology is less like watching a single master control panel than combining several instruments at a weather station. Border Gateway Protocol data show whether networks are still advertising routes to the wider internet. Active probes test whether destinations answer. Passive systems observe traffic volume and connection success. Latency and packet loss reveal degradation before a link disappears entirely. Investigators then compare those signals with geography, operators, time of day and reports from people on the ground.
What NetBlocks actually measured in Tigray
NetBlocks described a subnational disruption in northern Ethiopia that corresponded to reports of a Tigray telecoms blackout. “Subnational” is not a synonym for total. It indicates that the anomaly was concentrated below the country level, rather than an across-the-board collapse of Ethiopian connectivity. The public statement did not quantify every district, operator or service affected.
Human reporting provided a second layer of corroboration. AFP said it could not reach sources in Tigray by phone on Friday. Reuters reported that a Tigrayan living abroad could not contact people in the region and that contacts in Addis Ababa were also struggling to reach relatives. Those failed calls matter because web access, mobile data and voice service can fail differently; a blackout can be severe without every component disappearing at the same instant.
Local outlet Wegahta added an important complication. It reported disruption to Ethio Telecom mobile and internet service, while Safaricom reportedly continued to work in parts of Mekelle and elsewhere. Signal Post News could not independently verify how broad, reliable or durable that Safaricom access was. The mixed picture is consistent with an uneven, operator-specific or still-evolving event—and is one reason the evidence supports “subnational disruption” more securely than “every network in all of Tigray is offline.”
The first layer: BGP routing data
The internet is a network of networks. Each operator controls blocks of internet addresses, called prefixes, and uses the Border Gateway Protocol, or BGP, to tell neighboring networks which paths can reach them. Route collectors around the world record those announcements. If a provider withdraws many prefixes at once, or its paths vanish from the global table, an observatory may see a digital territory disappear from the map.
BGP is powerful because it observes the internet’s control plane: the instructions networks exchange about where traffic should go. A sudden regional withdrawal can be evidence of an operator going offline or being disconnected upstream. The timing and scope can be compared with the same network’s historical baseline and with unaffected providers elsewhere in the country.
But BGP is not a complete blackout detector. Routes can remain visible even when people cannot connect. A mobile operator may continue advertising its address space while radio access, local backhaul, authentication systems or power to cell sites has failed. Conversely, a route change can reflect maintenance or engineering rather than censorship. BGP answers “is a path being advertised?” more directly than it answers “can this resident send a message?”
The second layer: active probes, latency and packet loss
Active measurement sends controlled test traffic and records what comes back. Depending on the system and vantage points available, probes may attempt a network handshake, request a web resource, resolve a domain name or measure reachability to selected endpoints. If many probes that normally succeed begin timing out together, the failure becomes measurable even without access to an operator’s internal equipment.
Latency measures how long a response takes. Packet loss measures how much traffic never arrives. A network approaching failure may show rising delays, unstable routes or increasing loss before tests stop succeeding. Congestion often produces a noisy decline: service slows, improves and deteriorates as demand and capacity vary. A hard cutoff across many vantage points can look more abrupt. Neither pattern is a verdict by itself, but both help describe the shape and timing of an outage.
Active probes have blind spots. They require reachable test points or endpoints, and too few observations can make a local fault look larger than it is. Some networks filter diagnostic traffic. A test to one service cannot stand in for all internet use. Responsible observatories therefore look for agreement across multiple destinations, protocols and measurement sources rather than treating a single failed ping as proof of a shutdown.
The third layer: passive traffic-volume signals
Passive measurement does not send a special test. It observes ordinary traffic already flowing through systems such as internet exchanges, content networks, recursive DNS services or other large-scale infrastructure. When a region’s normal stream of connections falls far below its usual hour-by-hour pattern, the drop can reveal a disruption that routing data alone misses.
Baseline matters. Internet use naturally rises during the day, falls overnight and changes on holidays or during major events. Analysts compare like with like: the same place, operator and time window over previous days or weeks. A broad collapse across unrelated services is more significant than a decline on one platform, which could reflect a block on that service rather than loss of general connectivity.
Passive data also needs privacy safeguards and careful interpretation. Aggregated volumes can show that far fewer connections are succeeding without exposing the content of individual communications. They can reveal scale and timing, but usually not the experience of every household or the identity of the person who ordered—or accidentally caused—the change.
How analysts separate a shutdown from damage or congestion
No single graph labels its own cause. Investigators infer among competing explanations by asking whether the disruption lines up with administrative boundaries, providers, protocols and political events. A simultaneous cutoff across multiple operators can look different from one company’s equipment failure. A geographically tidy boundary may be more consistent with coordinated intervention than a cable break, while a cable break may produce routing changes along a physical path and affect places that share that infrastructure.
Timing also matters. A loss that begins during protests, an election or a military operation may raise suspicion of deliberate control, especially if authorities announce restrictions. A failure after a reported strike, power outage, flood or fiber cut points investigators toward infrastructure damage. Congestion is more likely to produce overloaded but partly functioning service than a stable flatline, although overloaded gateways can also fail catastrophically.
The strongest assessment combines technical and documentary evidence: network traces, provider notices, eyewitness accounts, public orders, power data and information about physical damage. Even then, observatories distinguish detection from attribution. Technical evidence can show that connectivity collapsed at a certain time and in a certain network; proving who caused it, under whose authority and for what purpose requires additional evidence.
The 2020–2022 Tigray precedent changed how wars are documented
Tigray entered the current crisis with one of the longest communications blackouts associated with a modern war. During the 2020–2022 conflict, service was severed or heavily restricted for more than 720 days. Food, medicine and cash were also constrained, journalists faced severe access limits, and families went long stretches without reliable contact. AFP has cited an estimated 600,000 deaths in the conflict, a figure whose uncertainty reflects in part how difficult contemporaneous documentation became.
The earlier blackout taught a hard lesson: evidence does not vanish simply because a network does, but it becomes slower, riskier and less complete. Survivors and local reporters carried testimony out physically. Humanitarian workers documented conditions when access allowed. Satellite imagery helped track destruction and displacement from outside the region. Photos and videos often surfaced only after connectivity returned, stripped of the real-time corroboration that makes location, date and sequence easier to verify.
That delay changes accountability. Hospitals cannot transmit casualty lists promptly. Witnesses cannot back up files in real time. Journalists cannot compare accounts while memories are fresh. Investigators may eventually reconstruct events, but a delayed record gives armed actors more time to deny, shape or overwhelm the evidence. The blackout therefore affects not just what the world knows today, but what courts, commissions and historians may be able to establish years later.
Landmark shutdowns built the modern detection playbook
Other shutdowns have shown why observatories use several methods at once. During Iran’s November 2019 crackdown, international traffic collapsed while much domestic connectivity remained available, demonstrating that a country can be isolated without switching off every local service. After Myanmar’s February 2021 coup, observers tracked nightly outages and later broader restrictions, a pattern whose regular timing pointed beyond ordinary technical failure. During Kazakhstan’s January 2022 unrest, connectivity fell on a national scale and later returned unevenly.
These cases were politically and technically different. Their common lesson was methodological: route visibility, traffic volume, reachability tests and on-the-ground reports become much more persuasive when they change together. They also showed that restoration can be selective. A government may reopen some networks, unblock some services or permit access during limited hours while the wider information environment remains constrained.
Why an internet blackout can become a weapon of war
Analysis: A communications blackout can create operational secrecy. It may make troop movements harder for civilians, journalists and opposing forces to track. It can slow the upload of photographs, testimony and geolocation clues, suppress evidence of civilian harm, and leave official statements with fewer immediate challenges. It can also impose economic pressure without a visible front line by disabling payments, remittances, orders and transport coordination.
Those advantages are not cost-free to the authority or armed actor seeking them. The same network loss can disrupt command, logistics and public administration. Rumor fills the information vacuum. But the burden is not evenly shared. Civilians cannot call relatives or emergency services. Hospitals struggle to coordinate referrals and supplies. Banks and mobile-money systems become inaccessible. Aid groups lose staff contact and needs data. Diaspora communities cannot verify whether family members are safe.
Economic strangulation compounds quickly. A merchant who cannot confirm a delivery may stop selling on credit. A household that cannot receive a remittance may be unable to buy food even if a market is open. A clinic with medicine may still fail to move it to the right place. Connectivity is therefore infrastructure in the same sense as roads and power: its loss changes who can move resources, who can document harm and who can be heard.
What NetBlocks can—and cannot—prove
The confirmed fact is narrow: network data indicated a subnational disruption in northern Ethiopia corresponding to reports of a telecoms blackout in Tigray. That is meaningful evidence of lost connectivity. It is not proof of a region-wide total shutdown, a specific technical mechanism or a responsible party.
The cause remains unconfirmed. An intentional order, physical damage, power failure, operator fault or a combination of factors could produce overlapping symptoms. The full geographic extent also remains unconfirmed, especially where measurements are sparse. Ethio Telecom had not commented at the time of publication. Wegahta’s report that Safaricom still worked in parts of Mekelle points to possible network diversity, but it does not establish region-wide resilience.
The measurements also cannot prove battlefield claims made while communications are constrained. They can explain why verification has become harder. For the political and military chronology, including airport seizures and fighting in Amhara and Afar, read Signal Post News’s separate report on the renewed Ethiopia–Tigray war. For the immediate humanitarian implications of the outage, see the companion blackout analysis.
What to watch next: restoration signals
A genuine restoration should appear in more than one place. Withdrawn BGP routes would be reannounced; active probes would begin succeeding; latency and packet loss would stabilize; passive traffic would climb toward the region’s normal baseline; and residents would report that voice, mobile data and fixed connections work across more than isolated pockets. Consistency across operators and locations matters more than a single successful call.
Partial recovery needs equally careful language. A route may return before last-mile access. One operator may reconnect while another remains offline. Traffic may recover but stay throttled, or selected services may work while others remain blocked. Observatories will be watching both the level of connectivity and the shape of the return.
What to watch next: escalation signals
The most serious network warning would be a wider fall extending beyond the initial subnational footprint or spreading across operators that had remained available. Repeated cuts after brief restorations, sustained loss of voice as well as data, or failures that track new fronts would suggest the communications crisis is deepening. Reports of damaged fiber, power or cell sites would strengthen an infrastructure explanation; an official restriction order would strengthen the case for deliberate action.
Human indicators matter just as much: hospitals unable to coordinate, banks suspending service, aid organizations losing staff contact, and families reporting prolonged silence. Those consequences show whether a technical disruption is becoming a humanitarian system failure.
Sources
- Reuters — Internet disruption seen in war-hit northern Ethiopia
- AFP via France 24 — Internet shut down in Ethiopia’s Tigray amid fears of war
- NetBlocks — Internet disrupted in Ethiopia’s Tigray region
- Wegahta Facts — Local network-service report
The September 25 alert does not solve the blackout. It makes the blackout visible. By combining routing data, reachability tests, traffic patterns and human reports, internet observatories can show that a region’s connection to the outside world has changed sharply. Their discipline is equally important: detection is not attribution, partial access is not normal service, and an empty data trace cannot tell the whole story of the people behind it.
Method note: Signal Post News used AI-assisted tools to organize source material and refine structure. Reporting claims are attributed to the organizations and outlets that established them; technical analysis distinguishes observed network behavior from unverified cause or intent.