We put about a 25% chance on a US region of at least one million people losing most Internet access for a week or longer by the end of 2029, from a cause other than weather. If it happens, we expect power, fuel or hardware to set how long it lasts, not network repair.
Key points
- By 2029 we give about 25% odds to a regional Internet outage lasting a week or more, triggered by a cyberattack, a physical attack, a grid cascade or a government order.
- The most likely chain starts with a grid problem, adds a cyber intrusion, and then drags on because transformers and fuel run short.
- If such an outage happens, we are about 70% confident that grid restoration, not network repair, will decide when access comes back.
- A national, multi-week loss of access stays unlikely, below 5%, and failure or coercion at the root zone is the least likely route.
- Operators can lower the odds this year: extend backup power at network facilities beyond 72 hours and map dependencies on a single region.
Our forecast
By December 31, 2029, a US region of at least one million people will lose most fixed and mobile Internet access for seven or more consecutive days. The trigger will be wholly or partly non-weather: a cyberattack, a physical attack on grid assets, a grid cascade involving data center load, or a government order. We put this at about 25%. We exclude hurricanes and wildfires on their own because they already cause week-long outages. Our claim is that the new failure paths have become live.
Why we think so
Each earlier part adds one piece of the chain. The signal scan found that DNS, cloud, power and politics are each becoming more concentrated while pressure on them rises. The contradictions piece put about 70% of multi-day risk in the unmanaged layers: single-region control planes and the utility footprints under them. It did not put that risk in formally governed chokepoints like the root zone. Convergences showed that the pressures reinforce each other. Implications showed that the length of an outage is now set outside the network.
The trigger is getting easier to pull. Adversaries already have persistent access in provider-edge routers at four major carriers1. AI has pushed vulnerability discovery past the rate at which fixes can be deployed2, and an AI-built zero-day in exactly the kind of admin tool operators expose has already shown up in a planned mass campaign3. The grid is less stable too. Data centers have dropped more than 1,000 MW within seconds4, and DOE models baseline outage risk rising sharply as load outpaces firm capacity5.
Duration is where the risk has changed most. A destroyed extra-high-voltage transformer takes up to five years to replace6. Most facilities hold 48 to 72 hours of fuel, and exchange points and landing stations usually hold less7. So the network edge can go dark while servers are still running. The October 2025 us-east-1 failure showed that a single-region fault in Northern Virginia can act as a national one8. The response is getting weaker as well: threat-sharing protections run only to December 11, 20269.
We stop at 25% because this has not happened yet. Carrier intrusions have so far served espionage, not disruption. Verisign's week-long signature window gives time to recover from a root zone problem10. Political levers such as supply-chain designations11 and Section 70612 are more likely to lengthen an outage than to start one.
How this call fails
Suppose it is 2030 and we were wrong. The most likely reason is that defenders won the patch race. Glasswing-class discovery2 reached router firmware before attackers had comparable tools, and deterrence kept pre-positioned access dormant. A second possibility is that FERC's computational-load standards4 closed the loop between data center trips and grid cascades, and operators added fuel and batteries fast enough that outages ended in hours. The miss in the other direction is that we were too cautious, and the event that came was national rather than regional.
Who loses
- Residents of Northern Virginia and Texas, where national control planes and heavy AI load share one utility footprint84.
- Regional ISPs, exchange points and cable landing stations with thin backup power and slow patch cycles7.
- Providers whose standing with the government is contested, since a designation can force customers off them within days11.
- Anyone in an outage zone who relies on connectivity for payments, emergency information and supplies.
First moves
- Test whether carrier hotels, exchange points and landing stations can run beyond 72 hours, and sign fuel contracts that hold up in a regional disaster7.
- Map which critical services still depend on one cloud region's control plane, and move the ones you cannot afford to lose8.
- Rank edge routers and management panels for patching by exposure, and assume some are already compromised13.
- Plan for threat-sharing protections to lapse after December 11, 2026, with bilateral agreements in place beforehand9.
- Put government-designation risk into vendor contracts for DNS, CDN and cloud services11.
What would change our mind
- Toward higher odds: confirmed disruptive use of carrier router access, or Mythos-class zero-days in router or OT firmware in the wild12.
- Toward higher odds: a threat-sharing lapse or weak FERC ride-through rules by year end 202694.
- Toward lower odds: a multi-year threat-sharing reauthorization, plus measurable falls in time-to-patch for ISP edge gear.
- Toward lower odds: hyperscalers showing that global control planes no longer depend on a single region.
Sources
- Chinese state actors hold persistent access inside US ISP backbone and provider-edge routers · institutional ↩
- Mythos-class AI finds more than 10,000 high/critical vulnerabilities across every major OS and browser · disclosure · also helpnetsecurity.com ↩
- Google confirms the first AI-generated zero-day used in a planned mass-exploitation campaign · disclosure · also cnbc.com ↩
- NERC issues a rare Level 3 alert after 1,000+ MW data center loads drop off the grid in seconds · journalism · also powermag.com ↩
- DOE models a 100x rise in US blackout risk by 2030 as load outruns firm capacity · institutional ↩
- Large power transformer lead times reach 2.5 to 5 years amid a roughly 30% supply deficit, while substations remain soft targets · journalism · also powermag.com, cisa.gov ↩
- Data center backup power is sized for 48, 72 hours and depends on diesel logistics that fail in regional disasters · journalism · also mansfield.energy ↩
- One DNS race condition in AWS us-east-1 cascades into a 15-hour outage of global control-plane services · expert · also gremlin.com ↩
- The legal basis for US cyber threat-sharing survives on short-term extensions while CISA loses staff · journalism · also congress.gov ↩
- Verisign stays the single root zone maintainer through the early 2030s while also running the .com registry and two root servers · disclosure · also icann.org, ntia.gov ↩
- The Pentagon labels a leading US AI company a 'supply chain risk'; a court rules the label unlawful retaliation · journalism · also cnbc.com ↩
- The President's Section 706 authority to seize or shut down US communications remains unreformed · expert · also uscode.house.gov ↩