Invest1 publisher3 min readPublished
Russian drone strikes on shared Kyiv data centers cut at least four ISPs at once
Russian drones hitting Kyiv's shared exchange buildings took at least four ISPs down together and left about 100,000 households with internet problems. Providers that share a building fail as one, taking with them the phone alerts that warn residents of the next strike.
The Investor · Invest desk

What happened
- On September 23, Russian drones struck several Kyiv colocation data centers that double as internet exchange points, where many ISPs connect their networks.
- NetBlocks confirmed connectivity losses on at least four networks afterward: Kyiv Link, Pautina, UTELS and Crazy Network.
- UTELS said a data center holding its core equipment lost power, and its crews restored most customers within about two hours.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- decision A buyer paying two Kyiv ISPs for redundancy has to learn which building holds each one's core equipment before the second contract protects anything.
- cost An ISP whose shared building is physically damaged faces rebuilding equipment and lines, a far longer outage for its customers than the two-hour power loss UTELS fixed.
- exposure Residents who lose service in one strike also lose the push and Telegram alerts for the next wave, so each outage raises the danger of the following attack.
- precedent Strikes that silence alert delivery fall in a category the ICC is already examining, per reporting on the probe, adding the data-center attacks to the legal record against Russia.
An internet exchange point is a building where competing networks hand traffic to one another. Several of the Kyiv sites struck on September 23 were colocation centers doing that job [1]. Tech Times described the failure plainly: when several providers route traffic through one building, destroying it cuts connectivity for every ISP with equipment inside [2]. A business that paid two of those providers for redundancy could have lost both at once if their core equipment sat in the same hall.
The provider accounts fit that picture less neatly. UTELS described a data center housing its core equipment that lost power [4]. Pavutyna said one of its own data centers was struck [7], and Crazy Network said a central exchange facility was hit [8]. That could be one building or three. Tech Times does not say which of the four networks NetBlocks flagged shared a facility [3], and the drones hit multiple sites over two consecutive days [1][15].
The headcount has a gap of its own. UTELS alone had grown to more than 200,000 apartments earlier this year [5], more than twice the ministry's count of about 100,000 affected households in Kyiv and the surrounding region [9][1]. UTELS said the power loss potentially disrupted service across its network, and that crews brought most customers back within roughly two hours [4][6]. I'd take the ministry's figure as a measure of problems that outlasted the first repairs. On that reading, the number of households exposed in the first hours was larger.
The two providers that gave detail had very different weeks. A power loss at UTELS took about two hours to fix [6]. At Pavutyna, damaged equipment and communications lines left nearly half the network temporarily dark [7]. Sharing a building costs an ISP hours when an attacker cuts the power, and much longer when the attacker destroys the hardware. Ukrainian military intelligence says the September 23 strikes used Geran-5 jet-powered drones [14]. A photo from the Solomianskyi district showed a damaged office building that had housed key internet backbone nodes [14].
One facility can reach well past the city. Crazy Network said the strike on its exchange data center in the capital also disrupted internet and telephone service in Vinnytsia and Khmelnytskyi oblasts [8].
The evidence allows other readings. Suppose the four networks sat in separate buildings, each struck deliberately: then the problem is the length of Russia's target list, and diversity would have needed more sites than one raid covers. Should UTELS' two-hour recovery prove typical, concentration costs customers about two hours. A Pavutyna-style outage, if that is the norm, costs a rebuild of equipment and lines. I think the concentration case holds, because Crazy Network's account shows one Kyiv building's failure reaching two other oblasts [8]. A facility-level map showing that each affected network kept its core in a different building, lost to a separate hit, would prove that wrong.
The same outages reach the warning system. Most Ukrainians get air raid alerts as smartphone push notifications and through messaging apps, chiefly Telegram, and those need a working connection [10]. "Russia has targeted major Ukrainian data centers, seeking to disrupt the flow of information," Foreign Minister Andrii Sybiha said [11]. "This is critical civilian infrastructure that ensures people can access life-saving information. It is not a military target," he said [12]. According to reporting on the International Criminal Court's probe of strikes on Ukrainian civilian infrastructure, the investigation already covers attacks that disrupted "mobile data services that transmit air raid warnings" [13].
What to watch
- Whether Pavutyna restores the dark half of its network in place or moves core equipment out of the struck data center.
- A facility-level account from NetBlocks, the ministry or the ISPs showing which of the four affected networks shared a building.
- Whether the ICC's civilian-infrastructure probe takes up the September 23-24 data-center strikes.