Much of China was effectively cut off from the internet after the standard port used for carrying HTTPS traffic into the country was blocked.
Uncovered by analysts at the Great Firewall Report and first spotted by The Register, traffic routed through TCP port 443 was effectively blocked for over an hour in the early hours of August 20.
“Between approximately 00:34 and 01:48 (Beijing Time, UTC+8) on August 20, 2025, the Great Firewall of China (GFW) exhibited anomalous behavior by unconditionally injecting forged TCP RST+ACK packets to disrupt all connections on TCP port 443,” the analysts wrote. “This incident caused massive disruption of the internet connections between China and the rest of the world.”
China’s internet traffic is censored, with the country’s Great Firewall, or Fánghuǒ Chángchéng, a series of technologies used to block access to parts of the internet, chiefly select foreign news websites and social media platforms.
It’s also not uncommon for the government to temporarily block web services in response to ongoing events such as protests. Regional governments also wield the power to suspend access, with a Great Firewall Report study published earlier this year revealing that internet users in Henan province, one of China’s most populous regions, were five times more likely to be blocked from accessing certain sites compared to citizens in other areas of the country.
What’s significant about this latest instance, however, is that no such events occurred, making the outage all the more mysterious.
The team at Great Firewall Report suggests the incident could have been caused by a new device installed as part of the Great Firewall of China or “a known device operating in a novel or misconfigured state.”
The analysts’ ability to understand the incident was “limited” by the short duration of the outage.
While it’s impossible to understand exactly what technologies have been implemented as part of the Great Firewall, China has been known to provide access to its block systems, with its ally Pakistan implementing similar systems – to the extent that traffic in the country dropped by 20% compared to ordinary levels just a handful of hours prior to the incident, according to data from NetBlocks.
Comments