Report: Cloudflare has foreign terrorist organizations as customers, possibly violating US laws; Cloudflare says it works with US to meet legal obligations
Rhett Jones / Gizmodo :
Context & Ripple Effects
This report lands mid-arc in Cloudflare's long-running tension between its position as a content-neutral network and the reality of who pays it for service. A year earlier, a ProPublica investigation had already forced an overhaul of its anonymous abuse-reporting system, and the company had separately picked a public fight with the FBI over National Security Letter gag orders.
What makes this story more than another abuse controversy is where it went: within nine months, Cloudflare disclosed potential sanctions violations in an SEC filing, naming blacklisted entities including terrorists and drug traffickers as users of its products — turning a press report into a formal legal and investor matter.
First-order effects
- Cloudflare faces direct legal exposure under US sanctions law if foreign terrorist organizations remain active customers, forcing account terminations and compliance reviews regardless of its content-neutral posture.
Second-order effects
- The SEC filing converts the issue into shareholder territory: institutional investors and enterprise buyers now price sanctions-compliance risk into a vendor whose core pitch is frictionless global reach.
Third-order effects
- If the pattern holds — from abuse reporting to sanctions disclosures to the later Kiwi Farms service controversy — infrastructure providers lose the 'neutral conduit' defense entirely, becoming legally accountable gatekeepers for who can build on their networks.
The trend: Internet infrastructure companies are being pulled from neutral utility status into enforced compliance and accountability roles, with regulators and investors rather than public pressure setting the terms.