A Moscow fire exposes the Russian internet’s single point of failure
On 18 August 2026, a fire at a Moscow power plant cut electricity to MMTS-9, the building that hosts the core of MSK-IX, Russia’s main internet exchange point; Discord, Steam, Telegram and the country’s mobile carriers went down with it. The incident confirms a twenty-one-year-old warning: concentrating interconnection in one place is fragile design.
18 August 2026. A fire hits Moscow’s Thermal Power Plant No. 20. 9 p.m. Moscow time. The power loss reaches MMTS-9, 1.5 kilometres away. May 2005. Engineers were already warning on the NANOG list that MSK-IX was a single point of failure. Twenty-one years later, the fire proved them right — and Discord, Steam, Telegram and the country’s mobile carriers went down with the building.
A fire 1.5 kilometres away takes a country’s internet down
The incident began around 9 p.m. Moscow time on 18 August 2026: an explosion followed by a fire struck an electrical facility on Vavilova Street in the Gagarinsky district, identified by witnesses as Thermal Power Plant No. 20. Within an hour, the power loss propagated to a building about 1.5 kilometres away at 7 Butlerova Street: Moscow Long-Distance Telephone Exchange No. 9, universally known as MMTS-9 or “M9”.
That geographic detail changes everything. MMTS-9 is not an ordinary office block: it hosts the core switching infrastructure of MSK-IX, Russia’s dominant internet exchange point. When M9 lost power, it was not a neighbourhood that went dark — the routing fabric of the Russian internet collapsed at its centre.
MSK-IX, the mandatory waypoint of the Runet
MSK-IX, the Moscow Internet Exchange, is Russia’s dominant exchange point. Founded in 1995, it connects 549 networks and handled peak traffic of 7.7 Tbps as of February 2025, making it the 17th largest IXP in the world and, by far, the largest in Russia. Its core switching infrastructure lives at MMTS-9.
The building combines two critical functions. First, interconnection: MMTS-9 hosts 41 telecom operators, more than any other Moscow data centre. Second, DNS: MSK-IX also operates the authoritative name servers for the .RU and .РФ country-code top-level domains. A prolonged outage of M9 would therefore not only cut ISP-to-ISP routing inside Russia — it would block resolution of any .RU address for users worldwide.
The Telegram channel ZaTelekom was among the first to name the cause, and the security outlet SecurityLab confirmed that hosting providers had begun “openly saying” their server racks at M9 were isolated.
Why one building brings down a whole country
To understand the cascade, it helps to recall what an IXP does. When two providers — say Rostelecom and MegaFon — want to exchange traffic, they have two options: pay a transit provider, or meet at a shared IXP and exchange traffic directly, for free. The technical mechanism is BGP: each provider announces its prefixes onto the switching fabric, the others learn those routes and send traffic accordingly.
When M9 lost power, every BGP session running through MSK-IX dropped simultaneously. Providers that peered only through MSK-IX suddenly had no direct path to each other; traffic had to reroute through paid transit links sized for low volumes, or simply failed. That is why the outage was national rather than local.
The redundancy systems M9 marketed — four independent power transformers and uninterruptible power supplies — are designed for internal equipment failures, not for a complete external grid disruption like the one a substation explosion produces.
A warning ignored since 2005
The fragility was not unknown: it was documented in writing. In May 2005, a Moscow power failure had already disrupted MSK-IX, and Michael Dillon, of Radianz, wrote on the NANOG list that “80% of Russian Internet traffic passes through MSK-IX” and that there was “no alternative exchange in Moscow”. His conclusion came down to one sentence: a single point of failure is “just plain bad design which WILL bite somebody in the end”.
Twenty-one years passed. In 2024, M9 announced it had run out of rack space entirely and was no longer accepting equipment. In May 2025, IXcellerate and MSK-IX launched a partnership to build a distributed telecom hub, presented as a “true alternative” — infrastructure that was not yet operational when the fire struck.
The economic logic explains the inertia: concentration on an IXP is self-reinforcing. The more operators in one place, the cheaper and more attractive it becomes to add another, which concentrates traffic further. The result is a hub-and-spoke architecture that piles massive dependencies into one ageing building.
The lesson for any network architect
The outage was visible within minutes: Downdetector logged more than 1,000 complaints in a single hour, concentrated in Moscow and St. Petersburg, for Discord, Steam, Telegram and the carriers MegaFon, Beeline, Rostelecom and Lovit. The registrar Reg.ru confirmed to TASS that the disruptions across the Runet were tied to a power outage at a major communications hub.
The lesson reaches far beyond Russia. Any critical operator that concentrates interconnection in one place reproduces the same pattern: a single data centre, a single IXP, a single power feed. Resilience is not declared inside a data centre — it is built through the geographic diversity of exchange points, power feeds and paths. Failures of this kind cannot be predicted in advance; they are paid for on the day you discover you should have anticipated them.
What resilience actually requires
The defence is not mysterious — it is simply rarely funded before the incident. It comes down to three moves.
- Two geographically separate exchange points. A backup IXP in another city, or at least in another building with independent power and connectivity, turns a national outage into a routine reroute.
- Distributed DNS announcements. The fact that MSK-IX combines interconnection with the .RU and .РФ name servers doubles the surface of the single point of failure. Anycast across separate sites would have contained the outage to routing alone.
- Tested fallback paths. Backup transit is useless if it is not sized for national traffic and exercised regularly. Redundancy is proven in real conditions, not on paper.
The cost of these measures is a fraction of the cost of a single hour of national outage. What the Runet lacked was not the technology — it was the decision to invest in redundancy whose urgency no one could see until the fire was already lit. Hub-and-spoke economics made MMTS-9 the cheapest place to peer, and every rational individual decision made the whole more fragile. Resilience is the opposite of a rational individual decision: it is a collective cost accepted in advance, so that a single substation explosion never becomes a national event. The Runet is not unique: the same concentration exists at smaller scale in many national and regional networks, and each of them is one substation explosion away from the same headline.
Verdict
If you operate critical interconnection, do not let network economics decide your resilience: build geographic diversity before you need it, with physically separate exchange points, independent power feeds and tested fallback paths.
If you depend on a service routed through a single IXP, map your exposure: identify the building, the exchange point and the power feed your traffic depends on, and put a number on what an hour or a day of downtime would cost you. The price of redundancy is trivial next to the price of a national outage.
References
- Moscow Fire Knocked Russia Offline: One Building Was Russia’s Runet Backbone — TechTimes, 19 August 2026
- Fire and blackouts near a Moscow telecom hub knock Discord, Steam and Telegram offline across Russia — Meduza, 18 August 2026
- Moscow Internet Exchange — Wikipedia
- 2005 NANOG discussion archive on MSK-IX
- Transnet 2025: Russian telecommunication infrastructure outlook — IXcellerate