Bluesky suffered a sustained distributed denial-of-service (DDoS) attack that caused intermittent outages and degraded performance across its website and mobile app for more than a day. The disruption began early Thursday and produced slow loading, blank screens, missing content, and repeated "Rate Limit Exceeded" errors, with users reporting problems accessing feeds, notifications, threads, search, user profiles, and popular areas such as Discover.
Company officials said the platform was being hit hard by coordinated traffic and was actively mitigating the attack, which also affected key API servers and even parts of Bluesky’s status infrastructure. Bluesky said it had found no evidence of unauthorized access to private user data, while reports indicated the impact was concentrated on Bluesky-operated services and that other communities running their own infrastructure on the underlying decentralized protocol remained available.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
A pro-Iran hacktivist group known as 313 Team, also called Islamic Cyber Resistance in Iraq, claimed responsibility for the DDoS attack that disrupted Bluesky for roughly 24 hours. The claim added a new attribution element beyond Bluesky's earlier confirmation that it was mitigating a sophisticated denial-of-service attack.
By the following day, Bluesky was still experiencing intermittent outages and degraded performance from the sustained traffic attack. Reporting noted that Bluesky-operated services remained primarily affected while some communities running their own infrastructure on the underlying decentralized protocol stayed functional.
As the disruption continued, Bluesky officials said the platform was being hit by a denial-of-service attack, with COO Rose Wang and protocol engineer Bryan Newbold publicly acknowledging the incident. Bluesky said it was mitigating a sophisticated DDoS attack and reported no evidence of unauthorized access to private user data.
Bluesky started suffering intermittent outages and degraded performance affecting its website, app, feeds, notifications, threads, search, and user profiles. The disruption began around 1:42–2:42 a.m. ET on Thursday, with users seeing blank screens, slow loading, missing content, and rate-limit errors.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
6 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcesecurityaffairs.com
Open sourcetherecord.media
Open sourcetechrepublic.com
Open sourcetechcrunch.com
Open sourcetechcrunch.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.