Mastodon said its primary server, mastodon.social, was hit by a significant distributed denial-of-service (DDoS) attack that caused intermittent outages and left the instance temporarily unusable for some users. The company said it began investigating early Monday morning and later deployed countermeasures that restored access, while warning that some instability could continue because the attack was still ongoing.
The disruption affected Mastodon’s flagship instance rather than the broader federated network, underscoring how decentralized social platforms can suffer localized availability failures without a platform-wide compromise. Reports noted that the incident followed a similar prolonged DDoS campaign targeting Bluesky, and emphasized that DDoS activity is intended to overwhelm services with junk traffic and degrade availability, not inherently to steal data.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
By 9:05 a.m. ET, Mastodon said it had implemented countermeasures that restored access to mastodon.social, though some instability remained because the attack was still ongoing.
Around 7:00 a.m. ET, Mastodon confirmed it was investigating the attack affecting mastodon.social as the disruption continued.
Mastodon said mastodon.social was hit by a significant distributed denial-of-service attack early Monday morning, causing intermittent outages and making the server partially unavailable.
A Bluesky account shared the Breakglass report on Kimsuky, highlighting the mapped phishing infrastructure and linking it to DPRK cyber activity.
Breakglass Intelligence published a report mapping a DPRK-linked Kimsuky credential-harvesting operation, describing 850 hostnames, 6 servers, and a single kill chain targeting Korean credentials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
5 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcescworld.com
Open sourcetechcrunch.com
Open sourcebsky.app
Open sourceintel.breakglass.tech
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.