Bluesky said a day-long outage affecting its social network was caused by a distributed denial-of-service (DDoS) attack that flooded the platform with junk traffic for roughly 24 hours. Users in the United States, United Kingdom, France, and other countries reported access problems, and the disruption affected both Bluesky’s website and mobile app, leaving the decentralized service inaccessible for part of the incident.
Bluesky said it has strengthened its defenses and is continuing to monitor the situation, but did not disclose technical details about the traffic or its origin. Security researchers cited posts on the IFIN public forum in which the Islamic Cyber Resistance in Iraq-313 Team, described as an Iran-backed actor, claimed responsibility; however, public attribution remains unconfirmed. The outage follows another major DDoS-related disruption that hit Bluesky earlier in the year, and researchers also linked the same group to claimed attacks on GitHub, Spotify, and Ubuntu.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
Bluesky officially said the day-long service disruption was caused by a distributed denial-of-service attack that flooded the platform with junk traffic over the previous 24 hours. The company publicly confirmed the attack in a Monday post.
Users in the United States, the United Kingdom, France, and other countries began reporting access issues affecting Bluesky's website and mobile application. The disruption was later described as part of a roughly 24-hour DDoS attack.
Following the outage, Bluesky said it strengthened or upgraded its defenses and continued monitoring the situation. The company did not disclose further technical details about the malicious traffic or infrastructure involved.
Security researchers on the public IFIN forum reported that the Islamic Cyber Resistance in Iraq-313 Team claimed responsibility for the Bluesky attack. The group was described as Iran-backed, though attribution remained unconfirmed by Bluesky.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.