Bluesky was knocked offline for hours by a distributed denial-of-service attack, marking the social network’s second major DDoS incident in just a few months.
The company said attackers flooded its infrastructure with malicious traffic and that the attack activity continued for more than 24 hours. Bluesky has since upgraded its defenses and is continuing to monitor the situation, according to TechCrunch.
The latest disruption follows another significant DDoS attack in April, raising questions about whether Bluesky is facing sustained interest from attackers and how well its defenses can absorb repeated traffic floods.

A DDoS attack succeeds by consuming the infrastructure’s available capacity with high traffic, often generated from compromised internet-facing devices, particularly IoT appliances.
There is also the timing to consider. This is the second major DDoS attack to hit Bluesky in just a few months, following a significant campaign in April, which has put the platform’s defenses under renewed scrutiny and raised questions about whether attackers are scaling up their resources or finding new ways to circumvent the protections Bluesky has put in place.
Threat group claims responsibility
While the platform is back online, with the investigation ongoing, a threat actor has claimed responsibility for the attack.
According to reports from IFIN, 313 Team, an Iranian-backed threat group with the alias Islamic Cyber Resistance in Iraq, posted on their Telegram page that they successfully took down the social networking site.
The researchers tracking the attack speculate that the group may have used Cypher Services, a DDoS-for-hire service that appears to use the same underlying technology as a previously identified Beamed booter, which was itself protected by Cloudflare.
They reached this conclusion based on similarities in the services’ infrastructure and operation, although they stress that this is an inference rather than a confirmed link.
The same 313 Team also claimed responsibility for the recent GitHub outage.
Continued growth in DDoS attacks
DDoS attacks are getting bigger, easier to launch, and harder to ignore. Cloudflare’s own report confirms that.
In the Bluesky case, researchers noted some attack domains may have been built using AI-assisted coding tools. While this does not prove AI executed the attack, it illustrates how AI lowers the technical barrier for quickly building and replacing attack infrastructure. That matters because DDoS is ultimately an attack on availability.
For users, the immediate risk is not necessarily stolen data but being unable to access a service when they need it. For platforms, repeated attacks mean investing more heavily in traffic filtering and DDoS mitigation techniques just to remain online.
Users cannot stop a DDoS attack themselves, but they can avoid falling for the second wave that often follows an outage: fake recovery pages, phishing messages, and supposed alternative access links.
If a service goes down, wait for its official status channels to confirm what happened rather than trusting links circulating on social media.
Other security news: Researchers uncovered a crypto phishing and vishing operation that used Anthropic’s Claude Code to help process large volumes of phone numbers and identify potential cryptocurrency targets.





