Bluesky Hit by Second Major DDoS Attack in Months

Bluesky suffered its second major DDoS attack in months, causing hours of disruption as a threat group claimed responsibility for the outage.

Aug 19, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Bluesky was knocked offline for hours by a distributed denial-of-service attack, marking the social network’s second major DDoS incident in just a few months.

The company said attackers flooded its infrastructure with malicious traffic and that the attack activity continued for more than 24 hours. Bluesky has since upgraded its defenses and is continuing to monitor the situation, according to TechCrunch.

The latest disruption follows another significant DDoS attack in April, raising questions about whether Bluesky is facing sustained interest from attackers and how well its defenses can absorb repeated traffic floods.

Screenshot form X post by Bluesky about the DDOS attack.
Image: Screenshot from Bluesky

A DDoS attack succeeds by consuming the infrastructure’s available capacity with high traffic, often generated from compromised internet-facing devices, particularly IoT appliances.

There is also the timing to consider. This is the second major DDoS attack to hit Bluesky in just a few months, following a significant campaign in April, which has put the platform’s defenses under renewed scrutiny and raised questions about whether attackers are scaling up their resources or finding new ways to circumvent the protections Bluesky has put in place.

Threat group claims responsibility

While the platform is back online, with the investigation ongoing, a threat actor has claimed responsibility for the attack.

According to reports from IFIN, 313 Team, an Iranian-backed threat group with the alias Islamic Cyber Resistance in Iraq, posted on their Telegram page that they successfully took down the social networking site.

The researchers tracking the attack speculate that the group may have used Cypher Services, a DDoS-for-hire service that appears to use the same underlying technology as a previously identified Beamed booter, which was itself protected by Cloudflare.

They reached this conclusion based on similarities in the services’ infrastructure and operation, although they stress that this is an inference rather than a confirmed link.

The same 313 Team also claimed responsibility for the recent GitHub outage.

Advertisement

Continued growth in DDoS attacks

DDoS attacks are getting bigger, easier to launch, and harder to ignore. Cloudflare’s own report confirms that.

In the Bluesky case, researchers noted some attack domains may have been built using AI-assisted coding tools. While this does not prove AI executed the attack, it illustrates how AI lowers the technical barrier for quickly building and replacing attack infrastructure. That matters because DDoS is ultimately an attack on availability.

For users, the immediate risk is not necessarily stolen data but being unable to access a service when they need it. For platforms, repeated attacks mean investing more heavily in traffic filtering and DDoS mitigation techniques just to remain online.

Users cannot stop a DDoS attack themselves, but they can avoid falling for the second wave that often follows an outage: fake recovery pages, phishing messages, and supposed alternative access links.

If a service goes down, wait for its official status channels to confirm what happened rather than trusting links circulating on social media.

Other security news: Researchers uncovered a crypto phishing and vishing operation that used Anthropic’s Claude Code to help process large volumes of phone numbers and identify potential cryptocurrency targets. 

Joseph Chisom Ofonagoro

Joseph is a Technical Writer with about 3 years of experience in the industry, also advancing a career in cyber threat intelligence. He is passionate about the responsible use of technology, a passion that led him into cybersecurity. As an undergrad, he leads a novel community of technology enthusiasts at his school, NOUN, where he guides and shares resources for beginners in tech. His writing experience includes a diverse range of topics, from consumer tech to startups to tutorials. Additionally, he periodically shares case studies and research reports on cybersecurity on his social media pages.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.