Bluesky Hit by Second Major DDoS Attack in Months

Bluesky suffered its second major DDoS attack in months, causing hours of disruption as a threat group claimed responsibility for the outage.

Aug 19, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Bluesky was knocked offline for hours by a distributed denial-of-service attack, marking the social network’s second major DDoS incident in just a few months.

The company said attackers flooded its infrastructure with malicious traffic and that the attack activity continued for more than 24 hours. Bluesky has since upgraded its defenses and is continuing to monitor the situation, according to TechCrunch.

The latest disruption follows another significant DDoS attack in April, raising questions about whether Bluesky is facing sustained interest from attackers and how well its defenses can absorb repeated traffic floods.

Screenshot form X post by Bluesky about the DDOS attack.
Image: Screenshot from Bluesky

A DDoS attack succeeds by consuming the infrastructure’s available capacity with high traffic, often generated from compromised internet-facing devices, particularly IoT appliances.

There is also the timing to consider. This is the second major DDoS attack to hit Bluesky in just a few months, following a significant campaign in April, which has put the platform’s defenses under renewed scrutiny and raised questions about whether attackers are scaling up their resources or finding new ways to circumvent the protections Bluesky has put in place.

Threat group claims responsibility

While the platform is back online, with the investigation ongoing, a threat actor has claimed responsibility for the attack.

According to reports from IFIN, 313 Team, an Iranian-backed threat group with the alias Islamic Cyber Resistance in Iraq, posted on their Telegram page that they successfully took down the social networking site.

The researchers tracking the attack speculate that the group may have used Cypher Services, a DDoS-for-hire service that appears to use the same underlying technology as a previously identified Beamed booter, which was itself protected by Cloudflare.

They reached this conclusion based on similarities in the services’ infrastructure and operation, although they stress that this is an inference rather than a confirmed link.

The same 313 Team also claimed responsibility for the recent GitHub outage.

Advertisement

Continued growth in DDoS attacks

DDoS attacks are getting bigger, easier to launch, and harder to ignore. Cloudflare’s own report confirms that.

In the Bluesky case, researchers noted some attack domains may have been built using AI-assisted coding tools. While this does not prove AI executed the attack, it illustrates how AI lowers the technical barrier for quickly building and replacing attack infrastructure. That matters because DDoS is ultimately an attack on availability.

For users, the immediate risk is not necessarily stolen data but being unable to access a service when they need it. For platforms, repeated attacks mean investing more heavily in traffic filtering and DDoS mitigation techniques just to remain online.

Users cannot stop a DDoS attack themselves, but they can avoid falling for the second wave that often follows an outage: fake recovery pages, phishing messages, and supposed alternative access links.

If a service goes down, wait for its official status channels to confirm what happened rather than trusting links circulating on social media.

Other security news: Researchers uncovered a crypto phishing and vishing operation that used Anthropic’s Claude Code to help process large volumes of phone numbers and identify potential cryptocurrency targets. 

Joseph Ofonagoro

Joseph is a technical writer with about three years of experience creating clear, practical content across consumer technology, startups, tutorials, and cybersecurity. He is also advancing a career in cyber threat intelligence, driven by a strong interest in the responsible use of technology and its role in protecting people, organizations, and digital systems. His passion for cybersecurity grew out of a broader commitment to helping others understand technology safely and effectively. As an undergraduate at the National Open University of Nigeria, he leads a community of technology enthusiasts, guiding beginners, sharing learning resources, and helping students build confidence as they explore careers in tech. Joseph’s writing combines technical curiosity with an accessible, beginner-friendly style. In addition to his editorial work, he periodically shares cybersecurity case studies and research reports on social media, covering threat trends, security lessons, and practical insights for readers interested in cyber awareness and digital safety.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.