Canonical confirmed widespread disruption across Ubuntu and Canonical web infrastructure after a sustained distributed denial-of-service attack hit ubuntu.com and related services. The pro-Iran hacktivist group The Islamic Cyber Resistance in Iraq (313 Team) claimed responsibility on Telegram, describing the operation as a multi-hour campaign, while reports said the impact lasted more than 12 hours. Canonical acknowledged the outages on its status page and through Ubuntu social channels as teams worked to restore availability.
The incident affected core services including website access, Canonical account logins, developer portals, package and security endpoints such as archive.ubuntu.com, security.ubuntu.com, and Ubuntu Security API resources for CVEs and notices. The disruption interfered with Ubuntu downloads, package installation, system updates, vulnerability-data retrieval, and automated patching workflows used by administrators worldwide. A follow-up message from the group introduced an apparent extortion angle, warning Canonical to make contact or face continued attacks, although no motive for targeting the company was publicly stated.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
An oss-sec mailing list post reported on Saturday that ubuntu.com, canonical.com, snapcraft.io, and security.ubuntu.com were reachable again, with successful DNS resolution and no observed packet loss. The post also showed a successful `apt update`, indicating package-related services had resumed after the prior DDoS disruption.
In a follow-up message, 313 Team told Canonical to contact the group or face continued attacks, indicating a shakedown element beyond the initial hacktivist claim. The motive for targeting Canonical was not otherwise stated.
Canonical confirmed the outages through its status page and Ubuntu's official X account, saying teams were working to restore full availability and would provide updates through official channels. At the time of reporting, Canonical had not publicly attributed the disruption to a DDoS campaign.
During the ongoing attack on Canonical's public-facing infrastructure, some users were reportedly unable to update or install Ubuntu packages. TechCrunch said it verified update failures on a test Ubuntu device, indicating the disruption extended beyond websites to package-related services such as the security API.
Canonical's main website and multiple subdomains experienced sustained disruption for more than 12 hours, affecting ubuntu.com, canonical.com, account access, downloads, developer portals, and security-related endpoints. Some services such as Archive and Discourse reportedly remained available during parts of the incident.
The pro-Iran hacktivist group The Islamic Cyber Resistance in Iraq, also known as 313 Team, announced on Telegram that it was conducting a distributed denial-of-service attack against Canonical's infrastructure and said the operation would last four hours.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourcetomshardware.com
Open sourcearstechnica.com
Open sourcecybersecuritynews.com
Open sourcetheregister.com
Open sourcetechcrunch.com
Open sourcego.theregister.com
Open sourceaskubuntu.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.