Bluesky disrupted by day-long DDoS attack claimed by pro-Iran 313 Team
Social network Bluesky suffered roughly a day of outages affecting feeds, notifications, threads and search after what it confirmed was a sophisticated distributed denial-of-service attack; the pro-Iran hacktivist group 313 Team claimed responsibility.
- Victim
- Bluesky
Starting late on 15 April 2026 (Pacific time), Bluesky, the decentralised social network with roughly 43.7 million users, suffered widespread service disruption. Feeds stopped refreshing, and by the next morning notifications, search and threads were also failing for many users. Engineers worked overnight to mitigate the problem, and the app stabilised on 16 April, after roughly a day of degraded service.
Bluesky later confirmed the cause was a sophisticated distributed denial-of-service (DDoS) attack. "The application has remained stable since April 16 despite ongoing distributed denial-of-service (DDoS) attacks," the company said, adding that it had found no evidence of unauthorised access to private user data.
Claimed by a pro-Iran group
The pro-Iran hacktivist group 313 Team, which also presents itself as the "Islamic Cyber Resistance in Iraq," claimed responsibility on Telegram, saying it had launched a "massive cyberattack" against Bluesky's API servers. Bluesky said it was "not in a position to speculate about attribution" and did not confirm the claim.
Why it matters
The attack showed that Iran-aligned hacktivist DDoS campaigns were not limited to government and public-service websites but also reached large Western social platforms. Analysts caution that 313 Team often exaggerates its impact, so its claim should be treated carefully. While no data was stolen, a day-long outage of a service used by tens of millions of people highlights how API-heavy platforms remain exposed to volumetric and application-layer flooding, and how hacktivist groups use such disruptions for propaganda value regardless of formal attribution.
Timeline
Late in the evening (Pacific time), Bluesky feeds stop refreshing as intermittent outages begin; engineers work overnight to mitigate.
Notifications, search and threads are disrupted before the app stabilises later in the day despite continuing DDoS traffic.
Bluesky publicly attributes the outage to a sophisticated DDoS attack and says it has found no evidence of unauthorised access to private user data.
Sources
- therecord.mediahttps://therecord.media/bluesky-blames-app-outage-on-ddos
- securityaffairs.comhttps://securityaffairs.com/191059/security/bluesky-hit-by-24-hour-ddos-attack-as-pro-iran-group-claims-responsibility.html