Skip to content
DDoSResolved

Pro-Iran 313 Team DDoS knocks Ubuntu and Canonical web services offline, then demands contact

A sustained distributed denial-of-service attack claimed by the pro-Iran hacktivist group 313 Team took down ubuntu.com, canonical.com and several Ubuntu security and archive services, after which the group tried to turn the outage into an extortion attempt.

Victim
Canonical (Ubuntu)

On 1 May 2026, Canonical, the company behind the Ubuntu Linux distribution, confirmed that its web infrastructure was under a distributed denial-of-service (DDoS) attack. The hacktivist group The Islamic Cyber Resistance in Iraq, known as 313 Team, claimed responsibility.

Services affected

More than a dozen domains and services went down or returned errors, including ubuntu.com, canonical.com, security.ubuntu.com, archive.ubuntu.com, developer.ubuntu.com and portal.canonical.com. Users could not download Ubuntu images through the usual channels or log in to their Canonical accounts, and reports showed update operations failing on some Ubuntu systems during the outage. The Ubuntu security APIs for CVEs and security notices, which patch-management tools rely on, were also disrupted.

Canonical said its teams were "working to restore full availability to all affected services." By 4 May, all affected services appeared to have recovered.

From hacktivism to shakedown

313 Team turned the attack into an extortion attempt. On Telegram, the group told Canonical it had emailed a Session messenger contact ID and warned that it would continue the assault if the company did not reach out. In the preceding month the group had also claimed DDoS attacks against eBay's U.S. and Japanese sites and the Bluesky social network. Its motive for choosing Canonical was not clear.

Why it matters

The attack hit the distribution and security-advisory infrastructure that millions of servers and desktops depend on, at a time of heightened activity by pro-Iran groups against Western targets. Even without any data theft, knocking package archives and vulnerability feeds offline can stall patching across a large part of the Linux ecosystem.

Timeline

  1. Ubuntu and Canonical web services go down under a DDoS attack claimed by 313 Team; Canonical confirms it is working to restore availability.

  2. All affected services appear to have recovered.

Sources

  1. theregister.comhttps://www.theregister.com/2026/05/01/canonical_confirms_ubuntu_infrastructure_under/
  2. tomshardware.comhttps://www.tomshardware.com/tech-industry/cyber-security/canonical-under-sustained-ddos-attack-as-ubuntu-26-releases-iranian-group-313-team-claims-responsibility
  3. fastnetmon.comhttps://fastnetmon.com/2026/05/04/ubuntu-and-canonical-services-disrupted-by-ddos-attack/

Related incidents

Data breachOngoing

Fortune 500 Azure/Entra ID data theft (TheHatman)

A threat actor using the handle TheHatman advertised roughly 3.64 million employee directory records scraped from the Microsoft Azure and Entra ID tenants of multiple Fortune 500 companies, with access reportedly gained through stolen credentials harvested by infostealer malware.

Victim
Multiple Fortune 500 companies (Azure/Entra ID tenants)
Records
3.6M