Monday, August 3, 2026

Compute & Cloud

Canonical infrastructure hit by sustained DDoS attack

Canonical’s Ubuntu infrastructure is facing a sustained, cross-border outage, believed to be caused by a DDoS attack that has disrupted software updates for around 20 hours.

Canonical infrastructure hit by sustained DDoS attack
Photo: Canonical

Canonical, the company that develops and maintains the Ubuntu Linux operating system, is currently managing a sustained, cross-border outage affecting its public-facing infrastructure. The disruption, which began on Thursday, has targeted critical services that Ubuntu users rely on, with hacktivists claiming responsibility for taking down the public-facing infrastructure of both Ubuntu and Canonical. According to a post on a threat intelligence forum, the DDoS attack has made it impossible for users to update and install Ubuntu, affecting both the operating system’s security API and several Canonical websites. As of writing, the outage has been ongoing for around 20 hours.

The disruption is believed to have been caused by a distributed denial-of-service (DDoS) attack, a method that floods a target with junk traffic until it overloads or crashes. Hacktivists calling themselves The Islamic Cyber Resistance in Iraq 313 Team claimed on its Telegram channel that it was to blame for the DDoS attack. The hackers claimed to be using Beamed, a DDoS-for-hire service. These types of platforms, also known as booters or stressers, allow anyone to pay to launch attacks even if they have no technical skills or the necessary infrastructure to flood targets with traffic. The Beamed service claims to power attacks in excess of 3.5 Tbps, a figure used for scale comparison against attacks tracked by cybersecurity firms like Cloudflare.

When contacted, Canonical spokesperson Lelanie de Roubaix reiterated the company’s public acknowledgment of the situation. On its website, the company stated: “Canonical’s web infrastructure is under a sustained, cross-border attack and we are working to address it. We will provide more information in our official channels as soon as we are able to,”. While international authorities such as the FBI and Europol have spent years targeting these DDoS-for-hire services through domain seizures and arrests, the incident highlights the ongoing challenge of securing critical open-source infrastructure against cyber threats.

Why it matters

The attack highlights the vulnerability of critical open-source infrastructure to DDoS-for-hire services, which can paralyze essential security updates and installation services for an operating system’s user base.