Bluesky's daylong outage last weekend wasn't a glitch - it was a DDoS attack, the company confirmed.
Users across the US, UK, and France started reporting trouble loading Bluesky's feeds and app on Sunday, August 16. By Monday, August 17, the company confirmed a distributed denial-of-service attack had knocked it offline for roughly 24 hours. Bluesky hasn't said who was behind it, where the traffic originated, or how many users were affected, though it says it has since upgraded its defenses. Separately, security researchers on the IFIN forum linked the attack to Iraq-313 Team, an Iran-backed group that also claimed a similar strike on GitHub around the same time.
The claim tracks with the group's history: Iraq-313 Team has previously targeted Spotify and Ubuntu with DDoS campaigns, so this fits a pattern rather than breaking one. The more interesting detail is the plumbing - researchers say the attack ran on DDoS-for-hire infrastructure built on DiamWall, pulling IP addresses from a China-based reseller, which is not the same as Chinese involvement but does show how cheap, rentable attack tools keep lowering the bar for taking down major platforms.
Bluesky sells itself as the decentralized alternative to X, but a 24-hour blackout from a rented botnet is a reminder that decentralized identity and centralized infrastructure are two different problems.