Skip to content
Hacktivists launched DDoS against Canonical and disrupted Ubuntu updates

Hacktivists launched DDoS against Canonical and disrupted Ubuntu updates

Mezha May 1, 2026

A coordinated DDoS campaign has crippled Canonical’s public services, blocking Ubuntu updates for many users. Investigations continue while maintainers work to restore critical infrastructure.

Based on data from Techcrunch

Hacktivists have claimed responsibility for outages in the public infrastructure of the Ubuntu distribution and the company Canonical, which develops and maintains this software. The attack began on Thursday and affected services used by Ubuntu users.

Canonical’s web infrastructure is under a prolonged state- attack, and we are working on it. We will provide more information through official channels as soon as we can.

Hacktivists likely launched a distributed denial-of-service (DDoS) attack – a nasty, but often effective tactic that floods the target with excess traffic to overload it or cause it to fail.

Ubuntu developers discussed the attack on an unofficial Ubuntu community forum, stating that the attack affected Ubuntu’s security API and several Ubuntu sites and Canonical. According to a threat-analysis post on the forum, the DDoS also made updating and installing Ubuntu impossible. TechCrunch confirmed that the update could not be installed on a test device running Ubuntu.

As of now, the outages have lasted 20 hours. Canonical did not respond to a request for .

Hacktivists who call themselves The Islamic Cyber Resistance in Iraq 313 Team said on their Telegram channel that they are indeed responsible for the DDoS attack.

Additionally, the attackers claim that they are using Beamed, a DDoS-for-hire service. Such services, also known as booters or stressers, allow anyone to pay for launching DDoS attacks even if they lack technical skills and the necessary infrastructure to flood targets with fake traffic. In this case, the service claims to support attack speeds of over 3.5 Tbps, which is roughly half the bandwidth of the cyberattack that Cloudflare last year called the largest recorded DDoS attack.

During the course of monitoring the situation, experts emphasize that such incidents demonstrate a serious risk to open systems and Linux distributions that rely on stable internet infrastructure. Official sources have meanwhile refrained from further .

The events highlight the vulnerability of open systems that depend on stable internet infrastructure, and remind of the need for careful monitoring of security and service reliability. Experts expect further explanations from interested parties and continuation of the discussion on protecting critical online infrastructures.

Extracted Entities

Attack Types (1)

Companies (1)

Countries (1)

Platforms (1)

Tools (1)