security
May 1, 2026
By Teun
Ubuntu services hit by DDoS attack and extortion demand
Canonical’s Ubuntu infrastructure has been hit by a sustained DDoS attack since April 30, 2026, causing 503 errors on ubuntu.com and outages across security and update services. The attackers, identifying as the Islamic Cyber Resistance in Iraq - 313 Team, claimed responsibility and demanded negotiation through a Session contact ID.
Canonical’s Ubuntu infrastructure has been under a sustained denial-of-service attack since 1 PM EST on April 30, 2026, causing widespread service disruption across the company’s sites and update systems. Users trying to reach ubuntu.com have been seeing 503 errors, and the outage had continued for more than 12 hours at the time of reporting.
The attackers said they were the Islamic Cyber Resistance in Iraq - 313 Team. They claimed responsibility for the disruption and sent Canonical a direct message demanding that the company open a negotiation channel or face continued attacks. The message included a Session contact ID, according to the source report.
What makes this incident more serious than a typical website outage is the scope of the systems affected. The main ubuntu.com domain is down, but so are services tied to security updates and package distribution, including security.ubuntu.com, the Ubuntu Security API for CVEs and notices, Livepatch API, Launchpad, PPA infrastructure, keyserver.ubuntu.com, and several Canonical and Ubuntu web properties.
Some services remain available, including archive.ubuntu.com, documentation.ubuntu.com/project/, and discourse.ubuntu.com. The source report also said country archive mirrors and archive.ubuntu.com were working as of that point, but the default repository URLs were not functioning normally.
For everyday Ubuntu users, the immediate effect is limited but real. Systems are not reported to have been breached, and no user data exposure has been described. The practical issue is that normal update checks and package retrieval may fail while Canonical’s infrastructure is unreachable.
The impact is more serious for organizations running Ubuntu at scale. Automated patching pipelines depend on these repositories and APIs to check vulnerability data and pull updates. When those services fail, security teams can be left working with stale CVE information, and some machines may remain unpatched without operators realizing it.
That creates a wider security concern. Analysts cited in the source material warned that other threat actors could use the outage window to exploit known vulnerabilities that would normally have been patched quickly. If update systems cannot reach Canonical’s repositories, those vulnerabilities can stay open longer than intended.
The 313 Team has appeared before in hacktivist contexts, usually in connection with politically motivated disruption. The source report said the group’s apparent backend support through Beamed Network suggests a more organized operation than a small crew using commodity tools, but it also said the exact scale of the attack and Canonical’s mitigation progress have not been confirmed.
Canonical has not released a detailed public statement, and no estimated time of recovery has been provided. The company’s status page remains the main source of live information, and the report described that page as the most current update available to users.
The extortion demand is the unusual part of the attack. DDoS attacks often target public websites to cause embarrassment or disruption, but this one appears to target the update pipeline itself and then attach conditions to the assault. That combination turns an availability problem into a security operations problem, because the disruption can delay patching long after the traffic flood ends.
For now, the reported facts are simple: Ubuntu services are still experiencing a large-scale DDoS attack, several Canonical and Ubuntu systems are down, and the attackers are demanding contact in exchange for stopping.