NEWS Ubuntu is more than 12 hours. Millions can’t download the system – hackers are demanding negotiations with Canonical

Gold Surfer

Administrator
Staff member
Administrator
Moon-Club
Exclusive
Infinity
Premium
Member
Joined
Jan 20, 2026
Messages
345
Reaction score
2,431
The pro-Iranian group 313 Team took responsibility. What do they need?
1777760742103.png
Canonical faced a long-lasting DDoS attack on the web infrastructure, which damaged the Ubuntu website and part of the related services. The company confirmed that traffic comes from different countries, and teams are trying to restore the full availability of the affected resources. For users, the problem is noticeable immediately: the usual pages of Ubuntu open with errors or do not work, and some Canonical services remain unavailable.

Ubuntu occupies a special place in the Linux world. The distribution is used at home, on servers, in clouds, in training environments and corporate infrastructure. Therefore, the attack on public services Canonical hits not only the showcase of the project. When the main sites, download pages and related technical resources are not available, users can not normally download the image of the system, log in to the Canonical account or get part of the data through regular channels. Also, the failures affected the installation and update of Ubuntu, and the test on the test device showed an error when installing updates.

The Islamic Cyber Resistance in Iraq, also known as 313 Team, claimed responsibility for the attack. It is referred to pro-Iranian Hackivstist groups. At first, the participants said in Telegram that the attack would last four hours, but after more than 12 hours the failures continued. The main site Ubuntu and many subdomains remained unavailable, although individual resources, including Archive and Discourse, continued to work.

DDoS-attack does not require server hacking in the usual sense. Attackers overload the resource with a large amount of requests, which is why the site or API ceases to respond to ordinary users. This method is crudely more grossly theft of data or exploiting the vulnerability, but with sufficient power, even important public services quickly disable even important public services. In the case of Canonical, we are talking about the availability of infrastructure, and not about the confirmed compromise of user data.

Later, 313 Team published a message addressed to Canonical and said that the company could contact the group through Session Contact ID. Upon refusal, the participants threatened to continue the attack.

Why Canonical is on the list of targets is not yet clear. The group did not give a coherent explanation in open channels. It is possible that the reason could be the popularity of Ubuntu: the project belongs to the most notable Linux distributions, and a blow to its sites immediately attracts the attention of the technical community. Over the past month, 313 Team has also announced attacks on the Japanese and American divisions of eBay and on Bluesky.

The incident shows the weak point of the open infrastructure on which millions of users depend. The Ubuntu code is open, mirrors and alternative channels help reduce the damage, but central sites, APIs, accounts and download pages are still important access points. While Canonical is restoring the services, it is better for users to check the state of resources through the official channels of the project and not to click on random links to images or updates that may appear against the background of a failure.
 
6,087Threads
80,300Messages
5,943Members
Lupo2026Latest member
Top Bottom