Threats · 148 days ago
Bluesky’s outage matters because a sustained DDoS can knock out the parts of a social platform people rely on most: feeds, notifications, threads, and search. The standard response is to treat this as a temporary availability issue, but the real risk is that a decentralized service can still be forced into broad user-visible disruption even when no data is touched.
Bluesky said the attack began on April 15 and continued into April 16, with intermittent outages that intensified through the day. The company said it saw no evidence of unauthorized access to private user data and said it mitigated the attack; 313 Team claimed responsibility, but that attribution has not been independently verified.
The forward risk is persistence, not theft. If the service remains a visible target, attackers can keep using traffic floods to degrade trust and availability without needing to breach accounts or systems.
3 sources covering this story
The Record from Recorded Future
Bluesky blames app outage on ‘sophisticated’ DDoS attack
The decentralized social network said the incident began on April 15, when the company received reports of intermittent outages affecting the app.
Bluesky Disrupted by Sophisticated DDoS Attack
A pro-Iran hacker group has taken credit for the attack on Bluesky, which appears to have lasted 24 hours.
Bluesky confirms DDoS attack is cause of continued app outages | TechCrunch
Bluesky has been experiencing ongoing service disruptions since just before 3 a.m.
Part of the PlainSec briefing for 2026-04-20