Large-scale cyberattack on Canonical confirmed
The IT infrastructure of Linux distributor Canonical is under heavy fire. An "ongoing, cross-border attack" has been affecting numerous critical company services since Thursday, as Canonical confirmed on its status page. The attack is categorised as a "complete outage" and affects a large number of important Ubuntu components.
The affected services include the Ubuntu website, the Snapstore, Launchpad, as well as numerous other platforms such as security.ubuntu.com, wiki.ubuntu.com, login.ubuntu.com and maas.io. The full list covers more than 20 different services that are difficult or impossible to reach.
Scale and impact of the attack
The consequences of the attack are far-reaching. Users are currently unable to obtain ISO images of Linux distributions from Ubuntu or to log into their Canonical accounts. Critical security services such as the Ubuntu Security API for CVEs and notices are also badly affected, which complicates the management of security updates.
It is notable, however, that not all services are equally impaired. A test showed that Snap installations under Kubuntu 25.10 could still be carried out successfully, which suggests that the attackers may be acting selectively or that certain infrastructure components are more resistant to the attack.
Affected services in detail
- Main Ubuntu website and developer portal
- Snapstore and package repositories
- Launchpad development platform
- Security APIs and CVE databases
- Login services and account management
- Cloud services such as MAAS and Landscape
- Documentation and wiki systems
Background on the attacker group
According to reports by the IT news portal The Register, the pro-Iranian cybercriminal group "313 Team" has claimed responsibility for the attack. The group originally announced the attack for Thursday and planned a duration of four hours. In practice, however, the problems are lasting considerably longer than originally intended.
The hacking group has contacted Canonical directly with contact details and is threatening to continue the attack if the company does not respond. This points to a targeted extortion strategy, even though no concrete demands have been made public so far.
A familiar attack pattern
313 Team is already responsible for several similar attacks. The group has previously claimed DDoS attacks on the social media platforms Bluesky and Mastodon. IT security experts attribute the cyber gang to Iran and describe it as ideologically aligned with the Iranian regime.
What stands out, however, is the apparently arbitrary choice of targets. The attacks follow no recognisable strategic pattern, which makes the attackers' motivation difficult to assess.
Significance for the IT security industry
The attack on Canonical illustrates the vulnerability of critical open source infrastructure. Ubuntu is one of the most widely used Linux distributions worldwide and is deployed in countless server environments, cloud infrastructures and development environments. An outage of Canonical services can therefore have far-reaching effects on the global IT landscape.
The disruption of security services is particularly critical. If companies cannot retrieve current security updates and CVE information, potential security gaps arise in their infrastructure. This underlines the importance of redundant security measures and alternative sources of information.
Lessons learned for security managers
The incident shows how important it is not only to secure your own infrastructure but also to take dependencies on external services into account. Security managers should develop contingency plans for the failure of critical upstream services and identify alternative sources for security information.
Measures and outlook
Canonical says it is already working on resolving the problems. The company has officially confirmed the attack and is keeping its users informed via the status page. Restoring the services is likely to take some time, however, as this is a complex, coordinated attack.
Companies and developers who depend on Ubuntu services are advised to use local mirrors and to download critical updates in advance. In the longer term, this incident could lead to a decentralisation of the Ubuntu infrastructure and improved DDoS protection measures.
The attack also underlines the growing threat from state-backed or ideologically motivated hacking groups that are increasingly targeting critical open source infrastructure. This calls for stronger international cooperation on cybersecurity and better protective measures for essential IT services.