
Bluesky has now been knocked offline twice in a matter of months by DDoS attacks, and this time, security researchers are pointing the finger at Iran-backed actors. That is not a small detail to bury at the end of a post. According to TechCrunch, the platform confirmed the latest attack on Monday, saying the disruption lasted roughly 24 hours before its defenses caught up.
Bluesky’s official statement was brief. “We have upgraded our defenses in response, and we continue to monitor the situation,” the company wrote. No further details were shared. A spokesperson did not respond to press questions. So users who lost access for a full day got a vague reassurance and not much else.
A DDoS attack works by flooding a server with so much junk traffic that it can no longer respond to legitimate requests. Attackers typically do this by building botnets, networks of compromised devices pulled from homes and businesses worldwide, then directing all of that combined bandwidth at a single target. The goal is not to steal data. It’s to make the service unusable.
Security researchers discussing the incident in the IFIN public forum say Iran-backed groups have claimed responsibility. That lines up with a broader trend. Iran has significantly increased its attacks on U.S. businesses and infrastructure since the start of the U.S. and Israel-led military campaign earlier this year. Social platforms are soft targets in that context, but they are also visible ones. Taking down a public forum, even briefly, sends a message.
What makes this harder to dismiss is the repetition. Bluesky faced a similar wave of outages back in April, also caused by a flood of web traffic. The company has not confirmed whether the two incidents are connected. But two major DDoS events in a few months is not bad luck. It suggests someone has decided this platform is worth targeting repeatedly.
For users, that matters beyond the inconvenience of downtime. Bluesky has positioned itself as a decentralized, open alternative to platforms like X, attracting users who are already skeptical of big tech. Those users now need to ask whether the infrastructure behind that promise can hold up under sustained pressure. Upgraded defenses are good. Transparency about what those defenses actually are would be better.