Ubuntu and Canonical servers remain offline following sustained cross-border cyberattack
A group sympathetic to the Iranian government has claimed responsibility for the Distributed Denial of Service assault using the Beam platform, while mirror sites continue to function for system updates.

Ubuntu and Canonical servers have remained inaccessible for over 24 hours following a sustained cross-border attack that has knocked out the operating system provider's primary infrastructure. The outage has effectively silenced officials, preventing them from communicating normally about a critical vulnerability that grants untrusted users root access to servers running virtually all Linux distributions. While the official Ubuntu and Canonical webpages remain unreachable, system updates continue to be available through mirror sites, ensuring that the core functionality of the software is not entirely compromised.
Canonical's status page confirmed that the web infrastructure is under attack and that the company is working to address the issue. However, aside from this brief statement, Ubuntu and Canonical officials have maintained radio silence since the outage began on Thursday morning. The timing of the incident is significant, as the infrastructure went down hours after researchers released potent exploit code allowing untrusted users in data centres and university settings to gain all-powerful root control. This sequence of events has limited Ubuntu's ability to disseminate security guidance to affected users while the official channels are down.
A group sympathetic to the Iranian government has taken credit for the outage, claiming responsibility for the Distributed Denial of Service attack executed via the Beam platform. Posts on Telegram and other social media channels attribute the assault to this faction, which has previously taken credit for similar attacks on eBay. Beam is described as an operation that claims to test server capacity under heavy loads but functions as a front for stressor sites, where miscreants pay to take down third-party websites.
The persistence of the outage has raised questions regarding the resilience of the targeted systems. It remains unclear why the infrastructure has remained unavailable for such an extended period, particularly given the availability of a wealth of DDoS protection services, including at least one free option. While DDoS-as-a-service operators have come under the attention of law enforcement in multiple countries, attempts to permanently shut down these services have historically failed. The full extent of the damage to Canonical's internal systems beyond the web infrastructure is also not yet known.
The attribution of the attack to the pro-Iran group is based on social media posts and Telegram claims and has not been independently verified by law enforcement or Canonical. Although the claim that the outage prevents communication about a critical vulnerability is grounded in the timing relative to the release of exploit code, the specific impact on user safety is currently limited by the lack of official guidance. The situation highlights the ongoing challenges in securing critical digital infrastructure against sophisticated, cross-border cyber threats.
