← Canonical

2026 Canonical / Ubuntu — sustained DDoS, outages, and extortion-style demands (May)

2026 Unknown records affected Share on X

Data compromised

Primarily service disruption; no widely corroborated customer-database exfiltration indexed at catalog time

Technical writeup

Canonical, publisher of Ubuntu, publicly confirmed early May 2026 that its web-facing infrastructure was under large-scale distributed denial-of-service (DDoS) pressure with downstream impact to Ubuntu downloads, forums, and related services. Trade outlets attributed the campaign to hacktivist-style personas (reporting named 313 Team / Islamic Cyber Resistance in Iraq among circulating labels) and described extortion-oriented messaging alongside service restoration timelines. Canonical’s status communications indicated recovery by May 4–5 2026 for core endpoints; BreachHistory classifies the row as availability/extortion rather than a confirmed structured-data leak absent credential-dump corroboration.

Root cause

External DDoS and coordinated hacktivist/extortion activity against Canonical public infrastructure

References