Menu
Browse

Cyber Incident Victim: Blender / blender.org

Date:

Mar 2021

Location:

Netherlands

Summary

The official website of a popular 3D graphics software entered maintenance mode following a hacking attempt, causing partial outages affecting some site sections and blogs while displaying error messages. Critical infrastructure including the Wiki, Developers portal, git repositories, and chat service remained operational, and downloadable software files were confirmed safe through verified checksums. The organization's cloud-based training platform was unaffected as the attack primarily targeted the main website subdomain, with restoration expected within hours.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 3 motives 4 techniques
Threat Actor Type Location
1 actor Available to members Available to members

Description

On March 15, 2021, the official Blender.org website entered maintenance mode following a confirmed hacking attempt targeting its infrastructure. The Blender team announced the incident via their official Twitter account, disclosing that the attack prompted immediate downtime for portions of the site while critical subsystems remained operational. The impacted infrastructure included specific sections of the primary blender.org domain and associated blogs, which displayed "This page is not available" errors directing visitors to archived copies. Core services such as the Wiki, Developers portal, git repositories, and blender.chat communication platform were unaffected and continued functioning normally throughout the incident. The Blender Cloud service at cloud.blender.org, hosting training materials, also remained online as the attack was confined to the www subdomain.

Cyber Incident Image

Initial containment measures involved isolating affected web assets and verifying the integrity of downloadable software releases. The team confirmed all distributed files were uncompromised by validating MD5 and SHA256 checksums available through download.blender.org and mirrors, assuring users of installation safety. Maintenance extended for several hours as technicians addressed vulnerabilities exploited during the breach, prioritizing restoration of full website functionality. No data exfiltration or secondary compromises of developer tools or version control systems were reported. The incident caused temporary disruption to public access for documentation and blog content but preserved operational continuity for collaborative development and software distribution channels. Blender's transparent communication via social media provided real-time status updates while technical teams executed recovery protocols to resume normal operations.

Sources
Sources available to members
1 source