Cyber Incident Victim: Blender / blender.org
Date:
Mar 2021
Location:
Netherlands
Summary
The official website of a popular 3D graphics software entered maintenance mode following a hacking attempt, causing partial outages affecting some site sections and blogs while displaying error messages. Critical infrastructure including the Wiki, Developers portal, git repositories, and chat service remained operational, and downloadable software files were confirmed safe through verified checksums. The organization's cloud-based training platform was unaffected as the attack primarily targeted the main website subdomain, with restoration expected within hours.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 3 motives | 4 techniques |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On March 15, 2021, the official Blender.org website entered maintenance mode following a confirmed hacking attempt targeting its infrastructure. The Blender team announced the incident via their official Twitter account, disclosing that the attack prompted immediate downtime for portions of the site while critical subsystems remained operational. The impacted infrastructure included specific sections of the primary blender.org domain and associated blogs, which displayed "This page is not available" errors directing visitors to archived copies. Core services such as the Wiki, Developers portal, git repositories, and blender.chat communication platform were unaffected and continued functioning normally throughout the incident. The Blender Cloud service at cloud.blender.org, hosting training materials, also remained online as the attack was confined to the www subdomain.

Initial containment measures involved isolating affected web assets and verifying the integrity of downloadable software releases. The team confirmed all distributed files were uncompromised by validating MD5 and SHA256 checksums available through download.blender.org and mirrors, assuring users of installation safety. Maintenance extended for several hours as technicians addressed vulnerabilities exploited during the breach, prioritizing restoration of full website functionality. No data exfiltration or secondary compromises of developer tools or version control systems were reported. The incident caused temporary disruption to public access for documentation and blog content but preserved operational continuity for collaborative development and software distribution channels. Blender's transparent communication via social media provided real-time status updates while technical teams executed recovery protocols to resume normal operations.
