ZeroFox Flash Report - Cyberattack Suspected in Worldwide X Outage
|by Alpha Team

ZeroFox Intelligence Flash Report - Cyberattack Suspected in Worldwide X Outage
Product Serial: F-2025-03-11a
TLP:CLEAR
In this Flash Report, ZeroFox researchers report on the recent global outage of the social media platform X (formerly Twitter), and the subsequent claiming of responsibility by the hacktivist collective Dark Storm.
Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- On March 10, 2025, social media platform X (formerly Twitter) experienced multiple service outages affecting a reported 1.6 million users worldwide and lasting several hours. As of the writing of this report, X services appear to be functional.
- Several hours later, the “Dark Storm” threat collective posted on its Telegram channel, claiming to have conducted a distributed-denial-of-service (DDoS) attack which resulted in X being “taken offline.”
- Ideologically motivated hackers, particularly pro-Russia hacktivist collectives, almost certainly view Elon Musk—and his high-profile government appointment and assumed political allegiances—as an acceptable and in-bounds target for disruptive cyberattacks.
- There is a likely chance that Dark Storm is responsible for a DDoS attack targeting X infrastructure as claimed. Although the collective offered no evidence to support its involvement, there is a robust correlation between the chosen target, Dark Storm’s publicly stated allegiances and motivations, and the historic tactics, techniques, and procedures (TTPs) of other pro-Russia, anti-Western hacktivist collectives.
Tags: global, tlp:clear, threat actor