Attacchi DDoS mettono fuori uso Threema per ore
Cloud Security

Illustrative image generated with AI

DDoS Attacks Take Threema Offline for Hours

Threema messaging service offline for hours due to DDoS attacks, affecting users and businesses. Upstream protection added for better security.

Text generated by artificial intelligence, published without human review. AI transparency

Threema, the Swiss privacy-focused paid messaging service, suffered a series of DDoS attacks that caused a complete outage lasting around four hours, followed by further intermittent issues.

The incident was reported on August 16, 2026. Users began reporting problems on Tuesday evening. Initially, Threema attributed the disruption to a network issue at its colocation provider, but later confirmed that a distributed attack was involved.

Four Hours of Downtime Followed by Further Disruptions

The service was unavailable from 7:30 p.m. to 11:30 p.m. CEST on Tuesday. Recovery was not immediately stable, however: several users continued to report outages and access problems on Wednesday morning.

Reports came from multiple countries, even after the official status page indicated that normal service had resumed. Full operating conditions were restored at 12:23 p.m. CEST.

The duration and geographic spread of the issues indicate a significant impact on platform availability. Neither the total volume of malicious traffic nor the number of affected users was disclosed.

The attack also affected Nine, Threema’s colocation partner. It has not been established whether Threema was the primary target or one of several targets in a broader operation against the provider’s infrastructure.

An Adaptive DDoS Attack That Was Difficult to Filter

A DDoS attack, or Distributed Denial-of-Service attack, aims to saturate or overload systems with requests and traffic originating from numerous sources.

According to the available account, the attackers repeatedly changed:

  • traffic sources;
  • techniques used;
  • request structures;
  • the operation’s overall patterns.

This variability makes simply blocking a single address or source ineffective. Defenders must instead continuously reconfigure filters while distinguishing malicious traffic from legitimate user connections.

Threema described the activity as prolonged and marked by constant changes. The combination of its duration, geographic scope, and shifting patterns complicated mitigation efforts.

The incident affected the availability of the service. It was not linked to a specific software vulnerability, no CVE identifiers were provided, and no indicators of compromise were reported.

Who Was Affected

Users of Threema’s standard applications experienced access problems and disruptions to their communications during the outage and in the hours that followed.

Business customers using Threema Work were also affected. The company emailed them on Wednesday morning, while account managers provided additional information in response to inquiries.

Threema On-Prem was different. Organizations using this deployment model were not affected because their installations run on their own infrastructure and do not depend on the impacted colocation environment.

This infrastructure separation limited the impact on organizations requiring greater operational isolation. It does not eliminate every connectivity risk affecting individual organizations, but it avoids dependence on the central infrastructure involved in the incident.

The Status Page Complicated Monitoring

During the incident, the system status page was not initially updated because of a technical issue unrelated to the DDoS attack. The service was therefore temporarily taken offline.

The lack of this channel made it more difficult for users and administrators to verify the actual progress of the incident. This explains why conflicting reports continued even after the platform had formally been restored.

Threema used social media to distribute ongoing updates. For Threema Work customers, email was the primary communication channel, supplemented by direct contact with account managers.

Countermeasures Introduced by Threema

On August 14, Threema added specialized upstream DDoS protection to its infrastructure. The system is intended to filter malicious traffic before it reaches the company’s systems, reducing the load on and direct exposure of the production environment.

The measure cannot guarantee that future attacks will be impossible, but it moves part of the detection and traffic-absorption capacity outside the core infrastructure. This approach is particularly relevant when attacks rapidly change their sources and characteristics.

The company also plans to enhance its status page with:

  • an incident history;
  • an RSS feed;
  • an independent channel for receiving service updates;
  • subscription options for Threema users and Threema Work administrators.

Organizations that cannot accept dependence on shared infrastructure can continue to use Threema On-Prem, which was not affected by the disruption described here.

What Is Not Known About the Operation

The attacks have not been attributed to a specific group, and no motive has been disclosed. It is also unknown whether Threema, Nine, or both infrastructures were the direct target.

No public details indicate unauthorized access to data or compromised systems. The available information describes an availability incident, not a breach involving a software flaw.

For the same reason, this case does not fall under CISA’s KEV Catalog: no exploited vulnerability or corresponding identifier was reported. Immediate steps for users are therefore to monitor official service updates, use the alternative channels identified by Threema, and, for organizations with stricter requirements, consider an On-Prem architecture.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicsDDoS attacksThreemamessaging serviceoutagecybersecurityonline privacydistributed denial of servicemitigation
Back to home