VYPR
advisoryPublished Aug 17, 2026· 1 source

Threema Suffers Major DDoS Attack, Disrupting Secure Messaging Service

Secure messaging service Threema experienced significant disruptions due to large-scale distributed denial-of-service (DDoS) attacks that temporarily made the service unavailable.

The privacy-focused secure messaging service Threema was subjected to a series of large-scale distributed denial-of-service (DDoS) attacks, causing temporary disruptions to user access. The incidents, which began on Tuesday evening and continued intermittently through Wednesday morning, impacted the platform's availability before normal operations were fully restored.

Threema reported that the service was unavailable for approximately four hours on Tuesday evening, from 7:30 p.m. to 11:30 p.m. CEST. Users also encountered brief, intermittent outages on Wednesday morning as the attackers shifted their methods. The company confirmed that all services had returned to normal by 12:23 p.m. CEST on Wednesday.

A DDoS attack aims to render an online service inaccessible by overwhelming its infrastructure with an immense volume of traffic. Unlike attacks originating from a single source, DDoS operations leverage numerous compromised devices distributed across various networks, making them significantly harder to mitigate. Security teams face a constant challenge in blocking malicious traffic as attackers rapidly alter their sources, request types, and attack patterns.

The attacks specifically targeted both Threema's own infrastructure and that of its colocation partner, Nine. It remains unclear whether Threema was the sole target or if the activity was part of a broader campaign affecting multiple organizations. Threema described the incident as an "ongoing wave of attacks with constantly changing patterns," which complicated mitigation efforts without impacting legitimate users.

Crucially, Threema emphasized that the DDoS attacks affected service availability only and did not compromise the confidentiality or security of user data. The nature of a DDoS attack means it does not grant attackers access to servers, messages, account information, or internal systems; its primary goal is to exhaust network bandwidth and processing resources.

The incident also affected Threema's public status page, which was temporarily offline due to a separate technical issue unrelated to the DDoS activity. This limited the availability of official outage information during the critical period. Threema communicated updates via its social media channels and notified Threema Work business customers via email.

Organizations utilizing Threema OnPrem were unaffected, as this product runs on customer-managed infrastructure. In response to the attack, Threema implemented an additional, specialized upstream DDoS protection mechanism. This new control filters malicious traffic before it reaches Threema's core infrastructure, thereby reducing the load on internal systems and existing defenses.

Threema plans to enhance its status page with incident history and an RSS feed to provide users and administrators with a more robust channel for receiving system status alerts during future outages. The company confirmed the activation of its upstream filtering protection on August 14, 2026, at 6:05 p.m. CEST.

Synthesized by Vypr AI