DDoS Attacks Cause Major Threema Outages
Sustained distributed denial-of-service attacks knocked Swiss secure messenger Threema offline for hours before upstream filtering restored service; On-Prem users unaffected.
Threema suffered a series of large-scale DDoS attacks that left its Swiss secure messaging service unavailable for about four hours Tuesday evening, with intermittent outages into Wednesday morning until restoration at 12:23 p.m. CEST. Attacks also targeted colocation partner Nine and kept changing patterns, complicating mitigation. Threema deployed additional upstream DDoS protection on August 14 and plans status page improvements; Threema On-Prem customers running their own infrastructure were unaffected.
- Service down roughly four hours Tuesday evening; intermittent disruptions Wednesday.
- Attack patterns constantly changed, making mitigation a cat-and-mouse exercise.
- Colocation partner Nine was also targeted; On-Prem deployments unaffected.
- Upstream DDoS filtering added August 14; status page gains incident history and RSS feed.
Full article551 words · extracted from securityaffairs.com · click to collapse

Large DDoS attacks disrupted Threema, causing severe communication outages. Threema On-Prem users were unaffected by the attacks.
Threema suffered multiple large-scale DDoS attacks that disrupted its secure messaging service and caused severe communication issues. Organizations using Threema On-Prem were not affected, as their deployments run on their own infrastructure.
Threema is a Swiss paid secure messaging service, similar to WhatsApp or Signal, focused heavily on privacy and security.
“If the attack originates simultaneously from multiple (and potentially changing) sources, it is referred to as a “Distributed Denial of Service” (DDoS) attack. This makes the attack significantly more difficult to defend against because it is not possible to simply block a single source.” reads the report. “Because sophisticated attackers constantly change their methods, sources, and attack patterns during an attack, a cat-and-mouse game ensues, with both sides continuously reacting to the other’s most recent action.”
Users began reporting Threema outages on Tuesday evening. The company initially blamed a network issue at its colocation provider, but later confirmed it was facing a series of DDoS attacks. The attacks caused intermittent disruptions into Wednesday, with users in several countries still reporting problems even after Threema’s status page showed the service as operational.
The company said a series of large-scale DDoS attacks also targeted its colocation partner, Nine. Attack patterns kept changing, making mitigation difficult. The service was unavailable for about four hours Tuesday evening, followed by intermittent outages Wednesday morning. Normal operations were restored at 12:23 p.m. CEST.
“It is not entirely clear whether Threema was the primary target or whether the attacks were directed at multiple targets. In any case, they continued over an extended period and their patterns were constantly adapted, making them difficult to defend against.” continues the report. “As a result of these attacks, Threema was unavailable on Tuesday between 7:30 p.m. and 11:30 p.m. CEST. The page providing information on the current system status was initially not updated due to a technical issue unrelated to the attack. We therefore temporarily took it offline until the problem was resolved.”
Threema communicated the service disruptions progressively through social media, while Threema Work customers received updates by email. To strengthen its defenses, Threema deployed additional upstream DDoS protection on August 14, filtering malicious traffic before it reached its infrastructure.
The company also plans to improve its status page with an incident history and RSS feed, giving users and administrators another way to receive independent service updates.
“We will also expand the status page in the coming days. The update will include an incident history and an RSS feed that interested users and Threema Work administrators can subscribe to in order to receive system updates through an independent channel.” concludes the report. “We apologize for any inconvenience caused and appreciate your understanding.”
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, DDoS)
“Business customers using Threema Work were informed via email on Wednesday morning about the unstable service conditions, and account managers provided information on the current situation in response to inquiries.”
To avoid similar incidents, the Swiss company has implemented “specialized DDoS protection as an additional measure” to filter attack traffic upstream and reduce the load on its infrastructure.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/197353/hacking/ddos-attacks-cause-major-threema-outages.html