Skip to main content
Emerging ThreatsMalware & Ransomware

DDoS Attacks Disrupt Threema Secure Messaging Service

Server room with rows of computer servers and networking equipment, slightly blurred with loose cables, indicating…

"a network outage on our colocation partner’s side." That was Threema’s initial explanation on Tuesday evening as users began reporting interruptions to the Swiss secure-messaging service — an early assessment that the company later revised after a more detailed post‑mortem made clear the disruptions were the result of large-scale distributed denial-of-service (DDoS) attacks.

Timeline: Tuesday evening through Wednesday morning

Problems began on Tuesday around 18:00 UTC, when users flagged interruptions. About an hour later Threema attributed the issue to “a network outage on our colocation partner’s side.” Roughly three hours after users first reported trouble, the company said it was working to restore services after the colocation partner reported the network issue resolved. Nevertheless, the next day users in Switzerland, India, and China continued to report outages even though Threema’s status page showed no problems. Threema subsequently confirmed a series of DDoS attacks and warned that intermittent outages were likely to continue.

Attack characteristics: large-scale, persistent, and adaptive

Threema described the incidents as large-scale DDoS attacks that affected both its own infrastructure and that of its colocation partner, Nine. The company said the attacks were difficult to defend against because the threat actor persisted for an extended period and continuously changed tactics to try to circumvent mitigation measures. Threema noted that it was “not entirely clear whether Threema was the primary target or whether the attacks were directed at multiple targets.”

Operational impact: who was affected and who was not

The interruptions impacted users of Threema’s hosted service, producing delayed or failed message delivery for many. Organizations using Threema On‑Prem — the product running on customers’ own infrastructure — reported no issues because those deployments do not rely on Threema’s public servers. Business customers using Threema Work were notified via email on Wednesday morning about the unstable service conditions, and account managers provided additional information in response to inquiries.

Company response: status page, mitigation, and new protections

Threema said it attempted to keep users informed but encountered an unrelated technical issue that prevented updates to its system status page; the company decided to take the status page offline until the problem could be fixed. To reduce the chance of a repeat, Threema implemented “specialized DDoS protection as an additional measure” to filter attack traffic upstream and reduce load on its infrastructure. The company contrasted these events with the normal outcome for many DDoS attempts, noting that typical mitigation often prevents noticeable disruption because defenses can adapt to attack patterns — a capability that was repeatedly challenged in this incident.

What this means for technologists, business customers, and end users

  • Technologists and security teams: The adaptive behavior of the attacker and the sustained duration of the campaign underline the need for layered defenses and upstream filtering; Threema’s decision to add specialized DDoS protection reflects an operational response to attacks that evolve faster than in-line mitigations can adapt.
  • Business customers using Threema Work and On‑Prem administrators: Those on On‑Prem deployments were insulated from the outage, while Work customers were notified directly by email and account managers; the incident highlights the divergence in resilience between self‑hosted and provider‑hosted deployments.
  • End users in affected regions (Switzerland, India, China): Intermittent outages and delayed message delivery were reported even when status indicators showed nominal service, demonstrating how observable user impact can lag or differ from official status displays when mitigation is ongoing or when status reporting itself is impaired.

Threema’s account of the event offers a compact but concrete record: an initially misattributed network outage, a later confirmation of a campaign of adaptive, large-scale DDoS attacks affecting both Threema and its colocation partner, and an operational shift toward upstream filtering to reduce future load. The company has left open the question of whether it was the primary target — a distinction that matters for attribution and for any long‑term hardening strategy. For now, Threema’s immediate priority has been restoring reliable delivery and introducing protections designed to blunt attacks that change tactics mid‑stream.

Original report