A Threema DDoS attack disruption knocked the encrypted messaging service offline for much of Tuesday evening and into Wednesday morning this week, after a threat actor launched large-scale, sustained attacks that proved unusually difficult to defend against. In a post-mortem published on Friday, Threema confirmed the attacks had targeted both its own infrastructure and that of its colocation partner, Nine.

Timeline of the Threema DDoS attack disruption

Users started reporting service interruptions on Tuesday around 6 PM UTC. Threema initially responded about an hour later, pointing to what it described at the time as “a network outage on our colocation partner’s side.” According to SC Media, the service was down between 7:30 p.m. and 11:30 p.m. CEST on Tuesday, with intermittent interruptions resuming on Wednesday morning. Normal operations were not restored until 12:23 p.m. on Wednesday, meaning users were dealing with degraded or unavailable service across the better part of two days.

On the ground, the experience was predictably frustrating. “Now Threema network status saying ‘Connecting’ instead of ‘Connected,’ welp… 10mins later, now it’s back to saying ‘Connected,’ yet msgs are still very much not sending right away and very delayed,” one user wrote. By Wednesday, users in Switzerland, India, and China were reporting ongoing outages even as Threema’s status page showed no problems, an awkward situation the company later acknowledged was compounded by an unrelated technical fault that prevented it from updating that page at all.

Rather than leave a broken status page visible, Threema took it offline until the fault could be fixed. Business customers using Threema Work were informed by email on Wednesday morning about the unstable conditions, with account managers fielding individual inquiries.

Why the attacks were so hard to mitigate

Threema is candid about why its usual defences did not hold. Normally, DDoS attacks are absorbed without any noticeable impact, Threema said, because effective countermeasures adapt to attack patterns quickly enough that users never feel anything. These attacks were different. They were large-scale, persisted for an extended period, and the threat actor continually changed tactics to circumvent mitigation measures as fast as they were put in place.

The company also noted it is not entirely clear whether Threema was the primary target, or whether the attacks were aimed at multiple targets through Nine simultaneously. That ambiguity complicates attribution and makes the pattern-shifting behaviour harder to interpret: was the attacker laser-focused on Threema, or simply sweeping through infrastructure and adapting opportunistically?

Organisations running Threema On-Prem came through unaffected, because those deployments rely on their own infrastructure rather than Threema’s central servers. Threema operates its server infrastructure across various locations in Switzerland and describes itself as offering “no ads, no profiling, no hidden data analyses.”

What Threema is doing differently now

The company has already moved to shore up its defences. Specialised DDoS protection has been implemented as an additional layer to filter attack traffic upstream and reduce the load on Threema’s own infrastructure. According to Cybersecurity News, Threema confirmed on 14 August 2026 at 6:05 p.m. CEST that this upstream filtering protection had been activated in its production environment, a concrete timestamp that suggests the company moved quickly once the immediate crisis passed.

Longer term, Threema is also rethinking how it communicates during incidents. Cyber Insider reports that the company plans to expand its status page to include an incident history and an RSS feed, giving users and administrators an independent way to monitor future service disruptions. That is a direct response to the uncomfortable episode this week, where the status page was both technically broken and actively misleading users about the state of the network.

The RSS feed detail is worth noting for Threema’s audience. Security-conscious users and IT administrators running Threema Work deployments tend to be exactly the kind of people who would subscribe to a machine-readable status feed rather than polling a web page manually. Whether the expanded status tooling arrives before the next incident is the more pressing question.

Share.

Software engineer and video game uber-nerd.

Comments are closed.

Exit mobile version