Threema Suffers Major DDoS Attack, Service Restored

Threema, the Swiss-based secure messaging service, recently experienced a significant distributed denial-of-service (DDoS) attack that temporarily disrupted user access. The attack commenced on Tuesday evening, causing service outages between 7:30 p.m. and 11:30 p.m. Central European Summer Time (CEST). Intermittent disruptions continued into Wednesday morning, with full service restoration achieved by 12:23 p.m. CEST.

DDoS attacks aim to overwhelm online services by flooding them with excessive traffic from multiple sources, often utilizing compromised devices across various networks. This distributed nature complicates mitigation efforts, as attackers can rapidly alter traffic patterns and sources, challenging defenders to adapt their filtering strategies continuously.

Threema reported that the attacks targeted both its infrastructure and that of its colocation partner, Nine. It remains uncertain whether Threema was the sole target or part of a broader campaign. The company described the incident as a series of attacks with evolving patterns, making it difficult to block malicious traffic without affecting legitimate users.

Importantly, Threema emphasized that the attacks impacted service availability but did not compromise user data confidentiality or security. DDoS attacks typically aim to exhaust network resources, preventing legitimate user requests from being processed, without granting attackers access to internal systems or data.

The incident also affected Threema’s public status page, which was temporarily taken offline due to a separate technical issue unrelated to the DDoS attack. During this period, Threema communicated updates through its social media channels and notified Threema Work business customers via email. Organizations using Threema OnPrem, which operates on customer-managed infrastructure, were not affected by the attack.

In response to the incident, Threema implemented an additional specialized DDoS protection mechanism. This new control filters malicious traffic upstream before it reaches Threema’s core infrastructure, reducing the burden on internal systems and existing defensive layers. The company confirmed that this upstream filtering protection was activated in its production environment on August 14, 2026, at 6:05 p.m. CEST.

Threema also plans to enhance its status page by adding incident history and an RSS feed, providing users and Threema Work administrators with an independent channel for system status alerts during future outages.

This incident underscores the persistent threat posed by DDoS attacks to online services, including those emphasizing security and privacy. It highlights the importance of robust, adaptive defense mechanisms and transparent communication channels to maintain user trust and service reliability.