
Encrypted messaging provider Threema says a series of large-scale distributed denial-of-service (DDoS) attacks disrupted its services this week, leaving users unable to connect for several hours on Tuesday and causing intermittent outages on Wednesday morning.
The company disclosed the incident today, explaining that the attacks targeted both Threema and its Swiss colocation partner, Nine. It remains unclear whether Threema was the primary target or one of several services affected.
According to Threema, the attacks began causing widespread disruption on Tuesday, when its service was unavailable between 7:30 p.m. and 11:30 p.m. CEST. The attacks resumed Wednesday morning and repeatedly changed their traffic sources and patterns, complicating mitigation efforts and causing shorter, intermittent service interruptions.
Normal operations were restored at 12:23 p.m. on Wednesday, and Threema says all services have remained fully operational since.
Threema is a Switzerland-based secure messaging provider known for its privacy-focused mobile apps and business communication products. Its services include the consumer Threema messenger, the enterprise-oriented Threema Work platform, and Threema OnPrem, which allows organizations to operate the messaging infrastructure within their own environments.
The company stressed that the incidents affected service availability rather than the security of its systems or user data. DDoS attacks attempt to overwhelm infrastructure by directing large volumes of requests or network traffic toward a target, preventing legitimate users from reaching the service. They do not, by themselves, provide attackers with access to internal systems or information.
Threema said the scale and continuously changing characteristics of this week's attacks made them more difficult to filter than the DDoS activity it routinely encounters. The company noted that attackers with significant technical and financial resources can rapidly alter attack methods to bypass defensive measures.
A separate technical issue also prevented Threema's status page from being updated correctly during the initial outage. The company temporarily disabled the page until that issue was resolved.
Customers using Threema Work were notified by email on Wednesday morning, while updates were also published through the company's social media channels. Threema OnPrem deployments were not affected because those customers operate their own infrastructure.
Following the attacks, Threema is adding specialized upstream DDoS protection to filter malicious traffic before it reaches its infrastructure. The protection was undergoing final stability testing at the time of the announcement.
Threema also plans to expand its status page to include an incident history and an RSS feed, giving users and administrators an independent way to monitor future service disruptions.







Leave a Reply