Large-scale DDoS attacks have left the secure messaging service Threema in disarray, causing widespread disruptions to communications for its users. The attacks, which targeted both Threema and its colocation partner Nine, were particularly challenging to defend against due to their sheer scale and the threat actor’s adaptability.
Threema, a paid messaging application with a focus on security and privacy, allows users to send end-to-end encrypted messages without any ads, profiling, or data analysis. However, earlier this week, users started reporting service interruptions, which were initially blamed on a network outage at Threema’s colocation partner’s facility. But as the situation unfolded, it became clear that something more sinister was at play.
DDoS attacks, or distributed denial-of-service attacks, occur when an attacker floods a website or online service with traffic from multiple sources, making it difficult for legitimate users to access the site. Threema acknowledged that its services were being targeted by such an attack, which made its service “temporarily unavailable or only partially available” on Tuesday evening and Wednesday morning.
The attacks were particularly large-scale, and the threat actor’s tactics changed frequently to evade mitigation measures. This adaptability made it challenging for Threema to defend against the attacks. The company noted that it was not entirely clear whether Threema was the primary target or if multiple targets were being attacked simultaneously.
Fortunately, organizations using Threema On-Prem did not experience any issues, as they rely on their own infrastructure and are therefore less vulnerable to such attacks. However, for other users, the disruptions caused by these DDoS attacks were significant. Threema’s status page was initially incorrect, showing no problems despite ongoing outages.
To mitigate similar incidents in the future, Threema has implemented “specialized DDoS protection as an additional measure” to filter attack traffic upstream and reduce the load on its infrastructure. This move demonstrates the company’s commitment to protecting its users’ communications from such threats.
For readers who rely on secure messaging services like Threema, this incident serves as a reminder of the importance of staying vigilant against DDoS attacks. While these attacks may be difficult to defend against, being proactive and investing in robust security measures can help minimize their impact.
Source: Bleeping Computer — 2026-08-16