Large-scale DDoS attacks disrupted Threema secure messaging service

Threema’s Secure Messaging Service Disrupted by Large-Scale DDoS Attacks

In a worrying incident, the secure messaging service Threema was hit with a series of large-scale distributed denial-of-service (DDoS) attacks earlier this week. The attacks caused significant disruptions to communications for users worldwide, highlighting the vulnerability even of highly secure services to these types of threats.

Threema is a paid instant messaging application that prioritizes security and privacy above all else. It boasts robust end-to-end encryption and promises not to collect or sell user data. However, despite its strong security posture, Threema’s infrastructure was unable to withstand the sheer scale of the DDoS attacks. The company confirmed that it was being targeted by a series of attacks that made its service temporarily unavailable or only partially available on Tuesday evening and Wednesday morning.

The reason behind this weakness lies in the nature of DDoS attacks themselves. Typically, these types of attacks are mitigated quickly due to effective defenses that adapt to the attack’s patterns. However, the attacks targeting Threema were unusually large-scale and complex, with the threat actor continually changing its tactics to evade mitigation measures. This made it challenging for the company to defend against the attacks, even with specialized DDoS protection in place.

The attacks also targeted Threema’s colocation partner, Nine, suggesting that either Threema was the primary target or that multiple targets were being hit simultaneously. Regardless of the motivation behind these attacks, they demonstrate the potential vulnerability of secure services like Threema to large-scale DDoS attacks. The incident serves as a reminder that even with robust security measures in place, these types of threats can still cause significant disruptions.

The good news is that organizations using Threema On-Prem did not experience any issues due to this attack, as they rely on their own infrastructure. However, for users relying on the cloud-based version of the service, the incident highlights the importance of having robust DDoS protection in place to filter out malicious traffic and reduce the load on infrastructure.

As a result of these attacks, Threema has implemented additional measures to prevent similar incidents from occurring in the future. These include specialized DDoS protection that filters attack traffic upstream and reduces the load on its infrastructure. For users relying on secure messaging services like Threema, this incident serves as a timely reminder to ensure that their service providers have adequate defenses in place to mitigate these types of threats.

To stay ahead of the threat landscape, it’s essential for organizations and individuals alike to prioritize cybersecurity measures that include robust DDoS protection. This will help prevent disruptions to critical services like Threema’s secure messaging platform and ensure that communications remain uninterrupted even in the face of large-scale attacks.


Source: Bleeping Computer — 2026-08-16