Threema, the privacy-focused Swiss messaging platform, suffered a series of large-scale distributed denial-of-service attacks earlier this week, leaving some users unable to send messages reliably and causing intermittent service disruptions across multiple regions.
The company initially believed the outage was related to a network problem affecting its colocation provider. However, further investigation revealed that both Threema and its infrastructure partner, Nine, were being hit by sustained DDoS attacks.
What made the incident particularly difficult to contain was not just the volume of malicious traffic, but the way the attackers continually changed their attack patterns to bypass mitigation measures.
Users Began Reporting Problems on Tuesday
The first reports appeared on Tuesday at around 6 PM UTC, when users started noticing that Threema was struggling to connect and messages were either delayed or failing to send.
At the time, Threema said the information available pointed toward a network outage involving its colocation partner.
That explanation initially appeared reasonable, especially after the infrastructure provider reported that its network problem had been resolved. Threema then began restoring affected services.
However, the situation was not completely over.
By the following day, users in countries including Switzerland, India and China were still reporting connectivity problems even though Threema's public status page appeared to show normal operations.
The company later confirmed that it was facing an ongoing series of DDoS attacks.
The Attacks Were Larger and More Persistent Than Usual
DDoS attacks work by overwhelming online infrastructure with enormous amounts of traffic, making legitimate requests difficult or impossible to process.
For established online services, these attacks are not unusual. Most major platforms deploy automated protection systems capable of identifying malicious traffic and filtering it before users notice anything.
Threema said it normally handles DDoS activity without visible disruption.
This particular incident was different.
The attacks were described as large-scale and prolonged, affecting both Threema itself and its colocation partner. The attackers also repeatedly changed their tactics, forcing mitigation systems and engineers to continually adapt.
That behaviour made it significantly harder to filter malicious traffic without disrupting legitimate users.
It Is Unclear Whether Threema Was the Main Target
One unanswered question is whether Threema itself was specifically targeted.
The company said the attacks affected both its infrastructure and its colocation provider, Nine, making it difficult to determine whether the messaging platform was the primary objective or simply one of several targets.
Whatever the motivation, the result was the same for users.
Threema became temporarily unavailable or only partially functional during parts of Tuesday evening and Wednesday morning.
For a messaging service built around reliability and privacy, even short periods of interrupted communications can quickly become noticeable.
Threema On-Prem Customers Were Not Affected
Interestingly, organisations using Threema On-Prem avoided the disruption entirely.
Unlike the standard hosted service, Threema On-Prem allows organisations to operate the messaging environment using their own infrastructure.
Because those deployments do not depend on Threema's public hosted systems in the same way, they were not affected by the attacks targeting the company's infrastructure.
That distinction highlights one of the advantages of self-hosted communication platforms for organisations that require greater control over availability and infrastructure.
It does, of course, shift more responsibility for security, maintenance and resilience to the organisation operating the system.
A Separate Issue Affected Threema's Status Page
The incident became slightly more confusing because Threema's system-status page was not always accurately reflecting what users were experiencing.
According to the company, this was caused by a separate technical problem unrelated to the DDoS attacks.
Rather than leave potentially incorrect information online, Threema temporarily took the status page offline while the issue was being resolved.
That explains why some users were still reporting outages while the official monitoring page appeared to suggest that everything was operating normally.
During major service disruptions, accurate status communication is almost as important as restoring the service itself, particularly for business customers trying to determine whether a problem is local or platform-wide.
Business Customers Were Updated Separately
Threema said customers using Threema Work were informed by email on Wednesday morning about the unstable service conditions.
Account managers were also available to respond to enquiries and provide information about the incident.
This was particularly important because Threema Work is designed for professional and organisational communication, where prolonged messaging disruptions can affect internal operations.
While consumer users may simply wait for service to return, businesses often need clearer information about expected availability and alternative communication options.
Threema Is Adding More Specialised DDoS Protection
Following the attacks, Threema has introduced additional protection intended to reduce the risk of similar disruptions.
The company says it has implemented specialised upstream DDoS filtering, allowing malicious traffic to be identified and removed before it reaches Threema's core infrastructure.
Upstream filtering can be especially useful during very large attacks because it prevents unwanted traffic from consuming network capacity before existing security systems have a chance to process it.
Rather than forcing Threema's own infrastructure to absorb the entire attack, the malicious traffic can be intercepted earlier in the network.
That should provide another layer of resilience if attackers attempt a similar campaign in the future.
Security Does Not Automatically Guarantee Availability
The incident also highlights an important difference between security, privacy and availability.
Threema is heavily focused on private communications and end-to-end encryption. The company also emphasises that it does not rely on advertising, user profiling or hidden data analysis.
Those protections are important, but encryption does not prevent a DDoS attack.
An attacker does not necessarily need to decrypt messages or compromise user accounts to cause disruption. They simply need to send enough unwanted traffic to overwhelm the infrastructure responsible for delivering those messages.
This means even highly secure communication systems still need strong network-level resilience.
Changing Attack Patterns Make DDoS Defence More Difficult
Modern DDoS attacks are also becoming more adaptive.
A basic attack may rely on one predictable traffic pattern that mitigation systems can quickly recognise and block.
More sophisticated attackers continually modify traffic sources, protocols and attack techniques as defenders respond.
That appears to have been one of the main difficulties Threema faced.
As mitigation rules were adjusted, the attackers changed their behaviour again.
This creates a moving target where security teams are constantly trying to distinguish legitimate traffic from newly modified attack traffic.
The longer that process continues, the greater the chance that users experience degraded performance or temporary outages.
Final Thoughts
Threema's recent disruption shows that even security-focused communication platforms are not immune to large-scale availability attacks.
The company appears to have been dealing with a particularly persistent DDoS campaign that repeatedly changed tactics while targeting infrastructure shared with its colocation provider.
Although Threema's encryption and privacy protections were not reported as compromised, the attacks were still able to interfere with users' ability to communicate.
The good news is that Threema has already added specialised upstream DDoS protection following the incident, which should strengthen its ability to absorb future attacks before they reach critical infrastructure.
For users, the episode is another reminder that secure messaging involves more than protecting message contents.
A truly resilient communication service also needs to remain available when someone is actively trying to knock it offline.


Comments 0