
Multiple distributed denial-of-service (DDoS) attacks targeted secure messaging service Threema earlier this week, causing severe communications disruptions.
Organizations using Threema On-Prem have not had any issues because they rely on their own infrastructure.
In an autopsy Friday, the end-to-end encrypted instant messaging service said the attacks are difficult to defend against because the threat is constantly changing patterns.
Threema is a paid messaging app developed by the Swiss tech company of the same name with a strong focus on security and privacy.
The service relies on its own server infrastructure in various locations in Switzerland and promises “no ads, no profiling, no hidden data analytics.”
At around 18:00 UTC on Tuesday, users started reporting service outages. The company responded about an hour later, saying that based on information available at the time, the cause was “a network outage by our colocation partner.”
“Now Threema’s network status says ‘Connecting’ instead of ‘Connected’, well… 10 minutes later, now it says ‘Connected’ again, but messages still don’t send immediately and are very slow.” one user complained.
About three hours later, Threema said it was working to restore all of its services after its partner reported that the network problem had been resolved.
The next day, users in Switzerland, India and China continued to report that the service was down, although Threema’s status page showed no problems.
However, the company confirmed that it had been targeted by a series of DDoS attacks, which it is working to mitigate, and warned users that intermittent outages are likely to occur.
Threema explained that the attacks made its service “temporarily unavailable or only partially available on Tuesday evening and Wednesday morning”.
Typically, DDoS attacks are mitigated without noticeable impact due to effective defenses that adapt to attack patterns, – said Trima.
However, this week’s attacks were large-scale and targeted both Threema and its colocation partner, Nine.
“It is not entirely clear whether Threema was the primary target or whether the attacks were aimed at multiple targets,” the company notes.
Defending against the attacks proved challenging as they continued for an extended period of time as the threat constantly changed its tactics to circumvent mitigation measures.
An unrelated technical issue prevented the company from updating the system’s current status page, and the company has decided to take it offline until the issue is resolved.
“Business customers using Threema Work were informed by email on Wednesday morning of the unstable service conditions, and account managers provided information on the current situation in response to inquiries.”
To avoid such incidents, the Swiss company has implemented “dedicated DDoS protection as an additional measure” to filter upstream attack traffic and reduce the load on its infrastructure.
Generic prevention scores can hide what happens after initial access. Once attackers use valid credentials, prevention plummets.
The 2026 Blue Report measures security techniques by techniques in 338 million simulations run in customer production environments.

