DDoS Attack Knocks Threema Messaging Service Offline for Hours

A large-scale DDoS attack disrupted Threema for hours, knocking hosted messaging offline as OnPrem deployments stayed online and attackers remained unknown.

執筆者
Liz Ticong
Liz Ticong
Aug 18, 2026
2 minute read
eSecurity Planet のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Secure messaging service Threema was knocked offline for about four hours after a large-scale DDoS attack disrupted access to its hosted platform.

Service problems returned Wednesday morning before normal operations resumed later that day. Attackers kept changing traffic patterns during the campaign, making the incident harder to contain than the routine DDoS activity the provider usually handles without visible disruption.

Impact varied depending on how customers deployed the service.

OnPrem deployments stayed online

Hosted users experienced disruptions, but self-managed OnPrem installations continued operating on customer infrastructure.

Business customers using Threema Work received email notices Wednesday morning about unstable conditions, and account managers handled direct inquiries. Self-managed deployments remained available throughout the incident, according to the company’s incident report.

No evidence indicated attackers gained access to systems or user data. Encryption remained intact while the attack disrupted service availability.

Attack patterns kept changing as defenses adapted

Recurring DDoS attempts are common for Threema, with most causing little or no visible disruption. August’s campaign proved harder to contain because attacks continued for an extended period and traffic patterns changed repeatedly.

Service went fully offline Tuesday evening, and attacks returned Wednesday morning, causing shorter interruptions before normal operations resumed around midday.

A separate technical problem briefly prevented the status page from updating, forcing the company to use social channels for outage information.

After service stabilized, the company activated additional protection to filter malicious traffic upstream before it reached its infrastructure. These controls can help keep flood traffic from consuming network capacity and are commonly used as part of DDoS prevention and mitigation. Plans also call for an incident history and RSS feed on the status page.

Advertisement

Attackers remain unidentified after the outage

Responsibility for the campaign remains unknown. Nine, Threema’s colocation provider, was also targeted, so it remains unclear whether Threema was the primary target or one of several.

If encrypted messaging is part of your organization’s cyber incident response, maintain a second communication channel outside the same provider or infrastructure. Add the fallback to your incident response plan and test the switch before an outage forces staff to improvise.

Provider reviews should cover DDoS defenses and outage communications alongside encryption controls. Ask where filtering occurs and how administrators will receive alerts if primary status systems fail.

OnPrem’s uninterrupted service does not make self-hosting universally safer, but it does show how deployment architecture can change exposure during a provider outage.

More news: Nearly 40,000 SafePal customers had information exposed in a breach that could give scammers more convincing material for targeted attacks.

Liz Ticong

Liz Ticong is a staff writer for eWeek and TechRepublic focused on AI, cybersecurity, enterprise software, and data. She has more than 10 years of editorial experience as a technology industry writer, combining reporting, product research, and hands-on software testing in her coverage. Her work has been published on Datamation, Enterprise Networking Planet, and TechnologyAdvice.com. She writes technology news, software reviews, product comparisons, and buyer’s guides for business and IT readers.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。