Secure messaging service Threema was knocked offline for about four hours after a large-scale DDoS attack disrupted access to its hosted platform.
Service problems returned Wednesday morning before normal operations resumed later that day. Attackers kept changing traffic patterns during the campaign, making the incident harder to contain than the routine DDoS activity the provider usually handles without visible disruption.
Impact varied depending on how customers deployed the service.
OnPrem deployments stayed online
Hosted users experienced disruptions, but self-managed OnPrem installations continued operating on customer infrastructure.
Business customers using Threema Work received email notices Wednesday morning about unstable conditions, and account managers handled direct inquiries. Self-managed deployments remained available throughout the incident, according to the company’s incident report.
No evidence indicated attackers gained access to systems or user data. Encryption remained intact while the attack disrupted service availability.
Attack patterns kept changing as defenses adapted
Recurring DDoS attempts are common for Threema, with most causing little or no visible disruption. August’s campaign proved harder to contain because attacks continued for an extended period and traffic patterns changed repeatedly.
Service went fully offline Tuesday evening, and attacks returned Wednesday morning, causing shorter interruptions before normal operations resumed around midday.
A separate technical problem briefly prevented the status page from updating, forcing the company to use social channels for outage information.
After service stabilized, the company activated additional protection to filter malicious traffic upstream before it reached its infrastructure. These controls can help keep flood traffic from consuming network capacity and are commonly used as part of DDoS prevention and mitigation. Plans also call for an incident history and RSS feed on the status page.
Attackers remain unidentified after the outage
Responsibility for the campaign remains unknown. Nine, Threema’s colocation provider, was also targeted, so it remains unclear whether Threema was the primary target or one of several.
If encrypted messaging is part of your organization’s cyber incident response, maintain a second communication channel outside the same provider or infrastructure. Add the fallback to your incident response plan and test the switch before an outage forces staff to improvise.
Provider reviews should cover DDoS defenses and outage communications alongside encryption controls. Ask where filtering occurs and how administrators will receive alerts if primary status systems fail.
OnPrem’s uninterrupted service does not make self-hosting universally safer, but it does show how deployment architecture can change exposure during a provider outage.
More news: Nearly 40,000 SafePal customers had information exposed in a breach that could give scammers more convincing material for targeted attacks.





