DDoS Attack Knocks Threema Messaging Service Offline for Hours

A large-scale DDoS attack disrupted Threema for hours, knocking hosted messaging offline as OnPrem deployments stayed online and attackers remained unknown.

Written By
LT
Liz Ticong
Aug 18, 2026
2 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Secure messaging service Threema was knocked offline for about four hours after a large-scale DDoS attack disrupted access to its hosted platform.

Service problems returned Wednesday morning before normal operations resumed later that day. Attackers kept changing traffic patterns during the campaign, making the incident harder to contain than the routine DDoS activity the provider usually handles without visible disruption.

Impact varied depending on how customers deployed the service.

OnPrem deployments stayed online

Hosted users experienced disruptions, but self-managed OnPrem installations continued operating on customer infrastructure.

Business customers using Threema Work received email notices Wednesday morning about unstable conditions, and account managers handled direct inquiries. Self-managed deployments remained available throughout the incident, according to the company’s incident report.

No evidence indicated attackers gained access to systems or user data. Encryption remained intact while the attack disrupted service availability.

Attack patterns kept changing as defenses adapted

Recurring DDoS attempts are common for Threema, with most causing little or no visible disruption. August’s campaign proved harder to contain because attacks continued for an extended period and traffic patterns changed repeatedly.

Service went fully offline Tuesday evening, and attacks returned Wednesday morning, causing shorter interruptions before normal operations resumed around midday.

A separate technical problem briefly prevented the status page from updating, forcing the company to use social channels for outage information.

After service stabilized, the company activated additional protection to filter malicious traffic upstream before it reached its infrastructure. These controls can help keep flood traffic from consuming network capacity and are commonly used as part of DDoS prevention and mitigation. Plans also call for an incident history and RSS feed on the status page.

Advertisement

Attackers remain unidentified after the outage

Responsibility for the campaign remains unknown. Nine, Threema’s colocation provider, was also targeted, so it remains unclear whether Threema was the primary target or one of several.

If encrypted messaging is part of your organization’s cyber incident response, maintain a second communication channel outside the same provider or infrastructure. Add the fallback to your incident response plan and test the switch before an outage forces staff to improvise.

Provider reviews should cover DDoS defenses and outage communications alongside encryption controls. Ask where filtering occurs and how administrators will receive alerts if primary status systems fail.

OnPrem’s uninterrupted service does not make self-hosting universally safer, but it does show how deployment architecture can change exposure during a provider outage.

More news: Nearly 40,000 SafePal customers had information exposed in a breach that could give scammers more convincing material for targeted attacks.

LT

Liz Ticong is a technology writer specializing in artificial intelligence, cybersecurity, software reviews, and emerging business technologies. With more than a decade of professional writing experience and over five years contributing technology content for TechnologyAdvice, she helps readers understand complex technologies and evaluate the tools that best fit their needs. Liz has extensive experience researching, testing, and analyzing software platforms, AI tools, and technology solutions. Her work includes in-depth software reviews, buyer’s guides, product comparisons, and technology news coverage designed to help businesses make informed purchasing and implementation decisions. She regularly evaluates AI applications, automation tools, cybersecurity solutions, and business software, providing practical insights based on hands-on testing and research. In addition to her work with TechnologyAdvice, Liz has contributed technology content to leading industry publications, including eWeek and TechRepublic. Her background in technical writing and software analysis enables her to translate complex technical concepts into clear, actionable guidance for both business and technology audiences. Liz holds a bachelor's degree in Broadcast Communication from the Polytechnic University of the Philippines and continues to expand her expertise through ongoing education in artificial intelligence and emerging technologies. Through her writing, she helps readers navigate a rapidly evolving technology landscape with practical, research-driven insights and real-world product analysis.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.