Threema, a privacy-focused secure messaging service, was hit by a series of large-scale distributed denial-of-service (DDoS attacks) that temporarily disrupted access for users.
The incidents affected the platform on Tuesday evening and continued intermittently through Wednesday morning before normal operations were restored. According to Threema, the service was unavailable between 7:30 p.m. and 11:30 p.m. CEST on Tuesday.
Users also experienced short, intermittent disruptions on Wednesday morning as the attacks continued and shifted in pattern. Threema confirmed that all services had returned to normal operation by 12:23 p.m. CEST.
A distributed denial-of-service attack, commonly known as a DDoS attack, attempts to make an online service unavailable by overwhelming its infrastructure with a very high volume of traffic.
Unlike a conventional attack launched from a single system, DDoS operations use many sources, often including compromised devices spread across different networks and locations. This distributed approach makes mitigation more difficult.
Security teams cannot simply block a single malicious IP address because attackers can rapidly change traffic sources, request types, and attack patterns. The result is often a continuous contest between defenders adapting their filtering controls and attackers modifying their methods.
Threema Hit by Massive DDoS Attack
Threema said the attacks targeted both its infrastructure and its colocation partner, Nine. It remains unclear whether Threema was the sole intended target or whether the activity was part of a broader campaign against multiple organizations.
The company described the incident as an ongoing wave of attacks with constantly changing patterns, making it more challenging to block without affecting legitimate users.
Importantly, Threema stressed that the attacks affected service availability rather than the confidentiality or security of user data. A DDoS attack does not inherently provide attackers with access to servers, messages, account data, or internal systems.
Its purpose is to consume network bandwidth, processing capacity, or other infrastructure resources until valid user requests can no longer be handled reliably.
The incident also affected Threema’s public status page. The company said the page was initially not updated because of a separate technical issue unrelated to the DDoS activity.
The status page was temporarily taken offline until that issue was resolved, limiting the availability of official outage information during part of the incident.
Threema communicated updates through its social media channels and notified Threema Work business customers by email on Wednesday morning. Account managers also responded to customer inquiries as the service instability continued.
Organizations using Threema OnPrem were not affected. The OnPrem product operates on customer-managed infrastructure, meaning those deployments remained available while Threema’s hosted service was under attack.
In response to the incident, Threema implemented an additional specialized DDoS protection mechanism. The new control filters malicious traffic upstream before it reaches Threema’s core infrastructure, reducing the burden on internal systems and existing defensive layers.
The company confirmed on August 14, 2026, at 6:05 p.m. CEST that the upstream filtering protection had been activated in its production environment.
Threema also plans to expand its status page with incident history and an RSS feed. This would provide users and Threema Work administrators with an independent channel to receive system status alerts during future outages.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

