Cyber Security News

Threema Secure Messaging Service Hit by Massive DDoS Attack

Threema, a privacy-focused secure messaging service, was hit by a series of large-scale distributed denial-of-service (DDoS attacks) that temporarily disrupted access for users.

The incidents affected the platform on Tuesday evening and continued intermittently through Wednesday morning before normal operations were restored. According to Threema, the service was unavailable between 7:30 p.m. and 11:30 p.m. CEST on Tuesday.

Users also experienced short, intermittent disruptions on Wednesday morning as the attacks continued and shifted in pattern. Threema confirmed that all services had returned to normal operation by 12:23 p.m. CEST.

A distributed denial-of-service attack, commonly known as a DDoS attack, attempts to make an online service unavailable by overwhelming its infrastructure with a very high volume of traffic.

Unlike a conventional attack launched from a single system, DDoS operations use many sources, often including compromised devices spread across different networks and locations. This distributed approach makes mitigation more difficult.

Security teams cannot simply block a single malicious IP address because attackers can rapidly change traffic sources, request types, and attack patterns. The result is often a continuous contest between defenders adapting their filtering controls and attackers modifying their methods.

Threema Hit by Massive DDoS Attack

Threema said the attacks targeted both its infrastructure and its colocation partner, Nine. It remains unclear whether Threema was the sole intended target or whether the activity was part of a broader campaign against multiple organizations.

The company described the incident as an ongoing wave of attacks with constantly changing patterns, making it more challenging to block without affecting legitimate users.

Importantly, Threema stressed that the attacks affected service availability rather than the confidentiality or security of user data. A DDoS attack does not inherently provide attackers with access to servers, messages, account data, or internal systems.

Its purpose is to consume network bandwidth, processing capacity, or other infrastructure resources until valid user requests can no longer be handled reliably.

The incident also affected Threema’s public status page. The company said the page was initially not updated because of a separate technical issue unrelated to the DDoS activity.

The status page was temporarily taken offline until that issue was resolved, limiting the availability of official outage information during part of the incident.

Threema communicated updates through its social media channels and notified Threema Work business customers by email on Wednesday morning. Account managers also responded to customer inquiries as the service instability continued.

Organizations using Threema OnPrem were not affected. The OnPrem product operates on customer-managed infrastructure, meaning those deployments remained available while Threema’s hosted service was under attack.

In response to the incident, Threema implemented an additional specialized DDoS protection mechanism. The new control filters malicious traffic upstream before it reaches Threema’s core infrastructure, reducing the burden on internal systems and existing defensive layers.

The company confirmed on August 14, 2026, at 6:05 p.m. CEST that the upstream filtering protection had been activated in its production environment.

Threema also plans to expand its status page with incident history and an RSS feed. This would provide users and Threema Work administrators with an independent channel to receive system status alerts during future outages.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

16 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

16 hours ago