SendTech Times
News
MARKET SIGNAL:

Threema DDoS Attacks Expose Hosted Messaging Availability Gap

Newsroom brief

Large DDoS attacks disrupted Threema’s hosted messaging service while On-Prem customers avoided the outage, prompting the company to add upstream DDoS filtering.

Verified against source materialEdited by SendTech Times Cybersecurity DeskSource: BleepingComputer
Threema DDoS Attacks Expose Hosted Messaging Availability Gap

Threema's secure messaging network spent part of Tuesday evening and Wednesday morning under large distributed denial-of-service attacks, BleepingComputer reported, exposing a resilience split between the hosted service and Threema On-Prem deployments that run on customer infrastructure.

The Swiss privacy-focused messaging provider initially treated user reports at about 6 PM UTC on Tuesday as a colocation-partner network outage.

Roughly an hour later, the company pointed to the partner issue as the apparent cause, but users continued to report delayed or stalled messages after the partner said the network fault had been resolved.

Hosted Service Took The Disruption

The attacks made Threema temporarily unavailable or only partly available across the hosted network.

Users in Switzerland, India and China continued to report service problems the next day, while the public status page showed no fault because a separate technical issue prevented the company from updating it.

Threema On-Prem customers avoided the incident because those deployments rely on their own infrastructure rather than Threema's hosted systems.

That split gives business customers a practical distinction: the same messaging product can carry different outage exposure depending on whether the organization depends on the vendor-operated network or runs the service inside its own environment.

The company later confirmed a series of DDoS attacks and warned that intermittent outages could continue while mitigation work proceeded.

Large traffic floods are normally absorbed by adaptive defenses before users notice them, but this campaign persisted and changed its patterns as defenders adjusted.

Changing Attack Patterns Complicated Mitigation

The traffic targeted both Threema and its colocation partner, Nine.

Threema did not establish whether it was the primary target or whether the flood covered multiple targets, leaving the exact objective unresolved even though the operational effect was clear.

The incident also created a communications problem for enterprise customers.

Business users of Threema Work received email updates on Wednesday morning about unstable service conditions, and account managers handled customer inquiries while public status information remained unavailable.

Threema has now added specialized upstream DDoS protection designed to filter hostile traffic before it reaches its infrastructure.

For security teams, the incident is less about message encryption and more about service availability: end-to-end encrypted platforms still need network-layer capacity and status-page reliability when traffic attacks move faster than ordinary mitigation patterns.

Share this article
inXf

Related articles

More
Kratos Takedown Leaves Microsoft 365 Session-Theft Risk Unfinished
Cybersecurity

Kratos Takedown Leaves Microsoft 365 Session-Theft Risk Unfinished

German and US law enforcement took more than 200 Kratos phishing-kit servers offline, but investigators still tie the service to roughly 1,800 customers and session-theft attacks against Microsoft 365.

Calix Router Flaw Exposes Home Devices To Public Internet
Cybersecurity

Calix Router Flaw Exposes Home Devices To Public Internet

An unpatched Calix GS7 XGS router flaw lets unauthenticated attackers create port-forwarding rules that can expose devices inside broadband customers' home networks.

Hugging Face Says AI Agent Drove Production Infrastructure Intrusion
Cybersecurity

Hugging Face Says AI Agent Drove Production Infrastructure Intrusion

Hugging Face said an autonomous AI agent system drove an intrusion into part of its production infrastructure, reaching internal datasets and service credentials. The company said public models, datasets and Spaces were not tampered with, while its assessment of partner or customer data remains unfinished.

ZBT Router Firmware Implants Expose Root-Level Control Risk
Cybersecurity

ZBT Router Firmware Implants Expose Root-Level Control Risk

VulnCheck found three backdoor-like implants in ZBT-made or white-label routers, including 203 exposed DARKLANTERN instances across 22 countries and sinkhole traffic from 392 devices.

Manchester Airports Group Breach Exposes Data On 8.7 Million Travellers
Cybersecurity

Manchester Airports Group Breach Exposes Data On 8.7 Million Travellers

Manchester Airports Group disclosed that personal data linked to about 8.7 million people was stolen from systems tied to airport parking, lounge, Fast Track and Wi-Fi services, while core airport operations continued.

UK Energy Cyberattack Shut Small Generator For Four Days
Cybersecurity

UK Energy Cyberattack Shut Small Generator For Four Days

A small U.K. energy generator was shut for four days after a July cyberattack linked to Iran, while officials said the wider power system was not at risk.

GitHub Outage Hit Actions And Enterprise Login Paths In Global Disruption
Cybersecurity

GitHub Outage Hit Actions And Enterprise Login Paths In Global Disruption

DigiconAsia reported that GitHub’s August 17 outage affected repositories, Actions, API traffic, archive downloads and enterprise identity tools, with Microsoft confirming worldwide platform issues.

Azure Tenant Data Claims Put Fortune 500 Directories In Focus
Cybersecurity

Azure Tenant Data Claims Put Fortune 500 Directories In Focus

SecurityWeek reported that TheHatman is selling millions of records allegedly taken from Azure and Entra tenants, while Hudson Rock tied the likely access path to stolen credentials.

Keep Reading

More Stories

Latest
The Loop X Opens Flagship Store Built Around Hands-On Device TestingDevices & Consumer TechOct 6, 2026The Loop X Opens Flagship Store Built Around Hands-On Device TestingThe Loop X opened its first flagship store at SM North EDSA The Annex, combining phones, laptops, wearables, accessories, experience zones and an in-store matcha bar.Ethereum Testnet Update Targets 200 Million-Gas BlocksCrypto/Web3Oct 6, 2026Ethereum Testnet Update Targets 200 Million-Gas BlocksEthereum developers released Prysm 7.2.1 so the Sepolia trial of Glamsterdam can test 200 million-gas blocks, more than three times the prior 60 million setting, before any main-network change.Kepler Targets 2027 Production for HBM Replacement MemoryCloud & Data CentersOct 6, 2026Kepler Targets 2027 Production for HBM Replacement MemoryEE Times reports that Kepler Computing is preparing 3D ferroelectric memory for 2027 production, promising higher capacity and bandwidth per watt while limiting reliance on advanced-node lithography.Yokogawa Opens Singapore Hub For Industrial Cyber ResilienceCapital & PolicyOct 6, 2026Yokogawa Opens Singapore Hub For Industrial Cyber ResilienceYokogawa Engineering Asia has launched a Singapore center focused on OT cyber resilience, training, response planning and recovery coordination for Southeast Asia, Oceania and Taiwan.ClickFix Attack Uses Browser Cache To Hide Malware PayloadCybersecurityOct 6, 2026ClickFix Attack Uses Browser Cache To Hide Malware PayloadMicrosoft Threat Intelligence traced a ClickFix cache-smuggling method that preloads malware into browser caches, then uses file size checks and a pasted Run command to launch later credential-theft stages.VOA Tests Six-Month Startup Buildout Before Funding DecisionsFintech & Digital PaymentsOct 6, 2026VOA Tests Six-Month Startup Buildout Before Funding DecisionsTechCabal’s interview with VOA Venture Partners founder Victoria Olayide Adesanya describes a six-month build programme that lets the firm work inside African financial-infrastructure startups before deciding whether to invest.Bitcoin Holds $86,000 As Dollar Index Hits 18-Month HighCrypto/Web3Oct 6, 2026Bitcoin Holds $86,000 As Dollar Index Hits 18-Month HighCoinDesk reported that bitcoin stayed near $86,000 while the U.S. Dollar Index reached about 102.5, with U.S. rate expectations and European political risks strengthening the dollar backdrop.Google Freezes OSS Bug Bounty Reports After AI Submission FloodCybersecurityOct 6, 2026Google Freezes OSS Bug Bounty Reports After AI Submission FloodGoogle has stopped accepting new product vulnerability reports in its OSS VRP after invalid automated submissions swamped reviewers, while older reports and some Cloud VRP routes remain open.Fleuret AI Raises €4M For Continuous AI Pentesting PlatformCybersecurityOct 6, 2026Fleuret AI Raises €4M For Continuous AI Pentesting PlatformTech.eu reported that French startup Fleuret AI raised €4 million in pre-seed funding to develop an agentic-AI platform that turns penetration testing into a continuous security process.GFT Analysis Says AI Documentation Can Cut Maintenance Work 30%Fintech & Digital PaymentsOct 6, 2026GFT Analysis Says AI Documentation Can Cut Maintenance Work 30%A GFT Technologies analysis says AI-linked software documentation can cut maintenance effort and speed developer onboarding when knowledge assets stay synchronized with code changes.Schneider Electric Lines Up $22.6 Billion PTC DealAIOct 5, 2026Schneider Electric Lines Up $22.6 Billion PTC DealSchneider Electric plans to buy PTC in a cash transaction valuing the US engineering software provider’s equity at about $22.6 billion, adding product-lifecycle software to its industrial AI push.Aggarwal Pledges Ola Electric Stake To Fund ₹1,000 Cr Rights IssueCapital & PolicyOct 5, 2026Aggarwal Pledges Ola Electric Stake To Fund ₹1,000 Cr Rights IssueOla Electric founder Bhavish Aggarwal pledged 20 Cr shares to finance his participation in a rights issue that forms part of a larger ₹1,500 Cr fundraising plan.