Threema DDoS Attacks Expose Hosted Messaging Availability Gap
Large DDoS attacks disrupted Threema’s hosted messaging service while On-Prem customers avoided the outage, prompting the company to add upstream DDoS filtering.

Threema's secure messaging network spent part of Tuesday evening and Wednesday morning under large distributed denial-of-service attacks, BleepingComputer reported, exposing a resilience split between the hosted service and Threema On-Prem deployments that run on customer infrastructure.
The Swiss privacy-focused messaging provider initially treated user reports at about 6 PM UTC on Tuesday as a colocation-partner network outage.
Roughly an hour later, the company pointed to the partner issue as the apparent cause, but users continued to report delayed or stalled messages after the partner said the network fault had been resolved.
Hosted Service Took The Disruption
The attacks made Threema temporarily unavailable or only partly available across the hosted network.
Users in Switzerland, India and China continued to report service problems the next day, while the public status page showed no fault because a separate technical issue prevented the company from updating it.
Threema On-Prem customers avoided the incident because those deployments rely on their own infrastructure rather than Threema's hosted systems.
That split gives business customers a practical distinction: the same messaging product can carry different outage exposure depending on whether the organization depends on the vendor-operated network or runs the service inside its own environment.
The company later confirmed a series of DDoS attacks and warned that intermittent outages could continue while mitigation work proceeded.
Large traffic floods are normally absorbed by adaptive defenses before users notice them, but this campaign persisted and changed its patterns as defenders adjusted.
Changing Attack Patterns Complicated Mitigation
The traffic targeted both Threema and its colocation partner, Nine.
Threema did not establish whether it was the primary target or whether the flood covered multiple targets, leaving the exact objective unresolved even though the operational effect was clear.
The incident also created a communications problem for enterprise customers.
Business users of Threema Work received email updates on Wednesday morning about unstable service conditions, and account managers handled customer inquiries while public status information remained unavailable.
Threema has now added specialized upstream DDoS protection designed to filter hostile traffic before it reaches its infrastructure.
For security teams, the incident is less about message encryption and more about service availability: end-to-end encrypted platforms still need network-layer capacity and status-page reliability when traffic attacks move faster than ordinary mitigation patterns.




















