Threema Deploys New DDoS Defense After August 2026 Outages Disrupted Service

Threema DDoS attack outage August 2026 encrypted messenger service disruption

Large-scale DDoS attacks on the evening of August 11 cut off user access to the secure messaging app Threema, followed by a fresh wave of disruptions the following morning of August 12. According to Threema’s official statement, attackers targeted both the messenger’s own infrastructure and its server hosting partner, Nine, continuously varying the sources and characteristics of the malicious traffic. Developers have not yet determined whether Threema itself was the primary target or whether attackers were pursuing multiple targets simultaneously.

Timeline: Two Waves of Disruption

On August 11, the messenger remained unreachable from 19:30 to 23:30 Central European Summer Time. Attacks resumed the following morning on August 12 and intermittently disrupted service throughout the day. By 12:23, the team had restored normal operations, and no further disruptions were subsequently recorded.

The official status page initially failed to display incident information due to a separate technical issue unrelated to the DDoS attack itself. Threema temporarily took the page offline, resolved the underlying problem, and restored access. In the meantime, the team posted updates through social media. On the morning of August 12, the company sent emails to Threema Work enterprise customers regarding the service instability, and support staff responded directly to customer inquiries.

How the Attack Overwhelmed Threema’s Infrastructure

During a DDoS attack, attackers direct an enormous volume of requests toward an online service from numerous constantly shifting source addresses. This flood overwhelms the underlying infrastructure and prevents legitimate users from being served normally. The continuous rotation of attack sources and request patterns makes it impossible to mitigate the threat by simply blocking a single address, forcing defensive systems to continuously reconfigure their filtering rules in real time.

Availability Affected, Security Unaffected

Threema emphasized that the attacks impacted service availability but not the messenger’s underlying security. According to the company, attackers gained access to neither its internal systems nor any user data. The service regularly encounters DDoS attacks, and its defensive mechanisms typically filter out malicious traffic before any noticeable disruption occurs. The scale, duration, and constantly shifting tactics employed during the August campaign, however, made filtering considerably more difficult than usual.

Threema OnPrem customers were unaffected by the disruption. Organizations running the on-premises version deploy it on their own infrastructure, meaning client-hosted systems continued operating without interruption throughout the incident.

New DDoS Protection Deployed August 14

On August 14 at 18:05 CEST, Threema activated a supplementary, specialized DDoS protection system following final testing. The new mechanism filters attack traffic before it reaches Threema’s infrastructure, reducing the load placed on the company’s servers. Threema also committed to expanding its status page, adding an incident history and an RSS feed. Users and Threema Work administrators will be able to subscribe to updates and receive service status information through an independent communication channel going forward.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply