Threema Deploys New DDoS Defense After August 2026 Outages Disrupted Service
Large-scale DDoS attacks on the evening of August 11 cut off user access to the secure messaging app Threema, followed by a fresh wave of disruptions the following morning of August 12. According to Threema’s official statement, attackers targeted both the messenger’s own infrastructure and its server hosting partner, Nine, continuously varying the sources and characteristics of the malicious traffic. Developers have not yet determined whether Threema itself was the primary target or whether attackers were pursuing multiple targets simultaneously.
Timeline: Two Waves of Disruption
On August 11, the messenger remained unreachable from 19:30 to 23:30 Central European Summer Time. Attacks resumed the following morning on August 12 and intermittently disrupted service throughout the day. By 12:23, the team had restored normal operations, and no further disruptions were subsequently recorded.
The official status page initially failed to display incident information due to a separate technical issue unrelated to the DDoS attack itself. Threema temporarily took the page offline, resolved the underlying problem, and restored access. In the meantime, the team posted updates through social media. On the morning of August 12, the company sent emails to Threema Work enterprise customers regarding the service instability, and support staff responded directly to customer inquiries.
How the Attack Overwhelmed Threema’s Infrastructure
During a DDoS attack, attackers direct an enormous volume of requests toward an online service from numerous constantly shifting source addresses. This flood overwhelms the underlying infrastructure and prevents legitimate users from being served normally. The continuous rotation of attack sources and request patterns makes it impossible to mitigate the threat by simply blocking a single address, forcing defensive systems to continuously reconfigure their filtering rules in real time.
Availability Affected, Security Unaffected
Threema emphasized that the attacks impacted service availability but not the messenger’s underlying security. According to the company, attackers gained access to neither its internal systems nor any user data. The service regularly encounters DDoS attacks, and its defensive mechanisms typically filter out malicious traffic before any noticeable disruption occurs. The scale, duration, and constantly shifting tactics employed during the August campaign, however, made filtering considerably more difficult than usual.
Threema OnPrem customers were unaffected by the disruption. Organizations running the on-premises version deploy it on their own infrastructure, meaning client-hosted systems continued operating without interruption throughout the incident.
New DDoS Protection Deployed August 14
On August 14 at 18:05 CEST, Threema activated a supplementary, specialized DDoS protection system following final testing. The new mechanism filters attack traffic before it reaches Threema’s infrastructure, reducing the load placed on the company’s servers. Threema also committed to expanding its status page, adding an incident history and an RSS feed. Users and Threema Work administrators will be able to subscribe to updates and receive service status information through an independent communication channel going forward.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.