Threema Grapples with Persistent DDoS Attacks, Disrupting Encrypted Communications
The secure messaging service **Threema** recently faced a series of sophisticated distributed denial-of-service (DDoS) attacks, leading to significant service disruptions for its users. The attacks, characterized by constantly shifting patterns, challenged **Threema**'s robust mitigation strategies and highlighted the evolving threat landscape for privacy-focused platforms.

End-to-end encrypted messaging service **Threema** was hit by multiple distributed denial-of-service (DDoS) attacks earlier this week, causing widespread communication outages.
Organizations leveraging **Threema On-Prem** were unaffected, as their reliance on proprietary infrastructure insulated them from the public service disruptions.
### Evolving Attack Patterns Prove Challenging
In a post-mortem report, **Threema** acknowledged the difficulty in defending against the attacks, citing the threat actor's continuous alteration of attack patterns. This adaptive strategy made traditional DDoS mitigation more complex and less effective than usual.
**Threema**, developed by the Swiss technology company of the same name, is a paid messaging application renowned for its strong emphasis on security and privacy. The service operates its own server infrastructure across various locations in Switzerland, promising users "no ads, no profiling, no hidden data analyses."
### Initial Outages and User Reports
Service interruptions began on Tuesday around 6 PM UTC, with users quickly reporting issues. **Threema** initially attributed the problem to a "network outage on our colocation partnerβs side."
User complaints surfaced rapidly, with one **Reddit** user noting, "Now **Threema** network status saying βConnectingβ instead of βConnected,β welp... 10mins later, now it's back to saying βConnected,β yet msgs are still very much not sending right away & very delayed."
Approximately three hours later, **Threema** announced efforts to restore services after its partner reported the network issue resolved. However, the problems persisted.
### Confirmation of DDoS and Mitigation Efforts
By the following day, users in Switzerland, India, and China continued to experience service outages, despite the **Threema** status page indicating no issues. The company later confirmed it was indeed under a series of DDoS attacks and was actively working on mitigation, warning of intermittent outages.
**Threema** explained that the attacks rendered its service "temporarily unavailable or only partially available on Tuesday evening and Wednesday morning." Typically, such attacks are mitigated with minimal user impact due to adaptive defenses.
However, this week's attacks were large-scale, targeting both **Threema** and its colocation partner, **Nine**. The company stated, "It is not entirely clear whether **Threema** was the primary target or whether the attacks were directed at multiple targets."
### Communication Challenges and Future Safeguards
Defending against the persistent attacks was challenging due to their extended duration and the attacker's constant tactical shifts to bypass mitigation. An unrelated technical issue also prevented **Threema** from updating its system status page, leading to its temporary removal.
**Threema Work** business customers received email notifications about the unstable service conditions, with account managers providing updates on the situation.
To prevent similar incidents, the Swiss company has implemented "specialized DDoS protection as an additional measure." This new layer of defense is designed to filter attack traffic upstream, thereby reducing the load on **Threema**'s core infrastructure and enhancing service resilience.