Multiple distributed denial-of-service (DDoS) attacks disrupted Threema, the end-to-end encrypted messaging service, earlier this week and caused significant delays and interruptions for users.
Organizations using Threema On-Prem were not affected because the service operates on their own infrastructure.
In an after-action report published Friday, Threema said the attacks were particularly difficult to mitigate because the threat actors repeatedly changed their tactics and attack patterns.
Threema is a paid messaging application developed by Swiss technology company Threema GmbH. The platform focuses on privacy and security, including end-to-end encryption for messages and calls.
The company operates its own server infrastructure across several locations in Switzerland and promises users “no advertising, no profiling, and no hidden data analysis.”
Users began reporting Threema service interruptions at approximately 6 p.m. UTC on Tuesday. About an hour later, the company said the disruption appeared to be caused by “a network failure on the part of the colocation partner.”
“Currently, the Threema network status says ‘Connecting’ instead of ‘Connected.’ Well… 10 minutes later it says ‘Connected’ again, but messages still aren’t sent right away and are very delayed,” one user reported.
Approximately three hours later, Threema said it was working to restore all services after its partners reported that the network issue had been resolved.
Despite the apparent recovery, users in Switzerland, India, and China continued to report outages the following day, even though Threema’s status page showed no active problems.
The company later confirmed that it had been targeted by a series of DDoS attacks and warned that users could continue to experience intermittent service disruptions while mitigation efforts were underway.
Threema said the attacks left its services “temporarily unavailable or only partially available on Tuesday night and Wednesday morning.”
Effective DDoS protection typically identifies and blocks malicious traffic with limited impact on legitimate users. However, Threema said this incident was unusually difficult to contain.
The large-scale attacks targeted both Threema and its colocation provider, Nine.
“It is not entirely clear whether Threema was the primary target or whether the attack was directed at multiple targets,” the company said.
The attacks were difficult to defend against because they continued for an extended period while the attackers constantly modified their methods to bypass mitigation measures.
Threema also said it was unable to update its system status page because of an unrelated technical issue. The company took the page offline until that problem can be resolved.
Business customers using Threema Work were notified by email about the unstable service on Wednesday morning. Account managers also provided additional information in response to customer inquiries.
To reduce the risk of similar disruptions, Threema has deployed “specialized DDoS protection as an additional measure.” The technology is designed to filter attack traffic upstream and reduce the load placed on the company’s network infrastructure.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




