Privacy-focused messaging platform Threema recently experienced a series of large-scale distributed denial-of-service (DDoS) attacks that temporarily affected service availability.
The disruption began on Tuesday evening and continued intermittently into Wednesday morning. Threema reported that its service was unavailable between 7:30 p.m. and 11:30 p.m. CEST on Tuesday. Users experienced additional short interruptions the following morning as the attack activity continued and changed in pattern.
By 12:23 p.m. CEST on Wednesday, Threema confirmed that its services had returned to normal.
How the DDoS Attack Affected Threema
A DDoS attack is designed to overwhelm an online service with a huge amount of traffic, making it difficult or impossible for legitimate users to access the platform.
These attacks typically come from many different sources rather than a single computer. Attackers may use compromised devices and systems across multiple networks to generate traffic, making the activity harder to block.
This also means security teams cannot simply block one malicious IP address and stop the attack. Attackers can constantly change their sources, traffic patterns, and request types, forcing defenders to continuously adjust their protection mechanisms.
Attack Patterns Kept Changing
According to Threema, the attack targeted both its own infrastructure and its colocation partner, Nine.
The company described the incident as a continuing wave of attacks with constantly changing patterns. This made mitigation more difficult because defensive controls had to distinguish malicious traffic from legitimate user requests.
It is still unclear whether Threema was the only organization targeted or whether the activity was part of a wider campaign.
User Data Was Not Compromised
Threema emphasized that the incident affected service availability rather than the security of user data.
A DDoS attack does not automatically give attackers access to messages, accounts, servers, or internal systems. Instead, the main objective is to consume network bandwidth, processing power, or other infrastructure resources until legitimate requests cannot be handled normally.
There is currently no indication that the incident compromised the confidentiality of Threema users’ data.
Status Page Also Experienced Issues
During the disruption, Threema’s public status page was also temporarily unavailable.
The company said this was caused by a separate technical issue and was not directly related to the DDoS attack. The status page was taken offline while that problem was addressed, which limited the availability of official outage information for part of the incident.
Threema instead provided updates through its social media channels and contacted Threema Work business customers by email. Account managers also responded to customer questions while the service experienced intermittent instability.
Threema OnPrem Customers Were Not Affected
Organizations using Threema OnPrem did not experience the same disruption.
This is because the OnPrem version runs on infrastructure managed by the customer rather than Threema’s hosted environment. As a result, those deployments remained operational while the hosted service was dealing with the attack.
Threema Adds Additional DDoS Protection
To strengthen its defenses, Threema deployed an additional specialized DDoS protection mechanism.
The new protection operates upstream, filtering malicious traffic before it reaches Threema’s core infrastructure. This reduces the amount of unwanted traffic reaching internal systems and adds another layer to the company’s existing defenses.
Threema confirmed that the additional upstream filtering mechanism was activated in its production environment on August 14, 2026, at 6:05 p.m. CEST.
More Outage Information Planned
Threema also plans to improve how it communicates during future service disruptions.
The company intends to expand its status page with an incident history and RSS feed, giving users and Threema Work administrators another way to receive service-status updates.
The incident highlights an important reality for online services: even platforms built around privacy and security must also maintain strong availability protections. Modern DDoS attacks can continuously change their behavior, making layered protection, upstream filtering, monitoring, and reliable incident communication essential for maintaining service availability.