> Back to All Posts

Threema DDoS Attack Disrupts Secure Messaging for Two Days

Threema DDoS attack

Users of the Swiss messaging app Threema spent two days this week staring at messages that refused to send. Some watched the connection indicator flip between “Connecting” and “Connected.” Others gave up and moved to another app. Behind the confusion sat a sustained Threema DDoS attack against the company and its hosting partner.

A Two-Day Disruption With a Shifting Explanation

Trouble began on Tuesday at roughly 6 PM UTC. Messages stalled, and complaints piled up within minutes. About an hour later, the company pointed to a network outage on its colocation partner’s side. That explanation sounded routine, so few users suspected anything hostile.

Three hours after that, the partner reported the network problem fixed. Services began coming back, but the calm proved short. On Wednesday morning, users in Switzerland, India, and China still could not get the app to work properly. Only then did the full picture emerge.

The company confirmed a series of DDoS attacks and warned that intermittent outages would continue. The Threema DDoS attack left the service unavailable or partly available on Tuesday evening and Wednesday morning. Business customers on Threema Work received email notice, while account managers answered direct questions.

The Attack Hit the Hosting Partner Too

The traffic flood did not stop at one door. Nine, the colocation provider behind Threema’s infrastructure, absorbed the same DDoS attack traffic. Because both layers strained at once, recovery took far longer than a routine mitigation cycle. The company still cannot say for certain that it was the intended target.

The operators may have aimed at several customers of the same provider. That uncertainty matters, because motive shapes how a defender prepares for the next round. A grudge against one encrypted messenger calls for different planning than collateral damage from a broader campaign.

Why the Status Page Showed No Problems

One detail frustrated users more than the outage itself. Through Wednesday, the official status page reported normal service even as the Threema DDoS attack continued. A separate technical fault, unrelated to the flood, stopped the page from updating. The company then took it offline rather than leave stale information on display.

That gap created a second problem. People who could not send messages also could not confirm that anything was wrong. Many assumed their own network or phone had failed. Trust in a privacy service rests on clear communication during a crisis, so a frozen status page does real damage.

How a Threema DDoS Attack Overwhelms a Secure Network

A distributed denial-of-service attack wins through volume rather than cleverness. Attackers control a large network of hijacked devices, often home routers, cameras, and other weakly secured hardware. Those machines fire junk requests at the target all at once. Legitimate traffic then gets stuck behind the pile-up.

Most attacks of this kind never reach the public, because filtering systems spot the pattern and drop the bad packets. This one behaved differently. The operator changed tactics again and again, so every new rule bought only a short reprieve. The length of the Threema DDoS attack made mitigation harder still, since defenders had no quiet window.

Encryption Held While Availability Failed

Here is the part that matters most for privacy. A flood of traffic pushes packets at a server, and nothing more. It does not decrypt messages, expose contact lists, or plant code on a phone. End-to-end encryption held throughout, and nothing suggests that message content leaked.

Availability and confidentiality remain separate properties, though. Attackers who cannot read your messages can still stop you from sending them. For journalists, activists, and business teams that rely on one secure channel, forced silence carries a real cost.

Self-hosted deployments stayed online

Organizations running Threema OnPrem noticed nothing unusual during the DDoS attack. Their systems sit on their own hardware, far outside the traffic storm. That contrast says something useful about concentration risk in any hosted communication tool.

The Hidden Cost of Privacy-First Infrastructure

Threema built its reputation on Swiss servers, paid accounts, and no advertising or profiling. Owning the hardware gives the company genuine control over user data. But independence comes with a smaller defensive perimeter. Global platforms push traffic through vast scrubbing networks that swallow terabits per second.

A smaller privacy company cannot match that scale alone. So when a serious flood arrives, the gap in raw capacity shows at once. Following the Threema DDoS attack, the company added specialized upstream protection, which filters hostile traffic before it reaches its systems.

What Users Should Take From the Incident

First, agree on a fallback channel with the people you depend on. A second encrypted app costs nothing and removes a single point of failure. Second, treat a status page as one signal rather than proof. Community reports often surface an outage faster than the dashboard does.

Third, secure the hardware in your own home. Botnets of that kind grow from routers, cameras, and smart plugs left on default passwords. Firmware updates and strong credentials keep your devices out of the next attack fleet.

A VPN cannot restore a service that attackers have knocked offline. Still, it shields your traffic and your location from anyone watching the network around you. During an outage, that protection keeps your fallback channel private as well.

Final Thoughts

Encrypted messaging carries a quiet assumption that the service will simply be there. This week tested that assumption for two full days. The Threema DDoS attack never touched the encryption, yet it still cut people off from each other. Availability belongs in any honest picture of digital privacy.

The response looks reasonable overall, since upstream filtering addresses the exact weakness the attackers found. Communication during the outage needs more work, and the company knows it. For users, the practical answer stays simple: pick a service you trust, then keep a second door open.

Janet Andersen

Janet is an experienced content creator with a strong focus on cybersecurity and online privacy. With extensive experience in the field, she’s passionate about crafting in-depth reviews and guides that help readers make informed decisions about digital security tools. When she’s not managing the site, she loves staying on top of the latest trends in the digital world.