Published · 6d agoSecurity3 min read
Threema went dark for hours. The only users who kept messaging ran it themselves
Large-scale DDoS attacks took the Swiss encrypted messenger offline on Tuesday evening and again Wednesday morning. Customers on Threema On-Prem, running their own infrastructure, saw nothing.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Multiple large-scale DDoS attacks targeted Threema, causing severe disruption to its secure messaging service.
- Threema said the attacks made its service temporarily unavailable or only partially available on Tuesday evening and Wednesday morning.
- Organizations using Threema On-Prem did not experience any issues because those deployments run on their own infrastructure.
- On Tuesday around 6 PM UTC, users started reporting service interruptions.
- Threema responded about an hour after the first user reports, saying that based on the information available at the time the cause was 'a network outage on our colocation partner's side'.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Threema, the paid Swiss end-to-end encrypted messenger, was made unavailable or only partially available by a series of large-scale DDoS attacks across Tuesday evening and Wednesday morning [1][2]. Organisations running Threema On-Prem experienced no issues, because those deployments sit on infrastructure the customer controls [3].
The sequence is worth reading closely. Users began reporting interruptions on Tuesday at around 6 PM UTC [4], and the company answered about an hour later saying the cause was, on the information then available, "a network outage on our colocation partner's side" [5]. Roughly three hours after that, Threema said it was restoring services after the partner reported the network problem resolved [6]. In its post-mortem, published Friday [7], the company dated the outage to Tuesday between 7:30 PM and 11:30 PM CEST [8], about four hours [9], followed by intermittent outages on Wednesday morning with normal operations restored at 12:23 PM CEST [10]. That is an incident window of roughly seventeen hours from first unavailability to all-clear [11].
Through Wednesday, users in Switzerland, India and China were still reporting that the service was down while the status page showed no problems [12]. The reason was mundane and instructive: an unrelated technical fault stopped the status page updating, and Threema took it offline until the fault was fixed [13]. So the outage was accompanied by a failure of the one component whose job is to tell customers there is an outage. Updates went out progressively via social media [14], and Threema Work business customers were emailed on Wednesday morning, with account managers fielding inquiries [15].
Threema says the attacks hit both its own service and its colocation partner, Nine [16], and that it is not entirely clear whether Threema was the primary target or whether the attacks were aimed at multiple targets [17]. Defence was hard because the attacker kept changing patterns over an extended period to get around mitigation [18]. The company's own description is candid: sophisticated attackers change methods, sources and patterns during an attack, producing "a cat-and-mouse game" in which both sides react to the other's last move [19].
None of this touched the encryption. Threema runs its own server infrastructure at various locations in Switzerland and promises no ads, no profiling and no hidden data analyses [20]. Those are confidentiality properties, and they held. Availability is a separate property, and it is concentrated in exactly the place a privacy architecture cannot decentralise away: the relay everyone connects to, plus whoever racks it. The On-Prem cohort was insulated not because it was better encrypted but because it was not sharing a chokepoint with everybody else.
The remediation is upstream capacity, not architecture. Threema says it deployed specialised DDoS protection on 14 August to filter attack traffic before it reaches its infrastructure [21], and plans to add an incident history and an RSS feed to the status page so administrators can get updates through an independent channel [22].
Watch whether the RSS and incident history actually ship, and whether they are hosted off the infrastructure they report on. For anyone buying Threema Work for business continuity, the useful question in the next renewal is what the On-Prem delta costs, and whether email to account managers is an acceptable out-of-band channel when the messenger itself is the thing that is down [15].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Multiple large-scale DDoS attacks targeted Threema, causing severe disruption to its secure messaging service.
ReportedView cited source - [2]
Threema said the attacks made its service temporarily unavailable or only partially available on Tuesday evening and Wednesday morning.
ReportedView cited source - [3]
Organizations using Threema On-Prem did not experience any issues because those deployments run on their own infrastructure.
ReportedView cited source - [4]
On Tuesday around 6 PM UTC, users started reporting service interruptions.
ReportedView cited source - [5]
Threema responded about an hour after the first user reports, saying that based on the information available at the time the cause was 'a network outage on our colocation partner's side'.
- [6]
About three hours later, Threema said it was working to restore all of its services after its partner reported that the network issue had been resolved.
ReportedView cited source
Sources & coverage · 3 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- bleepingcomputer.comIonut IlascuAug 16Large-scale DDoS attacks disrupted Threema secure messaging service
- securityaffairs.comPierluigi Paganini6d agoDDoS Attacks Cause Major Threema Outages
- scworld.comSC Staff



