Threema messaging service knocked offline by DDoS attack
Threema's secure messaging service went down for four hours after a large DDoS attack. Attackers flooded the service with fake traffic, making it unavailable to users relying on Threema's cloud version.
- Report priority
- High
- Victim
- Threema
What is known
Attackers sent massive amounts of fake internet traffic to Threema's cloud servers, overwhelming them and blocking real users.
What to do
If you use Threema's cloud version and saw service interruptions Tuesday evening or Wednesday morning, check your Threema app for updates or restart it if it's still acting slow.
Reported details
An attacker sends a flood of fake messages to Threema's cloud servers, clogging up the network. Threema's servers can't handle the sudden rush, so real users can't send or receive messages for hours. The attacker keeps changing the attack pattern to avoid detection, making it harder to stop.
A distributed denial-of-service (DDoS) attack disrupted Threema's hosted messaging service for approximately four hours on August 2024, causing service outages for users relying on the cloud-based platform. The attack employed shifting traffic patterns, making mitigation more challenging than routine DDoS events, which Threema typically handles without disruption. Self-managed OnPrem deployments remained operational throughout the incident, while hosted users experienced intermittent downtime.
No evidence suggested unauthorized access to user data or encryption compromise, though the attack temporarily overwhelmed network capacity. Threema later deployed upstream traffic filtering to mitigate future DDoS attempts. The attackers and their motives remain unidentified, though Threema's colocation provider, Nine, was also targeted, leaving unclear whether Threema was the primary or secondary target.
References
- threema.com · outage-august-2026 eSecurityPlanet
- zerodayinitiative.com · ZDI-26-576 Zero Day Initiative
- zerodayinitiative.com · ZDI-26-575 Zero Day Initiative
- zerodayinitiative.com · ZDI-26-572 Zero Day Initiative
- zerodayinitiative.com · ZDI-26-570 Zero Day Initiative
- zerodayinitiative.com · ZDI-26-569 Zero Day Initiative
- zerodayinitiative.com · ZDI-26-568 Zero Day Initiative
- zerodayinitiative.com · ZDI-26-563 Zero Day Initiative
- zerodayinitiative.com · ZDI-26-562 Zero Day Initiative
- zerodayinitiative.com · ZDI-26-561 Zero Day Initiative
- zerodayinitiative.com · ZDI-26-560 Zero Day Initiative
- zerodayinitiative.com · ZDI-26-559 Zero Day Initiative
- zerodayinitiative.com · ZDI-26-558 Zero Day Initiative
- zerodayinitiative.com · ZDI-26-557 Zero Day Initiative
- fortiguard.fortinet.com · FG-IR-26-156 Fortinet PSIRT
- snyk.io · why-we-rebuilt-evo-ai-model-risk-scoring Snyk
- wid.cert-bund.de · securityadvisory CERT-Bund Advisories
- acn.gov.it · risolte-vulnerabilita-in-prodotti-roundcube-webmail-1 ACN CSIRT Italy
- acn.gov.it · rilevate-vulnerabilita-in-mattermost-1 ACN CSIRT Italy
- securityonline.info · safepal-data-breach-order-information SecurityOnline
- gbhackers.com · realtek-ethernet-driver GBHackers
- infosecurity-magazine.com · gunra-ransomware-fortinet-flaws Infosecurity Magazine
- neuracybintel.com · ringcentral-data-breach-exposes-personal-details-of-16-million-accounts-in-shinyhunters-extortion-campaign NeuraCybIntel
- neuracybintel.com · trezor-shipping-partner-breach-exposes-personal-data-of-nearly-14000-hardware-wallet-customers NeuraCybIntel
- neuracybintel.com · critical-metabase-zero-day-sql-injection-flaw-actively-exploited-exposing-customer-data-at-framework-and-tally NeuraCybIntel
- securityweek.com · heights-finance-data-breach-impacts-at-least-1-2-million-individuals SecurityWeek
- securityweek.com · 40000-impacted-by-safepal-data-breach SecurityWeek
- openwall.com · 2 Openwall oss-security
- openwall.com · 3 Openwall oss-security
- bleepingcomputer.com · pokemon-center-data-breach-exposes-customer-info-cancels-some-orders BleepingComputer
- bleepingcomputer.com · french-tax-authority-data-breach-affects-678-000-individuals BleepingComputer
- bleepingcomputer.com · safepal-data-breach-impacts-39-798-customers-stolen-info-for-sale BleepingComputer
- darkreading.com · metabase-sql-zero-day-attacks-wide-blast-radius DarkReading
- sec.cloudapps.cisco.com · cisco-sa-notice-LDquvx5d Cisco PSIRT
- blogs.cisco.com · strengthening-the-foundation-a-predictable-customer-focused-response-to-ai-accelerated-vulnerability-discovery Cisco PSIRT
- discuss.hashicorp.com · 77657 HashiCorp
- hashicorp.com · subprocessors HashiCorp
- ibm.com · index.html HashiCorp
- cyber.gc.ca · beyondtrust-security-advisory-av26-826 CCCS Canada
- stepsecurity.io · anthropic-incident-ai-agent-malicious-package-pypi StepSecurity