Threema messaging service knocked offline by DDoS attack

Published August 2, 2026

Threema's secure messaging service went down for four hours after a large DDoS attack. Attackers flooded the service with fake traffic, making it unavailable to users relying on Threema's cloud version.

Report priority
High
Victim
Threema

What is known

Attackers sent massive amounts of fake internet traffic to Threema's cloud servers, overwhelming them and blocking real users.

What to do

If you use Threema's cloud version and saw service interruptions Tuesday evening or Wednesday morning, check your Threema app for updates or restart it if it's still acting slow.

Reported details

An attacker sends a flood of fake messages to Threema's cloud servers, clogging up the network. Threema's servers can't handle the sudden rush, so real users can't send or receive messages for hours. The attacker keeps changing the attack pattern to avoid detection, making it harder to stop.

A distributed denial-of-service (DDoS) attack disrupted Threema's hosted messaging service for approximately four hours on August 2024, causing service outages for users relying on the cloud-based platform. The attack employed shifting traffic patterns, making mitigation more challenging than routine DDoS events, which Threema typically handles without disruption. Self-managed OnPrem deployments remained operational throughout the incident, while hosted users experienced intermittent downtime.

No evidence suggested unauthorized access to user data or encryption compromise, though the attack temporarily overwhelmed network capacity. Threema later deployed upstream traffic filtering to mitigate future DDoS attempts. The attackers and their motives remain unidentified, though Threema's colocation provider, Nine, was also targeted, leaving unclear whether Threema was the primary or secondary target.

References