Threema DDoS attacks expose mitigation limits
Swiss messaging firm Threema faced sustained DDoS attacks this week, with changing tactics challenging defenses.
For a service built on a promise of privacy and reliability, this week brought an unwelcome disruption. Users of the Swiss secure messaging app Threema reported service interruptions starting Tuesday around 6 PM UTC, and the company later confirmed it was the target of a series of distributed denial-of-service (DDoS) attacks. What made these attacks notable, according to Threema, was not just their scale but the adversary's ability to constantly shift tactics, making mitigation unusually difficult. The outage stretched into Wednesday, leaving many users in Switzerland, India, and China unable to send or receive messages reliably.
Swiss Privacy Promise Meets Real-World Strain
Threema is a paid messaging application developed by the Swiss technology company of the same name, with a heavy focus on security and privacy. The service relies on its own server infrastructure in various locations in Switzerland and promises “no ads, no profiling, no hidden data analyses.” That infrastructure became the target of the attacks, which aimed to overwhelm the servers with traffic.
According to Threema's post-mortem report published on Friday, the attacks were difficult to defend against because the threat actor constantly changed patterns. This is a departure from typical DDoS campaigns, which often follow predictable traffic signatures that can be blocked relatively quickly.
Confusion and a Faulty Status Page
The initial response from Threema, about an hour after reports began, pointed to a network issue. The company said that based on the information available at the time, the cause was “a network outage on our colocation partner’s side.” That explanation would soon evolve.
Users, however, were already noticing problems. “Now Threema network status saying ‘Connecting’ instead of ‘Connected,’ welp... 10mins later, now it's back to saying 'Connected,' yet msgs are still very much not sending right away & very delayed,” one user complained. The mixed signals from the status page only added to the frustration.
About three hours later, Threema said it was working to restore all of its services after its partner reported that the network issue had been resolved. But the next day, users in Switzerland, India, and China continued to report that the service was down, despite Threema’s status page showing no problems. The company later admitted that an unrelated technical issue had prevented it from updating the status page, and it took the page offline until the problem was fixed.
Attacks Targeted Both Threema and Its Colocation Partner
Threema operates its own servers, but it relies on a colocation partner named Nine for hosting. The attacks this week were large-scale, though, and targeted both Threema and its colocation partner, Nine. “It is not entirely clear whether Threema was the primary target or whether the attacks were directed at multiple targets,” the company notes.
Threema explains that the attacks made its service “temporarily unavailable or only partially available on Tuesday evening and Wednesday morning.” The company confirmed that it was being targeted by a series of DDoS attacks it was working to mitigate, and warned users that intermittent outages were likely to occur.
Why Defending Was So Hard
Typically, DDoS attacks are mitigated without any noticeable impact due to effective defenses that adapt to the attack’s patterns, Threema said. This time, the defense was more complicated. Defending against the attacks proved challenging because they persisted for an extended period, while the threat actor continually changed its tactics to circumvent mitigation measures.
That combination of persistence and adaptability made the attacks harder to deflect than a standard flood of traffic. The mitigation systems that normally handle such events had to be adjusted in real time, and the attacks kept coming.
Business Customers Were Warned
Threema offers a version of the service called Threema Work for business customers. “Business customers using Threema Work were informed via email on Wednesday morning about the unstable service conditions, and account managers provided information on the current situation in response to inquiries.”
Organizations using Threema On-Prem did not experience any issues because they rely on their own infrastructure. That distinction matters: for businesses that chose to host Threema themselves, the DDoS attacks were a non-event.
New Defenses and Lingering Questions
To avoid similar incidents, the Swiss company has implemented “specialized DDoS protection as an additional measure” to filter attack traffic upstream and reduce the load on its infrastructure. This suggests the company is looking to push mitigation closer to the network edge, rather than relying solely on its own servers to absorb and filter malicious traffic.
The exact scale of the attacks, in terms of requests per second or gigabytes per second, has not been disclosed. What is clear is that Threema, a service that markets itself as a secure haven for private communication, faced a significant disruption that affected even non-technical users across multiple countries.
Why It Matters
For individual users and businesses that rely on Threema for encrypted communications, this incident is a reminder that even the most privacy-focused services are not immune to network-level attacks. A DDoS attack does not break encryption, but it can still deny service, preventing people from sending messages when they need to. The fact that Threema's status page was down during part of the outage only compounded the confusion, eroding trust in the service's operational transparency.
The shift toward specialized upstream DDoS protection suggests that Threema is treating this as a serious threat that could recur. If the attacks were indeed aimed at the company rather than its colocation partner, they may signal that threat actors are willing to target secure communication platforms specifically to disrupt their availability. For users, this means that even a service designed for security can face availability challenges, and that mitigating such attacks requires constant adaptation.
Sources
- BleepingComputer Original source
Continue Reading
Why 2,500-Org Breach Wasn't What It Seemed
SOCRadar says most orgs hit in LiteLLM attack were earlier Trivy victims, not LiteLLM.
Salesforce and ServiceNow attacks expose new API risks
Researchers say ‘City-Forum’ campaign targets Salesforce and ServiceNow, possibly tied to ShinyHunters.
Akira exploits Safe Mode to bypass EDR defenses
Akira ransomware used Windows Safe Mode to disable endpoint defenses, revealing a growing evasion trend.