Threema DDoS attacks caused major disruptions to the Swiss secure messaging service earlier this week. Users struggled to send messages and connect to the platform as the attacks affected both Threema and its colocation partner.

The company said the incidents temporarily made its service unavailable or only partly available on Tuesday evening and Wednesday morning. Threema On-Prem customers did not experience the disruption because they operate on their own infrastructure.

Threema is a paid end-to-end encrypted messaging app developed by the Swiss company of the same name. It operates its own server infrastructure in Switzerland and promotes a privacy-first approach without advertising, profiling or hidden data analysis.

Users report connection and delivery problems

Users first began reporting service problems on Tuesday at about 6 PM UTC. Threema initially said it believed a network outage at its colocation partner caused the disruption.

About an hour later, the company said it was investigating the problem. It then announced that its partner had resolved the network issue and that it was working to restore all services.

However, users continued to report problems the following day. Some users in Switzerland, India and China said messages arrived late or failed to send, even when the app appeared connected.

Threema later confirmed that a series of DDoS attacks caused the outages. The company warned that users could continue to face intermittent service issues while it worked to reduce the impact.

Attackers changed tactics during the campaign

The Threema DDoS attacks proved difficult to mitigate because the threat actor repeatedly changed attack patterns. The activity continued for an extended period and forced the company to adapt its defences throughout the incident.

DDoS attacks flood a target with traffic, preventing legitimate users from accessing an online service. Many providers can filter this traffic without users noticing. However, large and constantly changing attacks can overwhelm standard mitigation systems.

Threema said the attacks targeted both its own infrastructure and its colocation partner, Nine. The company could not determine whether attackers specifically targeted Threema or launched the activity against several targets.

The incident also affected Threema’s ability to communicate with users. An unrelated technical issue stopped the company from updating its system status page. Threema took the page offline until it could fix the problem.

Business customers received outage updates

Threema informed Threema Work business customers by email on Wednesday morning. Account managers also provided updates to customers who contacted the company directly.

Meanwhile, organisations using Threema On-Prem continued operating normally. These customers host the service through their own infrastructure rather than relying on Threema’s shared systems.

Threema adds extra DDoS protection

Following the incident, Threema introduced specialised DDoS protection as an additional security measure. The new protection filters malicious traffic upstream before it reaches the company’s infrastructure.

That approach should reduce the load placed on Threema’s systems during future attacks. It may also help the company maintain service availability when attackers alter their tactics.

Conclusion

Threema DDoS attacks disrupted communications for users around the world and showed how persistent attacks can challenge even well-prepared messaging platforms. Threema has now added extra traffic filtering to strengthen its protection against similar incidents.


0 responses to “Threema DDoS attacks disrupt secure messaging service”