Encrypted messaging provider Threema experienced significant disruptions this week due to a series of large-scale distributed denial-of-service (DDoS) attacks. These attacks rendered the service inaccessible for several hours on Tuesday and caused intermittent outages on Wednesday morning.
Details of the Incident
The company revealed that the attacks targeted both Threema and its Swiss colocation partner, Nine. It remains uncertain whether Threema was the primary target or merely one of several services affected. The disruptions began on Tuesday evening, with the service being unavailable from 7:30 p.m. to 11:30 p.m. CEST. The attacks resumed on Wednesday morning, characterized by rapidly changing traffic sources and patterns, complicating mitigation efforts and leading to shorter, intermittent service interruptions.
By 12:23 p.m. on Wednesday, normal operations were restored, and Threema reported that all services have remained fully operational since then.
About Threema
Threema, based in Switzerland, is renowned for its privacy-focused mobile applications and business communication solutions. Its offerings include the consumer-oriented Threema messenger, the enterprise-focused Threema Work platform, and Threema OnPrem, which allows organizations to manage their messaging infrastructure internally.
Impact on Security and User Data
The company emphasized that while service availability was affected, the security of its systems and user data remained intact. DDoS attacks aim to overwhelm infrastructure by directing vast amounts of requests or network traffic towards a target, thereby preventing legitimate users from accessing the service. Importantly, these attacks do not grant attackers access to internal systems or sensitive information.
Challenges in Mitigation
Threema noted that the scale and evolving nature of this week’s attacks made them particularly challenging to filter compared to typical DDoS activity. Attackers with substantial technical and financial resources can swiftly modify their methods to circumvent defensive measures.
Communication with Customers
A separate technical issue hindered Threema’s status page from updating accurately during the initial outage, prompting the company to temporarily disable the page until the problem was resolved. Customers using Threema Work were notified via email on Wednesday morning, and updates were also disseminated through the company’s social media channels. Notably, Threema OnPrem deployments remained unaffected, as those customers manage their own infrastructure.
Future Measures
In response to the attacks, Threema is implementing specialized upstream DDoS protection to filter out malicious traffic before it can impact its infrastructure. This protective measure was undergoing final stability testing at the time of the announcement.
Additionally, Threema plans to enhance its status page to include an incident history and an RSS feed, providing users and administrators with an independent means to monitor future service disruptions.
If you liked this article, be sure to follow us on X/Twitter and also LinkedIn for more exclusive content.