The Threema outage that occurred on Tuesday and Wednesday was caused by a series of large-scale DDoS. The encrypted messaging service was down for hours, followed by short, consecutive outages.

Threema explained in a detailed update that the attacks targeted both itself and colocation provider Nine. It is not yet clear whether Threema was the sole target or whether the attackers sought to hit more infrastructure.
See also: WhatsApp, Signal and Threema: What applies to location data privacy
Attacks of this type don't need to compromise accounts or decrypt messages to cause significant pressure. They simply need to temporarily make services more difficult to access, especially when used by businesses that rely on the direct exchange of instructions and files.
The case also highlights the importance of timely and independent reporting. When the status page itself is experiencing a problem, administrators need a second channel of communication, clear instructions for alternative services, and pre-established procedures for continuing work.
How the Threema outage unfolded
The first reports of problems appeared on Tuesday, at around 20:00 Greek time. The company initially attributed the situation to a failure in its provider's network, as that was the only picture it had available. About three hours later, it announced that it was working to restore services.
The next day, users in Switzerland, India, and China continued to report issues, although the status page did not show any. Threema confirmed at the time that it was experiencing a series of DDoS attacks and warned that there would be short, intermittent outages as it adjusted to the changing attack patterns.
According to the company, the service was completely unavailable on Tuesday from 19:30 to 23:30 CET. On Wednesday morning, there were further short-term outages, until normal operation was restored at 12:23.

Why the attacks made the defense difficult
The attacks were not static. The attacker constantly changed the characteristics of the traffic, forcing defense teams to repeatedly adjust their filters. The duration and scale of the campaign also strained the infrastructure of partner Nine, which complicated the picture of the incident.
Threema noted that an unrelated technical issue temporarily prevented the status page from being updated. The page was taken offline until the issue was fixed, with updates gradually being communicated via the company's official accounts. Threema Work customers were also notified by email.
The Threema outage did not affect organizations using Threema OnPrem. Because these installations operate on infrastructure controlled by the organizations themselves, they remained available throughout the attack. The distinction shows how important a service’s deployment architecture is in large-scale denial-of-service incidents.
See also: Cyberattacks on telecommunications companies: The basic ways to protect yourself
The new protection and next steps
To limit the likelihood of a repeat, Threema has activated specialized DDoS protection before its infrastructure. The mechanism filters malicious traffic before it reaches its own resources, reducing the load on systems serving messages, calls, and files.

The company announced that the additional protection was activated in production on August 14, after stability testing was completed. It also plans to expand the status page with incident history and an RSS feed so that Threema Work administrators can receive updates from an independent channel.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Signal and sensitive communications: Why availability remains critical
The Threema outage has been restored without any reported breach of message content or encryption. The incident concerns service availability and does not indicate that attackers gained access to conversations. Users and organizations should monitor the status page and maintain an alternative communication plan for such cases.
