Threema, the Swiss end-to-end encrypted messaging service, suffered severe service disruptions earlier this week after being hit by a series of large-scale distributed denial-of-service (DDoS) attacks. The company detailed the incident in a post-mortem published Friday.
The disruptions began around 6 PM UTC on Tuesday, when users started reporting that messages were not sending and the app repeatedly cycled between “Connecting” and “Connected” states. Threema initially attributed the issue to a network outage at its colocation partner, Nine, and said about an hour later it was working with the partner to restore service. Roughly three hours after that, the company said the network issue had been resolved.
However, users in Switzerland, India, and China continued reporting problems into Wednesday, even though Threema’s status page showed no issues. The company subsequently confirmed it was being targeted by a series of DDoS attacks affecting both Threema and Nine’s infrastructure, and warned customers that further intermittent outages were likely.
Why the attacks were hard to stop
Threema said its defenses normally mitigate DDoS attacks without noticeable impact because they adapt automatically to attack patterns. This week’s attacks were unusually large in scale and persisted over an extended period, with the threat actor continually shifting tactics to evade mitigation measures. Threema said it remains unclear whether it was the primary target or whether the attackers were aiming at multiple victims simultaneously, since Nine was also affected.
An unrelated technical problem also prevented Threema from updating its public status page during the incident, prompting the company to take the page offline until the issue was fixed. Business customers on Threema Work were notified by email on Wednesday morning, with account managers fielding inquiries about the unstable service.
Organizations running Threema On-Prem, which relies on customer-managed infrastructure rather than Threema’s own servers, were not affected by the outage.
Mitigation
To prevent similar incidents, Threema said it has deployed additional specialized DDoS protection designed to filter malicious traffic upstream and reduce load on its core infrastructure.
- Attacks began around 6 PM UTC Tuesday and continued into Wednesday morning
- Both Threema and colocation partner Nine were targeted
- Threema On-Prem customers were unaffected
- New upstream DDoS filtering has since been implemented
