Multiple distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service earlier this week, causing severe disruptions to communications.
Organizations using Threema On-Prem did not experience any issues because they rely on their own infrastructure.
In a post-mortem report on Friday, the end-to-end encrypted instant messaging service said that the attacks were difficult to defend against because the threat actor constantly changed patterns.
Threema is a paid messaging application developed by the Swiss technology company of the same name, with a heavy focus on security and privacy.
The service relies on its own server infrastructure in various locations in Switzerland and promises “no ads, no profiling, no hidden data analyses.”
On Tuesday around 6 PM UTC, users started to report service interruptions. The company responded about an hour later, saying that based on the information available at the time, the cause was “a network outage on our colocation partner’s side.”
“Now Threema network status saying ‘Connecting’ instead of ‘Connected,’ welp... 10mins later, now it's back to saying ‘Connected,’ yet msgs are still very much not sending right away & very delayed,” one user complained.
About three hours later, Threema said it was working to restore all of its services after its partner reported that the network issue had been resolved.
The next day, users in Switzerland, India, and China continued to report that the service was down, despite Threema’s status page showing no problems.
However, the company confirmed that it was being targeted by a series of DDoS attacks it was working to mitigate, and warned users that intermittent outages were likely to occur.
... continue reading