Skip to content
Tech News
← Back to articles

Large-scale DDoS attacks disrupted Threema secure messaging service

read original more articles
Why This Matters

The recent large-scale DDoS attacks on Threema highlight the ongoing cybersecurity threats faced by secure messaging services, emphasizing the importance of resilient infrastructure and adaptive defense mechanisms. These disruptions underscore the need for both providers and users to prioritize security and preparedness in safeguarding sensitive communications.

Key Takeaways

Multiple distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service earlier this week, causing severe disruptions to communications.

​Organizations using Threema On-Prem did not experience any issues because they rely on their own infrastructure.

In a post-mortem report on Friday, the end-to-end encrypted instant messaging service said that the attacks were difficult to defend against because the threat actor constantly changed patterns.

Threema is a paid messaging application developed by the Swiss technology company of the same name, with a heavy focus on security and privacy.

The service relies on its own server infrastructure in various locations in Switzerland and promises “no ads, no profiling, no hidden data analyses.”

On Tuesday around 6 PM UTC, users started to report service interruptions. The company responded about an hour later, saying that based on the information available at the time, the cause was “a network outage on our colocation partner’s side.”

“Now Threema network status saying ‘Connecting’ instead of ‘Connected,’ welp... 10mins later, now it's back to saying ‘Connected,’ yet msgs are still very much not sending right away & very delayed,” one user complained.

About three hours later, Threema said it was working to restore all of its services after its partner reported that the network issue had been resolved.

The next day, users in Switzerland, India, and China continued to report that the service was down, despite Threema’s status page showing no problems.

However, the company confirmed that it was being targeted by a series of DDoS attacks it was working to mitigate, and warned users that intermittent outages were likely to occur.

... continue reading