ctipilot.ch

Threema / Nine DDoS campaign (August 2026)

incident · incident:threema-nine-ddos-2026-08 single-source-victim

A series of large-scale, continuously adapting distributed denial-of-service attacks that targeted the Swiss encrypted messenger Threema and its Swiss colocation partner Nine over two days in August 2026, causing a four-hour outage on the Tuesday evening and intermittent interruptions into Wednesday. Threema states it is unclear whether it was the primary target, that only availability was affected and no systems or data were accessed, and that customers running Threema OnPrem on their own infrastructure were unaffected throughout (Threema, 2026-08-14).

Coverage timeline
1
first 2026-08-15 → last 2026-08-15
Peak priority
notable
1 notable
Sources cited
2
2 hosts
Sections touched
1
active-threats
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques
Affected products
Threema
Tags

ATT&CK techniques

1 technique observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Impact TA0040

T1498Network Denial of Service×1

Adversaries may perform Network Denial of Service (DoS) attacks to degrade or block the availability of targeted resources to users. Network DoS can be performed by exhausting the network bandwidth services rely on. Example resources include specific websites, email services, DNS, and web-based applications. Adversaries have been observed conducting network DoS attacks for political purposes and to support other malicious activities, including distraction, hacktivism, and extortion.

Evidence: 2026-08-15/threema-nine-colocation-ddos-swiss-messenger-outage · ATT&CK page ↗

Story timeline

  1. 2026-08-15Threema and its Swiss colocation partner were hit by the same adaptive DDoS wave — the attack moved to the hosting layer, and only the self-hosted customers stayed up
    active-threatsSwiss messenger Threema loses four hours to a DDoS campaign that also hit its colocation partner; availability only, no access to systems or data

Where this entity is cited

  • active-threats1

Source distribution

  • cyberinsider.com1 (50%)
  • threema.com1 (50%)

explore in graph

Entries about Threema / Nine DDoS campaign (August 2026) (1)

2026-08-15 · view entry permalink →

NOTABLENATOA2

Threema and its Swiss colocation partner were hit by the same adaptive DDoS wave — the attack moved to the hosting layer, and only the self-hosted customers stayed up

Threema, the Swiss end-to-end-encrypted messenger, published an account on 2026-08-14 of a two-day disruption: a series of large-scale DDoS attacks targeted Threema and its colocation partner Nine, and Threema states it is not entirely clear whether it was the primary target or whether the attacks were directed at multiple targets (Threema, 2026-08-14). The service was unavailable on the Tuesday between 19:30 and 23:30 CEST; the attacks resumed on Wednesday morning and produced intermittent brief interruptions until normal operations were restored at 12:23. Threema notes that its status page was initially not updating because of a technical issue unrelated to the attack, and that it took the page offline until that was fixed — a small detail with a wider lesson, since the channel an organisation uses to tell users what is happening shares infrastructure and failure modes with the thing that is failing.

Threema is explicit about what the incident was not: a denial-of-service attack targets only the availability of an online service, not its security, and even a successful one gives attackers no access to systems or data (Threema, 2026-08-14). It describes the defensive problem as a contest of resources in which sophisticated attackers continuously change their sources and patterns during an attack, producing what it calls a cat-and-mouse game, and notes that even with effective DDoS protection in place, temporary disruption cannot always be prevented when an attacker has considerable technical and financial resources — as, it says, may be the case with state actors. That is a general observation about well-resourced adversaries; Threema does not attribute this incident to one, and no other party has. Threema says it is adding specialised DDoS protection that filters attack traffic upstream of its own infrastructure, and an update on the same post records that protection as now activated in the production environment (Threema, 2026-08-14).

The transferable point for an operator sits in the two facts Threema puts either side of the outage. The attack reached the colocation partner as well as the service, which means an application-layer mitigation scoped to the service's own edge is not scoped to the whole failure domain — the hosting provider's capacity is a shared dependency, and a tenant is exposed to a volumetric attack aimed at a neighbour. And customers running Threema OnPrem, on their own infrastructure, were unaffected throughout and used their instances without interruption (Threema, 2026-08-14). For a public-sector body that has adopted a hosted secure-messaging service as its out-of-band or emergency communications channel, that is the operationally relevant sentence: the deployment model, not the protocol, decided who could still talk to each other that evening.

This week, however, a series of large-scale DDoS attacks targeted Threema and our colocation partner, Nine. It is not entirely clear whether Threema was the primary target or whether the attacks were directed at multiple targets.

Because organizations using Threema OnPrem rely on their own infrastructure, they were not affected by this wave of attacks and were able to use their Threema OnPrem instances as usual at all times, without any interruptions.

Threema GmbH 2026-08-14
incident15 Aug 04:53Zsingle-source · victim disclosureOpen finding ↗