Threema and its Swiss colocation partner were hit by the same adaptive DDoS wave — the attack moved to the hosting layer, and only the self-hosted customers stayed up
Threema, the Swiss end-to-end-encrypted messenger, published an account on 2026-08-14 of a two-day disruption: a series of large-scale DDoS attacks targeted Threema and its colocation partner Nine, and Threema states it is not entirely clear whether it was the primary target or whether the attacks were directed at multiple targets (Threema, 2026-08-14). The service was unavailable on the Tuesday between 19:30 and 23:30 CEST; the attacks resumed on Wednesday morning and produced intermittent brief interruptions until normal operations were restored at 12:23. Threema notes that its status page was initially not updating because of a technical issue unrelated to the attack, and that it took the page offline until that was fixed — a small detail with a wider lesson, since the channel an organisation uses to tell users what is happening shares infrastructure and failure modes with the thing that is failing.
Threema is explicit about what the incident was not: a denial-of-service attack targets only the availability of an online service, not its security, and even a successful one gives attackers no access to systems or data (Threema, 2026-08-14). It describes the defensive problem as a contest of resources in which sophisticated attackers continuously change their sources and patterns during an attack, producing what it calls a cat-and-mouse game, and notes that even with effective DDoS protection in place, temporary disruption cannot always be prevented when an attacker has considerable technical and financial resources — as, it says, may be the case with state actors. That is a general observation about well-resourced adversaries; Threema does not attribute this incident to one, and no other party has. Threema says it is adding specialised DDoS protection that filters attack traffic upstream of its own infrastructure, and an update on the same post records that protection as now activated in the production environment (Threema, 2026-08-14).
The transferable point for an operator sits in the two facts Threema puts either side of the outage. The attack reached the colocation partner as well as the service, which means an application-layer mitigation scoped to the service's own edge is not scoped to the whole failure domain — the hosting provider's capacity is a shared dependency, and a tenant is exposed to a volumetric attack aimed at a neighbour. And customers running Threema OnPrem, on their own infrastructure, were unaffected throughout and used their instances without interruption (Threema, 2026-08-14). For a public-sector body that has adopted a hosted secure-messaging service as its out-of-band or emergency communications channel, that is the operationally relevant sentence: the deployment model, not the protocol, decided who could still talk to each other that evening.
This week, however, a series of large-scale DDoS attacks targeted Threema and our colocation partner, Nine. It is not entirely clear whether Threema was the primary target or whether the attacks were directed at multiple targets.
Because organizations using Threema OnPrem rely on their own infrastructure, they were not affected by this wave of attacks and were able to use their Threema OnPrem instances as usual at all times, without any interruptions.
ATT&CK mapping
1 technique mapped from the cited reporting · MITRE ATT&CK v19.2
Impact TA0040
T1498Network Denial of Service
Adversaries may perform Network Denial of Service (DoS) attacks to degrade or block the availability of targeted resources to users. Network DoS can be performed by exhausting the network bandwidth services rely on. Example resources include specific websites, email services, DNS, and web-based applications. Adversaries have been observed conducting network DoS attacks for political purposes and to support other malicious activities, including distraction, hacktivism, and extortion.
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.