Decoding the world of cybersecurity

Threema outage exposes hosting split

A sustained DDoS campaign disrupted Threema and its colocation provider, while customers running the messaging platform on their own infrastructure remained available.

Threema outage exposes hosting split
Summary
  • Large-scale DDoS attacks hit both Threema and colocation provider Nine, causing a four-hour outage and further intermittent disruption.
  • Threema OnPrem customers were unaffected because their environments run on separate customer-controlled infrastructure.
  • Threema has added upstream DDoS filtering and is separating service-status communications from the infrastructure being reported on.

A series of large-scale distributed denial-of-service attacks against Swiss secure-messaging provider Threema and its colocation partner caused hours of disruption, while customers running the platform on their own infrastructure continued operating normally.

Threema said the attacks affected both its own systems and infrastructure operated by colocation provider Nine, with attack patterns changing repeatedly over an extended period. The company has not established whether it was the principal target or whether the traffic was directed more broadly at several organisations using the same underlying infrastructure.

The disruption left Threema unavailable between 19:30 and 23:30 CEST on Tuesday, followed by intermittent service interruptions on Wednesday morning. Normal operations were restored at 12:23, according to the company’s incident account.

A separate technical problem prevented Threema’s status page from being updated at the beginning of the outage, forcing the company to take the page temporarily offline and communicate through social media and direct emails to business customers. It now plans to add an incident history and RSS feed so service information can be received through an independent channel.

Architecture determined which customers remained available. Organisations using Threema OnPrem were unaffected because those deployments operate on customer-controlled infrastructure rather than relying on the hosted Threema environment.

Self-hosting does not remove resilience risk; it transfers capacity planning, maintenance, protection, recovery, and availability obligations to the customer. In this incident, however, the separate infrastructure boundary prevented the hosted-platform disruption from reaching OnPrem deployments.

Threema has since activated additional specialist DDoS protection that filters hostile traffic upstream before it reaches its own systems. Such filtering becomes relevant when attack volume is sufficient to consume connectivity or shared network infrastructure before application-level controls can respond.

The involvement of a colocation provider widens the service map beyond the company visible to customers. Communications platforms can depend on datacentres, network carriers, DNS providers, mitigation services, content-delivery networks, and identity infrastructure, each capable of becoming part of the same outage path.

Those relationships tend to remain largely invisible during normal operation because a customer contracts with one provider while the service itself is assembled from several infrastructure layers. During disruption, restoration and communication can depend on several organisations with different controls, escalation procedures, and operational responsibilities.

Secure communications services carry an additional availability burden because organisations may rely on them when ordinary channels are unavailable or untrusted. The resilience of the communications platform and the independence of its status channels therefore form part of the same continuity architecture.

Threema’s own business continuity material promotes secure messaging as an out-of-band communications option. If a crisis channel shares infrastructure dependencies with the systems affected by a wider outage, the supposed alternative route can fail at the same point.

The company’s incident account describes an availability event and reports no unauthorised access to systems or data. No attacker has been publicly identified.

By the time service was restored, the outage had exposed three separate operational dependencies: shared hosting infrastructure, upstream DDoS mitigation, and the status channel used to explain the outage itself. Threema’s response is now changing all three.

×