DDoS Attacks on Threema

Illustration of an overloaded server and malfunctioning connected devices.

If you use Threema regularly, you may have noticed that the service was temporarily unavailable or only partially available on Tuesday evening and Wednesday morning. This was due to a series of DDoS attacks. Below, we explain what happened and outline the measures we’ve taken.

What is a DDoS attack?

In a “Denial of Service” (DoS) attack, an attacker sends a disproportionately large number of requests or data packets to an online service in an attempt to overload its infrastructure and make the service temporarily inaccessible to users.

If the attack originates simultaneously from multiple (and potentially changing) sources, it is referred to as a “Distributed Denial of Service” (DDoS) attack. This makes the attack significantly more difficult to defend against because it is not possible to simply block a single source.

Put simply, it comes down to a contest of resources between the attacker and the service provider: the attacker attempts to generate more traffic than the service provider’s infrastructure can handle or than its protective mechanisms can block (i.e., filter). At the same time, the service provider analyzes the attack, adjusts its defensive measures, and attempts to block illegitimate traffic without disrupting legitimate requests.

Because sophisticated attackers constantly change their methods, sources, and attack patterns during an attack, a cat-and-mouse game ensues, with both sides continuously reacting to the other’s most recent action.

Even with effective DDoS protection in place, temporary disruptions cannot always be completely prevented during attacks involving large volumes of traffic and rapidly changing attack patterns. This is especially true when an attacker has considerable technical and financial resources at their disposal, as may be the case with state actors.

The Recent DDoS Attacks on Threema

Like most online services, Threema is subject to recurring DDoS attacks. In the vast majority of cases, however, Threema users notice (almost) nothing because our defense mechanisms are effective or because we adapt to changing attack patterns so quickly that the resulting service disruption is, at most, very brief and usually not widespread (e.g., only individual services are temporarily unavailable or the website takes longer to load).

This week, however, a series of large-scale DDoS attacks targeted Threema and our colocation partner, Nine. It is not entirely clear whether Threema was the primary target or whether the attacks were directed at multiple targets. In any case, they continued over an extended period and their patterns were constantly adapted, making them difficult to defend against.

As a result of these attacks, Threema was unavailable on Tuesday between 7:30 p.m. and 11:30 p.m. CEST. The page providing information on the current system status was initially not updated due to a technical issue unrelated to the attack. We therefore temporarily took it offline until the problem was resolved.

On Wednesday morning, the attacks continued, and the cat-and-mouse game outlined above took its course. Consequently, there were intermittent, brief service interruptions throughout Wednesday morning. At 12:23 p.m., normal operations had been restored, and all services have been fully operational since.

Measures Taken

The service interruptions were communicated step by step on our social media channels, based on the information available at the time. Business customers using Threema Work were informed via email on Wednesday morning about the unstable service conditions, and account managers provided information on the current situation in response to inquiries.

To complement our existing defense mechanisms, we are implementing specialized DDoS protection as an additional measure. This filters attack traffic upstream, thereby reducing the load on our own infrastructure. Once the final stability tests have been concluded – which we expect to happen within the next few hours – the mechanism will be activated in the production environment.

We will also expand the status page in the coming days. The update will include an incident history and an RSS feed that interested users and Threema Work administrators can subscribe to in order to receive system updates through an independent channel.

We apologize for any inconvenience caused and appreciate your understanding.