Affected Systems

Threema secure messaging service (cloud-hosted instances). Users in Switzerland, India, and China reported outages. Threema On-Prem customers unaffected as they use independent infrastructure. Colocation partner Nine also targeted.

Exploitation Status

Active campaign concluded. Multiple coordinated DDoS attacks occurred Tuesday-Wednesday (August 13-14, 2026). Threat actor continuously adapted tactics to evade mitigation. No ongoing exploitation reported as of August 16, 2026.

Business Impact

Organizations relying on cloud-hosted Threema for secure communications experienced severe service disruptions over 24+ hours. Business continuity impacted for teams using Threema Work. On-Prem deployments remained operational. Attack demonstrates risk to centralized encrypted messaging infrastructure. No data breach or encryption compromise reported.

Urgency

🟡 Within a week

Recommended Actions

  • Verify Threema service availability and test message delivery if your organization uses cloud-hosted Threema or Threema Work
  • Review business continuity plans for encrypted communications; consider redundant messaging channels for critical operations
  • If using Threema cloud service, contact vendor to confirm new DDoS protections are active and request SLA commitments
  • Evaluate migration to Threema On-Prem if service availability is mission-critical and infrastructure resources permit
  • Monitor Threema status page and vendor communications for any recurrence of attacks or service degradation