Threema, the Swiss secure messaging provider, suffered severe service disruptions this week after multiple distributed denial-of-service attacks hit its infrastructure, according to BleepingComputer. The report, citing Threema’s post-mortem, says the end-to-end encrypted messaging service was temporarily unavailable or only partially available on Tuesday evening and Wednesday morning. The incident began around 6 PM UTC on Tuesday, when users started reporting interruptions. BleepingComputer says Threema initially told users the issue appeared to be a network outage at a colocation partner. About three hours later, the company said it was working to restore services after the partner reported that the network issue had been resolved. The disruption did not end there. BleepingComputer reports that users in Switzerland, India, and China continued to report problems the next day, even as Threema’s status page showed no issues. Threema later confirmed that it was being targeted by a series of DDoS attacks and warned that intermittent outages were likely while mitigation continued. According to the report, the attacks were large-scale and targeted both Threema and its colocation partner, Nine. Threema said it was not entirely clear whether its service was the primary target or whether the traffic was aimed at multiple targets. The company also said the attacker repeatedly changed patterns, making the campaign harder to blunt with normal mitigation. The outage exposed a second operational problem: BleepingComputer reports that an unrelated technical issue prevented Threema from updating its current system status page. The company took that page offline until the problem was fixed. Business customers using Threema Work were informed by email on Wednesday morning about unstable service conditions, according to the report. One important boundary: organizations using Threema On-Prem were not affected, BleepingComputer reports, because those deployments rely on customers’ own infrastructure rather than Threema’s hosted service. That distinction matters for enterprises evaluating secure messaging architecture, because the same product family can have different outage exposure depending on where the service is hosted. Threema said it has now implemented specialized DDoS protection as an additional measure, designed to filter attack traffic upstream and reduce the load on its infrastructure. The company’s post-mortem, as summarized by BleepingComputer, frames the incident as a case where ordinary defenses were strained by scale, duration, and changing attack patterns. Who benefits: Threema On-Prem customers were insulated from this incident, according to the report, because their deployments use separate infrastructure. DDoS mitigation providers also gain relevance when attacks are large enough to affect both an application provider and its colocation partner. Who's exposed: Hosted Threema users were exposed to intermittent unavailability during the attacks. Threema Work customers also depended on direct email updates after an unrelated issue affected the company’s status page.