Jessica Entwistle
August 17 2026
Security Affairs reports that Threema, a Swiss-based secure messaging platform, suffered multiple large-scale distributed denial-of-service (DDoS) attacks that caused severe communication outages for users. The attacks disrupted the service for an extended period, preventing users from sending or receiving messages. Threema is used by organisations and individuals who prioritise privacy and secure communication, and the platform is particularly popular in sectors such as healthcare, legal services, and government. The attacks did not affect organisations using Threema On-Prem, a self-hosted version of the platform that runs on the customer's own infrastructure.
This incident is a reminder that availability is a core component of security, and that reliance on any single communication platform introduces risk. Organisations that depend on Threema or similar secure messaging tools for business-critical communication should consider whether they have alternative communication channels available in the event of a service disruption, and whether staff are aware of how to escalate or communicate during an outage. The incident also underscores the value of understanding the resilience and availability commitments of third-party communication platforms, and of reviewing whether service level agreements and incident response processes are appropriate for the organisation's operational needs. For UK organisations, this is a prompt to review whether business continuity plans account for communication platform outages, and whether alternative channels are available and tested.
UK organisations relying on Threema or similar secure messaging platforms should review whether business continuity plans account for communication platform outages. Ensure that alternative communication channels are available, tested, and that staff understand how to escalate or communicate during service disruptions. Consider whether service level agreements with communication platform providers are appropriate for the organisation's operational needs, and whether incident response processes are prepared to manage communication disruptions. Review whether ownership of business continuity planning is clear, and whether regular testing of alternative communication channels is part of routine resilience practice.
Source: Security Affairs