On Tuesday evening, August 11, 2026, the Swiss encrypted messaging service Threema lost availability for several hours. The site went down again on Wednesday morning, after a series of large-scale DDoS attacks hit both its own infrastructure and its colocation partner, Nine.
In the post-mortem it published on Friday, Threema explained why mitigation proved difficult: the attacker continuously altered traffic sources and attack patterns to work around each defensive measure.
According to Threema’s announcement following the disruption to their services, DDoS attacks against their service are normally mitigated without any noticeable impact, because those defenses adapt to the attack patterns they observe. On Tuesday, however, the attacker changed patterns faster than the defenses adapted. The result was that a service built on strong infrastructure was disrupted for parts of two consecutive days.
Bottom line: Deployed DDoS protection only covers the attack patterns its policies anticipate. This leaves large-scale enterprises including companies like Threema vulnerable to the unexpected: new and evolving DDoS attacks.
What Happened in the Threema DDoS Attack of August 2026?
Threema reported that its service was temporarily unavailable or only partially available on Tuesday evening and Wednesday morning. Users in Switzerland, India, and China continued reporting problems into Wednesday even while the company status page showed no issues, and full operation returned around midday.
The first public explanation pointed to a network outage on the colocation partner’s side, but the picture changed as the attacks continued. The attacks targeted both Threema and Nine. As Threema noted, it is not entirely clear whether Threema was the primary target or whether the attacks were directed at multiple targets. Availability risk travels through the supply chain, and an organization inherits the exposure of the infrastructure underneath it.
Note that organizations running Threema On-Prem. saw no disruption, because they rely on their own infrastructure. This means that the same application, delivered over different infrastructure, produced a different availability outcome because the vulnerability was inherent to the delivery path (not the software).
Why Changing DDoS Attack Patterns Defeat Static Mitigation Configurations
DDoS security differs from most areas of cybersecurity because the vulnerability isn’t in the application. Rather, it’s in the defenses and their configurations: mitigation policies, rate limits, scrubbing rules, routing decisions, and how each protection layer aligns with the ones around it.
Typically, those configurations get tuned against attack patterns that are known. But an attacker who rotates traffic sources and vectors is running a live search for the patterns the configuration does not cover, and every rotation is a free experiment. Threema described that behavior directly, observing that attackers with significant technical and financial resources can rapidly alter attack methods to bypass defensive measures.
Moreover, vulnerabilities develop continuously in large enterprise environments as environments drift. Services get added, routing changes, new vendors come onboard, and policies accumulate exceptions. As a result, there is typically a gap between the configuration of DDoS defenses, and the environment that they are protecting. A configuration validated in March does not accurately reflect the environment that an attacker may encounter in August.
DDoS Attacks in Switzerland 2026: Salt, Davos and Federal Targets
Threema is the most recent Swiss availability incident, but it is not the only one Switzerland has seen this year.
On May 15, 2026, Swiss operator Salt confirmed that a DDoS attack, rather than a routine technical fault, took its fixed-line internet service offline for roughly 40 minutes, as reported by SwissCybersecurity.net. The attack affected the fixed-line services; mobile service kept running, although Swisscom and Sunrise customers could not reach numbers on the Salt network during the disruption. As a critical infrastructure operator, Salt was required to report the incident to Switzerland’s Federal Office for Cybersecurity within 24 hours under the reporting duty that took effect in April 2025.
Switzerland’s profile as a host of international institutions, private banking, and privacy-focused technology keeps it on hacktivist target lists. In a report published in March 2026, the Swiss Federal Office for Cybersecurity recorded 325 cyberattacks against critical infrastructure in the second half of 2025, with roughly 16 percent of reported incidents categorized as DDoS. Swiss federal websites were also disrupted by pro-Russian DDoS activity during the World Economic Forum in Davos in January 2024, when the group NoName057(16) claimed responsibility.
Why Messaging Platforms, ISPs and Telecom Operators are DDoS Targets
Messaging platforms, ISPs, and telecom operators share a property that makes them attractive DDoS targets: When they go down, everything “downstream” goes down with them, and the disruption reaches users who have no relationship with the attacker or the target.
MazeBolt’s Q1 2026 DDoS Threat Landscape Report recorded availability attacks across this sector, including the ISP Inter.link in February 2026 and a March 2026 campaign against Romanian infrastructure in which NoName057(16) targeted banks, insurers, rail operators, logistics companies, and telecom providers. In December 2025 a suspected DDoS attack disrupted La Poste in France, degrading parcel tracking, the Digiposte digital vault, and online and mobile banking at La Banque Postale.
The pattern across those incidents is consistent. Every organization involved had DDoS protection deployed. The attacks caused damaging downtime anyway, because deployed protection and proven protection are two different states.
How Continuous DDoS Validation Proves What Mitigation Actually Works
MazeBolt RADAR™ is the independent validation layer for DDoS protection, providing continuous proof of resilience for enterprises whose online services cannot afford damaging downtime. RADAR runs thousands of simulations a year against live production without maintenance windows, designed to run without affecting service availability or SLA response times.
MazeBolt’s validation data shows that 37% of attack vectors, on average, bypass deployed DDoS protections.
RADAR eliminates the risk of damaging DDoS downtime by enables a validate, remediate, revalidate sequence:
- Validation reveals which attack vectors reach the target
- Remediation strengthens the defenses
- Revalidation proves the fix held
RADAR provides current, independent evidence of what deployed DDoS protection blocks, where vulnerabilities remain, and whether remediation continues to hold. RADAR does not replace DDoS mitigation. It turns protection into proven resilience: certainty you can act on.
Want to learn more about how to validate your DDoS defenses? Speak with an expert.
Key Takeaways about the Threema DDoS Attack
- Large-scale DDoS attacks against Swiss messaging service Threema and its colocation partner, Nine, caused outages across Tuesday evening and Wednesday morning in August 2026.
- Threema reported that the attacker continuously changed traffic sources and attack patterns, which is what made mitigation difficult.
- Organizations running Threema On-Prem saw no disruption, because availability risk follows the delivery path rather than the application.
- Swiss operator Salt lost fixed-line internet service for roughly 40 minutes on 15 May 2026 in a confirmed DDoS attack.
- MazeBolt’s 2026 validation data shows that 37% of attack vectors, on average, bypass deployed DDoS protection; continuous independent validation identifies first.