Tuta has suffered multiple DDoS attacks in one week – but it claims privacy has not been compromised

Tuta
(Image credit: Tuta)

Encrypted email service Tuta was the victim of multiple DDoS attacks this week.

The German-based provider first announced the incident with a post on X on Tuesday, December 3, 2024, with another attack causing the service downtime two days later. Tuta is said to have successfully mitigated both attacks, but some users are still lamenting issues accessing their accounts or using the service.

Short for Distributed Denial of Service, a DDoS attack's goal is to make a website, service, or machine inaccessible to users. Cybercriminals achieve this by flooding the targeted network with internet traffic to overwhelm their capacity to carry on with legitimate requests.

The impact on Tuta's users

"While we have to mitigate DDoS attacks constantly, and usually do so without the users noticing, the attackers used new attack vectors which our DDoS protection system was not prepared for," Hanna Bozakov, press officer at Tuta, told TechRadar, commenting on this week's incidents.

We are a privacy-focused service, we can not simply hide our application behind mitigation services

Matthias Pfau, Tuta's co-founder

DDoS attacks cause downtime to targeted networks as they become unable to respond to user queries. On a practical level, people using Tuta services couldn't get into their accounts.

While Tuta users couldn't access their mailbox for some time, Bozakov ensures that no emails received during the attack have been lost or users' privacy has been compromised. She said: "[Users' data] is encrypted end-to-end on our servers, and no data has been harmed. The attacks only aim at the availability of our service."

The team is currently working on hardening its systems against these types of attacks. As Matthias Pfau, co-founder of Tuta, explains, however, these incidents are among the challenges of building a privacy-first secure email service.

He said: "As we are a privacy-focused service, we can not simply hide our application behind mitigation services that require our SSL key for their service. This would be a violation of the trust that users put into Tuta Mail to keep their data safe and private."

We should support Tuta - especially NOW from r/tutanota

Tuta's sub-Reddit group has been filled with frustrated customers reporting connectivity issues starting on Monday, with the latest report being shared only a few hours ago.

The provider, however, confirms the attacks have now been mitigated. At the time of writing, Tuta's status page also confirmed that "all systems are operational."

If you are still experiencing issues accessing your inbox, this could mean your IP address has been blocked during the attacks by Tuta's DDoS protection system.

One of the best VPN apps could help here as it spoofs your IP by assigning you another one for each session. Bear in mind, though, that VPNs could also have been blocked by Tuta's mitigation systems as many people tried to use them during the attack.

Bozakov then suggests rather using a completely different connection to access your Tuta's app, such as another WI-Fi or mobile internet data.

The provider is still analyzing the attacks at the time of writing and is set to publish a detailed report of what happened in the coming days.

Chiara Castro
News Editor (Tech Software)

Chiara is a multimedia journalist committed to covering stories to help promote the rights and denounce the abuses of the digital side of life – wherever cybersecurity, markets, and politics tangle up. She writes news, interviews, and analysis on data privacy, online censorship, digital rights, cybercrime, and security software, with a special focus on VPNs, for TechRadar and TechRadar Pro. Got a story, tip-off, or something tech-interesting to say? Reach out to chiara.castro@futurenet.com

Read more
DDoS inscribed on a digital background made up of numbers
DDoS attacks take down game studio servers, causing DayZ and Arma network outages
DDoS attack
Japan’s largest telco NTT Docomo disrupted by DDoS attack
An image of network security icons for a network encircling a digital blue earth.
Standing strong against hyper-volumetric DDoS attacks
Shutterstock.com / kanlaya wanon
Microsoft Teams abused in Russian email bombing ransomware campaign
ID theft
Tata Technologies confirms ransomware attack, says investigation still ongoing
DDoS attack
Europol announces takedown of major DDoS-for-hire network
Latest in Cyber Security
ignal messaging application President Meredith Whittaker poses for a photograph before an interview at the Europe's largest tech conference, the Web Summit, in Lisbon on November 4, 2022.
"We will not walk back" – Signal would rather leave the UK and Sweden than remove encryption protections
Man uses a laptop in a hotel room
4 ways to avoid misinformation on social media and retain control of your newsfeed
Apple
"We will never build a backdoor" – Apple kills its iCloud's end-to-end encryption feature in the UK
DeepSeek
DeepSeek accused of sharing users' data with TikTok's ByteDance in another blow around privacy concerns
This photograph shows wordmark of Siri, a digital assistant developed by Apple Inc., displayed on a smartphone
Did Siri break the law? Apple's latest privacy complaint in France doesn't bode well
Artificial intelligence and white-collar workers are chatting in love on mobile phones, stock photo
Don't take AI on a Valentine's Day date – there's a hefty bill to pay that you'd never expect
Latest in News
Man adjusting settings on Garmin Fenix 6 watch
Garmin Fenix 6, Enduro, Marq and Tactix watches are getting fixes to solve some frustrating problems – here's what's new
Apple iPhone 16 Plus Review
iPhone 17 Air leaks suggest it'll get next-gen battery – and offset the 17 Pro Max's weight gains
King Charles III sat at his desk in promo for his radio broadcast for Apple Music 1
Apple Music gets the royal treatment with special King Charles show – and the playlist has some real jewels
ExpressVPN's new Linux app interface
ExpressVPN releases a major upgrade to its Linux app
Nvidia geforce 4070
Don’t panic, gaming laptop buyers – Nvidia assures us that mobile RTX 5000 graphics cards won’t have the chip-level fault that hit desktop GPUs
Google Chrome logo on desktop and mobile
Google Chrome launches better warning labels to make sure you know you're using a company profile