Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code

June 6, 2026

How Proton Fights Against Cybercriminals Using Its Services

June 5, 2026

Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer

June 5, 2026
Facebook X (Twitter) Instagram
Saturday, June 6
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»How Proton Fights Against Cybercriminals Using Its Services
News

How Proton Fights Against Cybercriminals Using Its Services

Team-CWDBy Team-CWDJune 5, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


It has become common to observe cyber threat actors using a Proton Mail email address to run their operations. The result is that the Switzerland-based privacy-focused service provider is facing a difficult balancing act: stop cybercriminals from exploiting its services while preserving the end-to-end encryption and privacy guarantees that define the brand.

Proton made its debut at Infosecurity Europe in 2026 and in conversation with Infosecurity, Raphael Auphan, the COO, described how the company approaches that tension through engineering, operational controls and strict legal processes.

Auphan emphasized that Proton’s technical architecture imposes clear limits on what the company can do.

“We cannot access message contents because we don’t have the keys, and we cannot geolocate our users, as end-to-end encryption is part of our privacy model,” he said. That cryptographic constraint, he explained, is central to user trust but means content-level surveillance or forced decryption is simply not possible.

Faced with that limitation, Proton invests heavily in account-level and behavioral defenses.

Auphan reported that Proton has a dedicated anti-abuse team that builds machine‑learning models to detect suspicious account-creation patterns and other signals of misuse.

Those systems focus on identifying bot-driven clusters, automated mass sign-ups and other early indicators so malicious actors can be stopped prior to carrying out operations that rely on Proton accounts.

Takedown Requests Must Be Lawful and Legitimate

When unlawful activity does occur, Proton’s response is shaped by Swiss law and strict verification steps.

While the company cannot hand over encrypted message contents, it can close accounts, provide available metadata and hand over this information to vetted law enforcement and help investigations – as long as they follow lawful processes and are motivated by legitimate reasons.

Auphan said that the company receives a “significant amount” of such requests from all over the world.

To get Proton onboard, however, he explained that requests should go through Interpol or the Swiss federal police for validation, so that only after Swiss authorities vet a submission Proton will act.

“When legitimate requests come in, they must be routed through Swiss federal authorities and legally verified before we act,” Auphan noted.

Additionally, even if the law enforcement followed the right processes, Proton will only act if it deems the request legitimate.

“It needs to come from true suspicion of malicious, or even criminal, activity. We would not take down the account of an individual for an political opponent,” said Auphan.

The executive acknowledged the trade-offs involved, as anti-abuse systems that rely on behavioral signals can raise privacy and false‑positive concerns and denying content access even to fight crime can frustrate investigators.

Still, he argued that Proton’s approach aims to strike the right balance.

“We have no interest in allowing malicious actors to use our platform,” Auphan concluded.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleThreat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer
Next Article Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code
Team-CWD
  • Website

Related Posts

News

Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code

June 6, 2026
News

Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer

June 5, 2026
News

Infosecurity Europe: Reactive Security Is Failing Healthcare, Experts

June 5, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Can password managers get hacked? Here’s what to know

November 14, 2025

The hidden risks of browser extensions – and how to avoid them

September 13, 2025

What are brushing scams and how do I stay safe?

December 24, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.