<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>The Proton Blog</title><description>News from the front lines of privacy and security</description><link>https://proton.me/</link><language>en</language><feed_url>https://proton.me/feed</feed_url><item><title>Proton partners with Apertus, Switzerland&amp;#8217;s sovereign AI model</title><link>https://proton.me/blog/lumo-apertus-partnership</link><guid isPermaLink="true">https://proton.me/blog/lumo-apertus-partnership</guid><description>Proton has partnered with the team behind Apertus, adding their sovereign AI model to its privacy-first AI chatbot Lumo.</description><pubDate>Thu, 17 Sep 2026 11:56:33 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton is partnering with the team behind Apertus to bring its new Apertus 1.5 model to Lumo, Proton&amp;#8217;s privacy-focused alternative to ChatGPT. The partnership will also give researchers behind Apertus access to real-world feedback that can help them improve it more quickly.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Apertus is a fully open large language model developed by researchers at &lt;a href=&quot;https://actu.epfl.ch/news/apertus-s-associe-a-lumo-l-assistant-ia-de-proton/&quot;&gt;EPFL&lt;/a&gt;, &lt;a href=&quot;https://ethz.ch/de/news-und-veranstaltungen/eth-news/news/2026/09/apertus-arbeitet-neu-mit-dem-ki-assistenten-lumo-von-proton-zusammen.html&quot;&gt;ETH Zurich&lt;/a&gt;, and the Swiss National Supercomputing Centre (CSCS). Its architecture, training data, and methods are open, and it’s trained on publicly available data, respecting opt-out requests and filtering out personal details. It fills an important role in today&amp;#8217;s AI landscape by providing a fully open source model with a transparent and reproducible training pipeline. In a world dominated by US and Chinese models, Apertus is instrumental in Europe&amp;#8217;s tech sovereignty.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The world’s leading AI models have millions of people using them every day, creating real-world feedback loops that help make them better. Fully open models developed in an academic context do not have access to feedback at the same scale, limiting their ability to compete at the frontier.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;With this partnership, that could start to change. Proton is introducing a feedback mechanism that connects people using Apertus in Lumo with the researchers building it. Tens of millions of Lumo users around the world can now choose to contribute feedback, helping independent, ethical, and truly open source AI become more competitive.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Building a European alternative&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Europe now has the pieces of an independent AI stack: infrastructure it controls, a model open by design, and a product that puts it directly in people’s hands.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&amp;#8220;We don’t want to spend the next decade relying on other countries for the AI we use every day,&amp;#8221; said Eamonn Maguire, Director of AI at Proton. &amp;#8220;Having our own AI isn’t enough. It needs to be competitive so that people actually use it. This partnership with the Swiss AI Initiative gives Europe a path to get there.&amp;#8221;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;One of the biggest advantages leading AI labs have is a constant stream of feedback from millions of people using their models. Bringing Apertus to Lumo gives the university research teams behind it access to this feedback at scale, helping level the playing field.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Apertus in Lumo today&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;To start using Apertus in Lumo, select Apertus 1.5 from the model dropdown, and start chatting as normal. Like other conversations in Lumo, your chats are protected by zero-access encryption and stay private by default.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you choose to give feedback on an Apertus response, tap the thumbs-up or thumbs-down button to send in your feedback. Your contribution will be anonymized, and made available to the university research teams behind Apertus.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;“Real-world feedback is the one ingredient that open models have been missing. Thanks to Proton, Lumo users will be able to voluntarily provide feedback that contributes to Apertus research. For a fully open, publicly developed model, that is a game changer,” says Imanol Schlag, Research Scientist at the ETH AI Center and co-lead of the Apertus project.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;“Making Apertus available in Lumo gives us valuable insights into how the model performs in real-world settings. Voluntary feedback also helps us identify where it can be made more useful and more robust,” says Martin Jaggi, Professor at EPFL and co-lead of the Apertus project. “It also means that we are enabling a broader community to contribute to the model’s further improvement.”&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Why work together&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Building an open and independent AI ecosystem is bigger than any one model or company. To compete in AI, Europe needs to pool its resources and build public-private partnerships that can do what no single organization can achieve alone. Europe&amp;#8217;s future in AI depends on researchers building in the open, infrastructure governed in Europe, companies turning that technology into products people can use, and people willing to help those technologies improve.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Through this partnership, we are taking steps to make that alternative more than an idea. Starting today, fully open source AI is now something people can use and — if and when they choose to — help shape for the future.&lt;/p&gt;



&lt;div class=&quot;flex flex-wrap justify-center gap-2&quot;&gt;
&lt;a class=&quot;btn inline-block rounded-full font-bold btn-small btn-solid-purple&quot; href=&quot;https://lumo.proton.me/&quot;&gt;Try Lumo now&lt;/a&gt;
</content:encoded><category>Lumo AI</category><category>Proton updates</category><author>Eamonn Maguire</author></item><item><title>87% of Canada&amp;#8217;s biggest companies depend on US tech</title><link>https://proton.me/business/blog/canada-us-tech</link><guid isPermaLink="true">https://proton.me/business/blog/canada-us-tech</guid><description>Our latest research found that 87% of Canada’s largest companies and 100% of government domains rely on US-owned email infrastructure.</description><pubDate>Thu, 17 Sep 2026 11:48:36 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;It’s clearer than ever that too much of the technology the world relies on is controlled by too few tech giants, most of them based in the United States and China.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/drive&quot;&gt;Cloud storage&lt;/a&gt;, web hosting, &lt;a href=&quot;https://proton.me/business/mail&quot;&gt;email&lt;/a&gt;, social media, &lt;a href=&quot;https://proton.me/business/meet&quot;&gt;video calling&lt;/a&gt;, communication platforms, and the basic productivity tools that companies and governments use every day have become essential infrastructure. The modern economy cannot function without them. And control over that infrastructure gives both providers — and the countries whose laws they operate under — outsized power over everyone who depends on it.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;We’ve been tracking this concentration for some time. Our previous research found that 74% of publicly listed &lt;a href=&quot;https://proton.me/business/europe-tech-watch&quot;&gt;European companies rely on US tech&lt;/a&gt;, fueling a wider debate in Europe about economic security, digital sovereignty, and geopolitical risk.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Now we&amp;#8217;ve found that Canada is even more exposed than Europe. We examined 220 publicly listed companies representing 70% of the Canadian stock market’s total capitalization and found that 87% rely on US-owned infrastructure for their email. The same was true for 84% of the 100 largest municipalities. We also found that 14 out of 14 federal, provincial, and territorial government domains rely on American email infrastructure.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;To be clear, the problem is not that these companies are American. The risk comes when too much of the infrastructure the world depends on sits under the control and jurisdiction of any single government. At a time of increasing geopolitical tensions and trade negotiations, we believe it&amp;#8217;s important to fully understand the different levers that one country can hold over another behind the scenes.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full&quot;&gt;&lt;img width=&quot;2400&quot; height=&quot;744&quot; data-public-id=&quot;wp-pme/us-tech-reliance-across-sectors-in-canada/us-tech-reliance-across-sectors-in-canada.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_2400,h_744,c_scale/f_auto,q_auto/v1789637989/wp-pme/us-tech-reliance-across-sectors-in-canada/us-tech-reliance-across-sectors-in-canada.png?_i=AA&quot; alt=&quot;A diagram showing the US tech reliance across different sectors in Canada&quot; class=&quot;wp-post-296473 wp-image-296474&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;195 KB&quot; data-optsize=&quot;46 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;76.5&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=296474&quot; data-version=&quot;1789637989&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1789637989/wp-pme/us-tech-reliance-across-sectors-in-canada/us-tech-reliance-across-sectors-in-canada.png?_i=AA 2400w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_93,c_scale/f_auto,q_auto/v1789637989/wp-pme/us-tech-reliance-across-sectors-in-canada/us-tech-reliance-across-sectors-in-canada.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_317,c_scale/f_auto,q_auto/v1789637989/wp-pme/us-tech-reliance-across-sectors-in-canada/us-tech-reliance-across-sectors-in-canada.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_238,c_scale/f_auto,q_auto/v1789637989/wp-pme/us-tech-reliance-across-sectors-in-canada/us-tech-reliance-across-sectors-in-canada.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_476,c_scale/f_auto,q_auto/v1789637989/wp-pme/us-tech-reliance-across-sectors-in-canada/us-tech-reliance-across-sectors-in-canada.png?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_2048,h_635,c_scale/f_auto,q_auto/v1789637989/wp-pme/us-tech-reliance-across-sectors-in-canada/us-tech-reliance-across-sectors-in-canada.png?_i=AA 2048w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_486,c_scale/f_auto,q_auto/v1789637989/wp-pme/us-tech-reliance-across-sectors-in-canada/us-tech-reliance-across-sectors-in-canada.png?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 2400px) 100vw, 2400px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;h2 class=&quot;wp-block-heading&quot;&gt;How we measured Canada&amp;#8217;s dependence on US tech&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;We collected the data using the same method as our earlier research in Europe. Using public DNS lookups, we identified the mail exchange (MX) records associated with each organization’s domain. These records show which companies handle an organization’s email, either directly or through an email security service.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For Canada, we looked at three parts of the economy and public sector:&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Federal, provincial, and territorial governments.&lt;/strong&gt; We examined all 14 federal, provincial and territorial domains. Of these, all 14 rely on &lt;a href=&quot;https://proton.me/business/microsoft-365-alternative&quot;&gt;Microsoft 365&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Companies.&lt;/strong&gt; We analyzed the 220 companies in the S&amp;amp;P/TSX Composite Index, which together account for around 70% of the Canadian stock market’s total capitalization. Of the companies reviewed, 161 used &lt;a href=&quot;https://proton.me/business/microsoft-365-alternative&quot;&gt;Microsoft 365&lt;/a&gt; and nine used &lt;a href=&quot;https://proton.me/business/google-workspace-alternative&quot;&gt;Google Workspace&lt;/a&gt; for their email infrastructure.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Municipalities.&lt;/strong&gt; Canada has more than 4,000 local governments, so we focused on the country’s 100 largest municipalities by population. Of those, 77 used Microsoft and one used Google.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Why this matters&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The problem with this arrangement is quite simple: One company, headquartered in one country, operating under one country&amp;#8217;s laws, carries the email of an entire G7 nation&amp;#8217;s governments.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;US law gives that country real power. Under the CLOUD Act, US authorities can compel American tech companies to hand over data they hold,&amp;nbsp;including data stored outside the US. When the US placed sanctions on the International Criminal Court, for example, &lt;a href=&quot;https://www.theregister.com/2026/02/18/microsoft_asks_uk_parliament_to_correct_record/&quot;&gt;Microsoft cut off the email account of the court&amp;#8217;s chief prosecutor&lt;/a&gt; — a move Microsoft initially told UK lawmakers was the ICC&amp;#8217;s own decision, before acknowledging that testimony was inaccurate. Access to infrastructure can be withdrawn on political terms and virtually overnight.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;AWS, Microsoft Azure, and Google Cloud serve an estimated&amp;nbsp;85% of the European cloud market&amp;nbsp;— and when one of them fails, the failures cascade.&amp;nbsp;A major &lt;a href=&quot;https://proton.me/business/blog/aws-outage&quot;&gt;AWS outage&lt;/a&gt; in late 2025&amp;nbsp;crashed apps across industries;&amp;nbsp;&lt;a href=&quot;https://www.reuters.com/technology/microsoft-azure-down-thousands-users-downdetector-shows-2025-10-29&quot;&gt;an Azure outage followed nine days later&lt;/a&gt;, knocking &lt;a href=&quot;https://proton.me/business/mail/outlook-alternative&quot;&gt;Outlook&lt;/a&gt;, &lt;a href=&quot;https://proton.me/business/meet/microsoft-teams-alternative&quot;&gt;Teams&lt;/a&gt;, and dozens of enterprise services offline for eight hours.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Much of the email infrastructure used by Canadian companies and governments depends on Microsoft, leaving them exposed to the same kind of service disruption.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;These risks, however, exist regardless of which country holds leverage. A world where one government can lawfully reach into the central communications of other nations is the problem, no matter who that government is, and wherever its companies are headquartered.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Canadians are already reacting&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The dependence we measured in Canada&amp;#8217;s public and private sectors comes amid a wider rupture in Canada-US relations, including retaliatory tariffs matched dollar for dollar and trade talks that broke down in a very public manner.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This backdrop is already shaping how Canadians see their tech dependence.&amp;nbsp;&lt;a href=&quot;https://www.politico.com/newsletters/digital-future-daily/2026/02/02/canadas-digital-sovereignty-dilemma-00760361&quot;&gt;Politico&amp;#8217;s reporting&lt;/a&gt; on Canada&amp;#8217;s digital sovereignty dilemma&amp;nbsp;describes a country forging its own path to reduce reliance on American tech, noting that its smaller economy and US-tied tech industry severely limit its bargaining power. This mirrors the shift we documented in Europe over the last year, where our research found&amp;nbsp;&lt;a href=&quot;https://proton.me/blog/european-alternative-us-tech-survey&quot;&gt;73% of Europeans believe their societies rely too heavily on US tech&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href=&quot;https://proton.me/business/blog/european-digital-independence-survey-2026&quot;&gt;56% now say local infrastructure matters more to them than a year ago&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Canada&amp;#8217;s position differs from Europe&amp;#8217;s in one important way: European institutions have moved from diagnosis to legislation, with the European Commission&amp;#8217;s&amp;nbsp;&lt;a href=&quot;https://proton.me/business/blog/eu-tech-sovereignty-package&quot;&gt;tech sovereignty package&lt;/a&gt;&amp;nbsp;committing major funding to local alternatives. Canadian institutions haven&amp;#8217;t announced migration plans, and we&amp;#8217;re not the ones to call for it. Proton is a Swiss company. What we can do is show what the data says and what it implies for anyone who depends on these systems, including what&amp;nbsp;&lt;a href=&quot;https://proton.me/business/blog/europe-us-tech-dependence-qwant&quot;&gt;Europe&amp;#8217;s slow, imperfect transition&lt;/a&gt;&amp;nbsp;reveals about how hard these moves are in practice.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What any organization can do about it&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For Canadian businesses and institutions assessing their own exposure, the starting steps are concrete:&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;List every third-party tool you use:&lt;/strong&gt; Flag which are headquartered outside Canada and which of those fall under a foreign government&amp;#8217;s legal jurisdiction.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Identify what would stop your operations:&lt;/strong&gt;&amp;nbsp;Which tools, cut off tomorrow, would halt work? This belongs in &lt;a href=&quot;https://proton.me/business/business-continuity&quot;&gt;business continuity&lt;/a&gt; planning.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Check where your data sits:&lt;/strong&gt;&amp;nbsp;Which country&amp;#8217;s laws govern it? Who can access it, and through what legal process?&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Test the alternatives:&lt;/strong&gt;&amp;nbsp;For most critical tools, Canadian and European alternatives are available, and some offer built-in tools that make switching easier, such as Proton&amp;#8217;s &lt;a href=&quot;https://proton.me/easyswitch&quot;&gt;Easy Switch&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Move the highest-risk services first:&lt;/strong&gt;&amp;nbsp;Full migration takes time. Start with the systems you can&amp;#8217;t operate without.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When your &lt;a href=&quot;https://proton.me/business/mail&quot;&gt;business email&lt;/a&gt; relies on US tech companies, you&amp;#8217;re exposing your organization to strategic risks that, at the end of the day, are out of your control.&lt;/p&gt;
</content:encoded><category>For business</category><author>Raphael Auphan</author></item><item><title>8 more privacy tools experts actually use</title><link>https://proton.me/blog/more-privacy-tools-experts-use</link><guid isPermaLink="true">https://proton.me/blog/more-privacy-tools-experts-use</guid><description>See the tech tools used by privacy experts, from a DIY smartwatch and travel router to Tails, Linux, Pi-hole, and offline Wikipedia.</description><pubDate>Tue, 15 Sep 2026 18:02:32 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Privacy technology does not have to mean replacing every device you own or learning how to build your own computer.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;There are plenty of smaller changes you can make to adjust the way you use technology. You can keep information offline, block trackers across your home network, choose software that gives you more control, or even carry an entire operating system on a USB drive.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The tools below take different approaches to privacy, but they share a common idea: you get to decide how your technology works instead of simply accepting its default settings.&lt;/p&gt;



&lt;figure class=&quot;wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio&quot;&gt;&lt;div class=&quot;wp-block-embed__wrapper&quot;&gt;
&lt;iframe loading=&quot;lazy&quot; title=&quot;Seven Gadgets A Security Expert Actually Trusts&quot; width=&quot;750&quot; height=&quot;422&quot; src=&quot;https://www.youtube-nocookie.com/embed/3VJ5Htyhm7k?feature=oembed&quot; frameborder=&quot;0&quot; allow=&quot;accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share&quot; referrerpolicy=&quot;strict-origin-when-cross-origin&quot; allowfullscreen&gt;&lt;/iframe&gt;
&lt;/div&gt;&lt;/figure&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Build a smartwatch that only does what you want&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Many smartwatches are designed to work alongside an app and an online account. Your activity data is collected by the watch, transferred to another device, and potentially sent onwards to a company&amp;#8217;s servers.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You can take a different approach with &lt;a href=&quot;https://watchy.sqfmi.com/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Watchy&lt;/a&gt;, a small programmable computer designed to be used as an open-source smartwatch. Because you can program the device yourself, you get to decide what it does and what information it collects. You could use it for something as simple as counting your steps without requiring an account or constantly syncing your activity to a remote service.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The data can either stay on the device or transfer it to your computer. You can also customize the watch with your own features, information, and displays. This makes Watchy an interesting alternative to more ubiquitous smartwatch brands if you want the functionality of a wearable without automatically handing control of the experience to a third party.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Use Flipper Zero to understand wireless technology&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A surprising amount of everyday technology communicates wirelessly. Your garage door opener, office access system, television remote, and other devices all rely on different kinds of wireless signals to communicate. Most of the time, you never see any of this happening.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://flipperzero.one/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Flipper Zero&lt;/a&gt; gives you a way to experiment with some of those signals. It can read, save, and replicate certain wireless communications, depending on the technology and security involved.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For example, you can use it with a compatible infrared remote. The device can capture the signal sent by the remote, store it, and transmit the same command itself. That does not mean it can unlock or control everything around you. What it can interact with depends on the particular technology being used.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The real value is educational. Instead of treating wireless communication as something invisible happening in the background, you can use a Flipper Zero device to understand how some of it actually works.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Keep Wikipedia in your pocket with Kiwix&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://kiwix.org/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Kiwix&lt;/a&gt; lets you download large collections of information so you can access them offline. One of the best-known examples is Wikipedia, which you can store locally and search without being connected to the internet.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That can be useful when you&amp;#8217;re travelling somewhere with unreliable connectivity, spending an extended amount of time in a remote location, or simply want access to information without constantly requesting it from an online service.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;There is one obvious limitation: your offline library is only as current as the version you downloaded. But once the content is stored on your device, you do not need a live connection to access it.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It is a useful reminder that you do not have to depend on the internet for every piece of information you need. Sometimes, you can simply keep the information yourself.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Turn an old iPod into a dedicated music player&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You probably already have a device that can play music. Your phone can stream millions of songs, recommend something based on your listening habits, and keep your entire library in the cloud. But if all you want is a device that plays your music, an old iPod Classic can still do the job.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;With alternative software such as &lt;a href=&quot;https://www.rockbox.org/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Rockbox&lt;/a&gt;, you can give an iPod Classic a new lease on life. Hardware modifications can also bring it up to date with features such as USB-C. The result can be deliberately simple. You load your own music onto the device, much like copying files to a USB drive, and listen without needing a streaming subscription or account.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That way, there are no recommendations for deciding what you should listen to next. Nor is there a need for a service to track your listening habits as your music library can simply remain on the device. You can even use the extra storage for things such as important phone numbers or other information you might want available when your phone is unavailable.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Sometimes privacy means choosing a device that does less.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Block trackers across your home network with Pi-hole&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Your phone is not the only device that can connect to advertising and tracking services. Your laptop, smart TV, tablet, and other connected devices can all make requests to servers around the internet.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://pi-hole.net/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Pi-hole&lt;/a&gt; lets you filter some of those requests at the network level. You can run Pi-hole on a small computer like a Raspberry Pi. It sits between the devices on your network and the wider internet, checking where they are trying to connect. Requests to destinations on your blocklist can then be stopped before they leave your network.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Because Pi-hole operates at the network level, you can use it to cover multiple devices at once. This can be particularly useful for devices such as smart TVs, where installing conventional ad-blocking software may not be possible. You can also see the requests being made by devices on your network, including the ones Pi-hole has blocked.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For even more local control, you can combine Pi-hole with &lt;a href=&quot;https://nlnetlabs.nl/projects/unbound/about/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Unbound&lt;/a&gt;. Instead of relying entirely on another company&amp;#8217;s DNS server to resolve website addresses, your own system can handle more of that work and store the answers locally. Your home network becomes something you can inspect and manage rather than a black box.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you want to try it yourself, check out our guide explaining &lt;a href=&quot;https://protonvpn.com/blog/pi-hole&quot;&gt;how to set up a Pi-hole&lt;/a&gt; and use it to filter DNS requests across your network.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Take your own network with you when you travel&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Hotel Wi-Fi can become awkward when you have several devices. You might have to connect your phone, laptop, tablet, and other hardware individually, and some hotels place limits on how many devices you can use. A travel router gives you another option.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Instead of connecting every device directly to the hotel&amp;#8217;s network, you connect the router to the hotel Wi-Fi. Your devices then connect to your router. That means you only have to deal with the hotel&amp;#8217;s network once. Your own devices can stay connected to the network you&amp;#8217;ve configured, even if you&amp;#8217;re travelling with several of them.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You can also run a VPN directly on the router. Traffic from the devices connected to it can then pass through the VPN connection before reaching the internet. A travel router is a small piece of hardware, but it gives you considerably more control over how your devices connect when you&amp;#8217;re away from home.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Our guide to &lt;a href=&quot;https://protonvpn.com/blog/setup-a-vpn-router&quot;&gt;setting up a VPN on your router&lt;/a&gt; explains how router-level VPN protection works and how it can cover devices across a network.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Choose a laptop you can repair and customize&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A laptop does not have to be a closed system that gets replaced when something goes wrong. &lt;a href=&quot;https://frame.work/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Framework&lt;/a&gt; laptops are designed so you can open them up, replace components, upgrade parts, and customize the hardware. Even the ports are modular, allowing you to swap one type for another when your needs change. That philosophy extends to the software if you run Linux.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Linux gives you more control over what is running on your computer and most Linux distributions are largely open source. That means the underlying code can be inspected by developers and researchers rather than requiring you to rely entirely on a company&amp;#8217;s description of what its software does.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Open-source software is not automatically private or secure. But having access to the underlying code gives you another level of control over the technology you use.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Together, repairable hardware and open-source software let you take greater ownership of both the physical computer and the software running on it.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Carry a privacy-focused operating system on a USB drive&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You can carry an entire privacy-focused computer environment without carrying another computer.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://tails.net/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Tails&lt;/a&gt; is an operating system designed around privacy that you can boot from a USB drive on a compatible computer. Instead of using the operating system already installed on the machine, you can start the computer using Tails.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Internet traffic is routed through the &lt;a href=&quot;https://www.torproject.org/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Tor&lt;/a&gt; network, which sends connections through multiple relays to make it harder to determine where they originally came from. Tails is also designed to be amnesic. When you shut it down, it aims to leave as little trace as possible on the computer you were using.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That makes a USB drive containing Tails something like a portable privacy setup. You can carry your preferred operating system with you and use it on a compatible computer without relying on the machine&amp;#8217;s usual operating system.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It is an extreme example of the same principle behind many of the other tools here: you can have more control over the technology you use, even when you are away from your own devices.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you want to understand how Tor and VPNs differ, Our guide to &lt;a href=&quot;https://protonvpn.com/blog/tor-vpn&quot;&gt;Tor over VPN&lt;/a&gt; explains how the two technologies provide different layers of privacy.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Start with one change&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You do not need a programmable smartwatch, a modified iPod, or a privacy-focused operating system on a USB drive to take more control over your technology.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Each of these tools represents a different way to change a default. You can keep your data locally instead of automatically syncing it. You can block trackers at the network level. You can store information offline, choose open-source software, or create your own network when travelling.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You can also start much smaller. Check which permissions your existing apps have. Think about whether an app actually needs access to your location, microphone, or other device features. Look at which services require accounts and which information is being stored remotely.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You also do not have to change everything at once. One deliberate choice can reduce the amount of information you hand over by default.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Privacy does not require completely changing how you use technology. It can start with deciding that one part of your technology should work differently.&lt;/p&gt;
</content:encoded><category>Videos</category><author>Proton Team</author></item><item><title>What does CC mean in emails? To, CC, and BCC explained</title><link>https://proton.me/business/blog/what-is-to-cc-bcc</link><guid isPermaLink="true">https://proton.me/business/blog/what-is-to-cc-bcc</guid><description>Learn the different ways to send an email to multiple email addresses with our explainer on To, CC, and BCC.</description><pubDate>Fri, 11 Sep 2026 18:57:00 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;CC (carbon copy) and BCC (blind carbon copy) are standard email features that control who receives a message and what information they can see.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Understanding the difference between To, CC, and BCC is crucial in a business context. CC the wrong person and your client sees an internal aside they shouldn&amp;#8217;t have. Forget to CC a decision-maker and they never see an email thread they really needed to.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Keep reading to find out which option to select to communicate clearly (to the right recipient/s), avoid unnecessary replies, protect recipients’ &lt;a href=&quot;https://proton.me/blog/what-is-email-address&quot;&gt;&lt;u&gt;email addresses&lt;/u&gt;&lt;/a&gt;, and safeguard sensitive information.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What does CC mean?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;CC stands for Carbon Copy, a throwback to a time when physical, handwritten memos or letters would be &lt;a href=&quot;https://en.wikipedia.org/wiki/Carbon_copy&quot;&gt;&lt;u&gt;replicated using a sheet of carbon paper&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;CC allows you to send a copy of an email to multiple recipients who are not the primary recipient in the To field. The primary recipient will see the email address(es) you have entered into the CC field, and any responses from them. Likewise, the person you have CCd will see any responses from the recipient (unless they&amp;#8217;re removed from the CC field, or the recipient clicks Reply instead of Reply all).&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;CC&amp;#8217;ing is especially useful when sending &lt;a href=&quot;https://proton.me/business/mail&quot;&gt;&lt;u&gt;business emails&lt;/u&gt;&lt;/a&gt;, because you can add as many recipients into an email as you like, all of whom will receive a copy of the same email and see each other&amp;#8217;s addresses and responses. This keeps everyone in the loop and creates a transparent record of the conversation without requiring a response.&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;a href=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1707569552/wp-pme/bcc-and-cc-1/bcc-and-cc-1.png?_i=AA&quot;&gt;&lt;img width=&quot;1024&quot; height=&quot;862&quot; data-public-id=&quot;wp-pme/bcc-and-cc-1/bcc-and-cc-1.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_862,c_scale/f_auto,q_auto/v1707569552/wp-pme/bcc-and-cc-1/bcc-and-cc-1.png?_i=AA&quot; alt=&quot;&quot; class=&quot;wp-post-10543 wp-image-12683&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;78 KB&quot; data-optsize=&quot;24 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;69.3&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=12683&quot; data-version=&quot;1707569552&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_862,c_scale/f_auto,q_auto/v1707569552/wp-pme/bcc-and-cc-1/bcc-and-cc-1.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_253,c_scale/f_auto,q_auto/v1707569552/wp-pme/bcc-and-cc-1/bcc-and-cc-1.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_647,c_scale/f_auto,q_auto/v1707569552/wp-pme/bcc-and-cc-1/bcc-and-cc-1.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1707569552/wp-pme/bcc-and-cc-1/bcc-and-cc-1.png?_i=AA 1268w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;/a&gt;&lt;/figure&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;When to use CC in email&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;CC is a useful function when you need someone (or multiple people) other than the recipient to know about and follow an &lt;a href=&quot;https://proton.me/blog/what-is-an-email-thread&quot;&gt;&lt;u&gt;email thread&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For example, when you want to loop in an entire project team on something that affects everyone&amp;#8217;s work, such as a scope or deadline change, you can simply CC them in.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;CC&amp;#8217;ing can also be helpful when you want particular individuals to have visibility of an email thread without requiring their input. When emailing a client proposal, for example, you might want to CC anyone directly involved in the project so they have visibility of their feedback and your subsequent discussion. If anything gets escalated or referenced in a review later, they&amp;#8217;re always informed on time.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;When not to use CC in email&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;CC&amp;#8217;ing should be avoided when your email (or the subsequent email thread) contains sensitive or confidential information. When you email one person sensitive information, there’s a risk they could forward or store it, but CCing increases that risk by adding more recipients, often including people who weren&amp;#8217;t the intended audience for the content in the first place.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You should also avoid using CC when you expect someone you&amp;#8217;re CC&amp;#8217;ing to take action. People included in CC often assume they don&amp;#8217;t need to respond, which can lead to missed tasks or delays. This risk grows when you CC large numbers of recipients unnecessarily, which also clutters inboxes with irrelevant noise.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;CC&amp;#8217;ing an entire distribution list on a routine status update creates noise without adding accountability. Emailing your entire team about a change that doesn&amp;#8217;t affect them can create confusion.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You should also be careful about CC&amp;#8217;ing someone into an existing conversation without the other party&amp;#8217;s knowledge or agreement — like, for example, adding a new stakeholder to a client thread without telling the client first. Even if you have a legitimate reason, it can look like you&amp;#8217;re widening access to a conversation that may be confidential.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What does BCC mean?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/blog/bcc-email&quot;&gt;&lt;u&gt;BCC&lt;/u&gt;&lt;/a&gt; stands for Blind Carbon Copy. It works like CC&amp;#8217;ing, without the visibility. The BCC function allows you to send copies of the same email to multiple people without revealing that they are part of a mass email, or revealing the other recipients’ email addresses or responses to your original email.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Another key difference: If you enter multiple contacts into the BCC field, when they respond it is only you who will receive their response email. It will not be received by any other BCC recipients.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;When to use BCC in email&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;BCC should be used whenever you need to send multiple people the same email, but you do not want them to know they are a part of a mass email or to be able to see the email addresses of the other recipients.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;BCC&amp;#8217;ing is useful for protecting the privacy of people who have given you their email address with the expectation that you will not share it without their permission. For example, when sending an update about your company to a mailing list, you should use the BCC function to ensure the individual recipients cannot see the addresses of everyone else who has signed up for that mailing list.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You can also BCC yourself when sending an email from a shared or generic team inbox, to keep a personal record of correspondence sent on your team&amp;#8217;s behalf.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;When not to use BCC in email&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;As with CC&amp;#8217;ing, be wary of BCC&amp;#8217;ing when your email contains sensitive information, or you suspect that the email thread resulting from your email will contain sensitive information.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Avoid using BCC in situations where transparency matters. Covertly adding someone to the conversation can damage trust if it surfaces and be considered a breach of &lt;a href=&quot;https://proton.me/business/blog/email-etiquette&quot;&gt;email etiquette&lt;/a&gt;. It&amp;#8217;s better to CC them openly or send a separate note.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;BCC should not be used for ongoing conversations, such as an active back-and-forth negotiation or client conversation — where you expect whoever you&amp;#8217;ve BCC&amp;#8217;d in to be able to follow the whole conversation. Since BCC recipients are excluded from replies, this means cutting them out of exactly the conversation you wanted them to follow.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What’s the difference between To, CC, and BCC?&lt;/h2&gt;



&lt;figure class=&quot;wp-block-table&quot;&gt;&lt;table class=&quot;has-fixed-layout&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Feature&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;To&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;CC&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;BCC&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Role&amp;nbsp;&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;The intended main contact of the email.&amp;nbsp;&lt;/td&gt;&lt;td&gt;For people who need to stay in the loop.&amp;nbsp;&lt;/td&gt;&lt;td&gt;To include people without others knowing.&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Visibility&amp;nbsp;&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Visible to everyone.&amp;nbsp;&lt;/td&gt;&lt;td&gt;Visible to everyone.&amp;nbsp;&lt;/td&gt;&lt;td&gt;Hidden from all other recipients.&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Recipient Awareness&amp;nbsp;&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Everyone knows they are the main contact.&amp;nbsp;&lt;/td&gt;&lt;td&gt;Everyone knows who else is being kept informed.&amp;nbsp;&lt;/td&gt;&lt;td&gt;Only you and the BCC’d person know they are there.&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Reply All Behavior&amp;nbsp;&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Receives all replies.&amp;nbsp;&lt;/td&gt;&lt;td&gt;Receives all replies.&amp;nbsp;&lt;/td&gt;&lt;td&gt;Excluded from future &amp;#8220;Reply All&amp;#8221; threads.&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Expectation&amp;nbsp;&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Response expected.&lt;/td&gt;&lt;td&gt;For your information (FYI) only.&amp;nbsp;&lt;/td&gt;&lt;td&gt;Should not participate in the thread.&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Best For&amp;nbsp;&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Direct requests, tasks, and 1:1s.&amp;nbsp;&lt;/td&gt;&lt;td&gt;Transparency and team collaboration.&amp;nbsp;&lt;/td&gt;&lt;td&gt;Mass emails, privacy, and discreet oversight.&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/figure&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What happens when you hit reply or reply all?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Reply behavior can be confusing, especially when multiple recipients are involved. What happens depends on whether you choose Reply or Reply all.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Hitting Reply all when you intended to hit Reply can lead to internal asides and information leaking to clients, or to an entire distribution list being emailed by mistake. One wrong click can stifle your team’s productivity and even threaten your company’s reputation.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;If you are in the To or CC field:&lt;/strong&gt;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Clicking Reply sends your response only to the sender.&lt;/li&gt;



&lt;li&gt;Clicking Reply all sends your response to everyone in the To and CC fields.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;If you are in the BCC field:&lt;/strong&gt;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Clicking Reply sends your response only to the sender.&lt;/li&gt;



&lt;li&gt;Clicking Reply all sends your response to everyone in the To and CC fields, not to other BCC recipients — but you will reveal to them that you were BCC&amp;#8217;d  &lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;A better way to send group emails&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Although using the CC and BCC functions is the main way to send an email to multiple people, our encrypted email service &lt;a href=&quot;https://proton.me/business/mail&quot;&gt;&lt;u&gt;Proton Mail&lt;/u&gt;&lt;/a&gt; also lets you do this by putting multiple recipients in a contact group.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/support/contact-groups&quot;&gt;&lt;u&gt;Contact groups&lt;/u&gt;&lt;/a&gt; are useful for emailing multiple people who all know each other, especially if you regularly email them as a group. For example, a team sending weekly updates to stakeholders can save time by using a contact group instead of adding recipients manually every time.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Once you&amp;#8217;ve created a &lt;a href=&quot;https://proton.me/support/contact-groups&quot;&gt;&lt;u&gt;contact group&lt;/u&gt;&lt;/a&gt; in your Proton Mail account, you can email everyone in that group at once by typing the name of the contact group into the To field and selecting the contact group you want to mass-email from the autofill menu. This will enter all of the email addresses of the contacts in that group to the To field.&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-full&quot;&gt;&lt;img loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;300&quot; height=&quot;108&quot; src=&quot;https://pme.protonblog.tech/wp-content/uploads/2022/02/image-12.png&quot; alt=&quot;&quot; class=&quot;wp-post-10543 wp-image-245173&quot;/&gt;&lt;/figure&gt;



&lt;figure class=&quot;wp-block-image size-full&quot;&gt;&lt;img loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;300&quot; height=&quot;109&quot; src=&quot;https://pme.protonblog.tech/wp-content/uploads/2022/02/image-13.png&quot; alt=&quot;&quot; class=&quot;wp-post-10543 wp-image-245197&quot;/&gt;&lt;/figure&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When you email people who are in a contact group with each other, they can all see each other’s email addresses, although they will not know that you have put them in a contact group, and the name of that group won’t appear in their inboxes. If you don’t want the contacts in your contact group to know the other members’ addresses, you can enter the contact group into the BCC field instead.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Key takeaways on using CC and BCC in a professional setting&lt;/h2&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;To: is for the people expected to take action.&lt;/li&gt;



&lt;li&gt;CC (Carbon Copy): is for keeping people informed (FYI).&lt;/li&gt;



&lt;li&gt;BCC (Blind Carbon Copy): is for privacy (recipients are hidden from everyone else).&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How Proton Mail protects To, CC and BCC email messages&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Contact groups make CC and BCC quicker to use, but they don&amp;#8217;t make them any safer from interception by a third party. That&amp;#8217;s a different problem, and it&amp;#8217;s one Proton Mail&amp;#8217;s encryption can help with.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton Mail encrypts messages sent between Proton accounts with &lt;a href=&quot;https://proton.me/learn/encryption/types-of-encryption/what-is-end-to-end&quot;&gt;end-to-end encryption&lt;/a&gt;, and protects everything stored in your mailbox with &lt;a href=&quot;https://proton.me/learn/encryption/types-of-encryption/zero-access&quot;&gt;zero-access encryption&lt;/a&gt;, meaning even Proton can&amp;#8217;t read it — or decrypt it, even under compulsion from law enforcement. You can also add password protection to emails sent to non-Proton addresses, so they&amp;#8217;re encrypted too.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;None of this stops an email reaching the wrong person through a misplaced CC or BCC, and it doesn&amp;#8217;t change who can see whose address in a CC or BCC field.&amp;nbsp;That&amp;#8217;s still down to you using the fields correctly. What &lt;a href=&quot;https://proton.me/learn/encryption&quot;&gt;encryption&lt;/a&gt; does protect is the content of a CC&amp;#8217;d or BCC&amp;#8217;d business email in transit, so a client proposal or an internal aside can&amp;#8217;t be intercepted by a third party.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If your business regularly sends CC&amp;#8217;d and BCC&amp;#8217;d correspondence containing sensitive content like client proposals and internal decisions, Proton&amp;#8217;s &lt;a href=&quot;https://proton.me/business/mail&quot;&gt;&lt;/a&gt;&lt;a href=&quot;https://proton.me/business/mail&quot;&gt;&lt;u&gt;business email service&lt;/u&gt;&lt;/a&gt; applies that protection automatically, without your team having to think about it.&lt;/p&gt;



&lt;hr class=&quot;wp-block-separator has-alpha-channel-opacity&quot;/&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;FAQ&lt;/h2&gt;



&lt;div class=&quot;wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex&quot;&gt;
&lt;div class=&quot;wp-block-column is-layout-flow wp-block-column-is-layout-flow&quot; style=&quot;flex-basis:100%&quot;&gt;
&lt;div class=&quot;schema-faq wp-block-yoast-faq-block&quot;&gt;&lt;div class=&quot;schema-faq-section&quot; id=&quot;faq-question-1643737620478&quot;&gt;&lt;strong class=&quot;schema-faq-question&quot;&gt;Is BCC safer than CC?&lt;/strong&gt; &lt;p class=&quot;schema-faq-answer&quot;&gt;When it comes to protecting your contacts&amp;#8217; email addresses from your other contacts, BCC is safer than CC. With BCC, there is no way for a recipient to know that they are not the only recipient of an email (as long as all other recipients are marked BCC), let alone find out the email addresses of other recipients. For this reason, you should use BCC when you do not have permission to share a contact’s email address with anyone else.&lt;br&gt;It&amp;#8217;s important to note that neither CC nor BCC is safer when it comes to protecting your messages against interception by a third party. That protection only comes with encryption, not through your choice of field.&lt;br&gt;&lt;/p&gt; &lt;/div&gt; &lt;div class=&quot;schema-faq-section&quot; id=&quot;faq-question-1789131685714&quot;&gt;&lt;strong class=&quot;schema-faq-question&quot;&gt;&lt;strong&gt;Is it safe to CC or BCC sensitive business information?&lt;/strong&gt;&lt;/strong&gt; &lt;p class=&quot;schema-faq-answer&quot;&gt;This depends on who you send it to: the mechanisms don&amp;#8217;t protect you. CC and BCC control who receives a copy of an email, not what happens to it afterward. Anyone included in a CC or BCC field for a message can forward, screenshot, or store it. If you&amp;#8217;re sending confidential information, keep your recipient list as small as possible, and consider encrypting the message itself so the content stays protected even if it ends up somewhere you didn&amp;#8217;t intend.&lt;/p&gt; &lt;/div&gt; &lt;div class=&quot;schema-faq-section&quot; id=&quot;faq-question-1643737839389&quot;&gt;&lt;strong class=&quot;schema-faq-question&quot;&gt;Is it better to CC or BCC?&lt;/strong&gt; &lt;p class=&quot;schema-faq-answer&quot;&gt;If you want to maintain a conversation with all the original recipients of your email, it is better to use the CC function, so that all contacts who were initially included in the email receive all the responses. However, if it is important that your contacts’ email addresses are not exposed to each other, and they are not expected to continue an inclusive email chain, then you should use BCC to conceal your recipients’ contact information.&lt;/p&gt; &lt;/div&gt; &lt;div class=&quot;schema-faq-section&quot; id=&quot;faq-question-1643737864828&quot;&gt;&lt;strong class=&quot;schema-faq-question&quot;&gt;Can a CC’d person see BCC’d recipients?&lt;/strong&gt; &lt;p class=&quot;schema-faq-answer&quot;&gt;No. CC recipients cannot see the names or addresses of anyone who was included as a BCC on any original message. The only time the BCC recipients’ contact information will be exposed is if they respond to the email using “reply all”.&lt;/p&gt; &lt;/div&gt; &lt;div class=&quot;schema-faq-section&quot; id=&quot;faq-question-1785510331074&quot;&gt;&lt;strong class=&quot;schema-faq-question&quot;&gt;How is CC different from To?&lt;/strong&gt; &lt;p class=&quot;schema-faq-answer&quot;&gt;The To field should be used for the main recipient(s) of your email, who you expect to respond or take some kind of action after receiving your email. The main recipients will usually be the ones the email is addressed to in the salutation of your email.&lt;/p&gt; &lt;/div&gt; &lt;div class=&quot;schema-faq-section&quot; id=&quot;faq-question-1785510378759&quot;&gt;&lt;strong class=&quot;schema-faq-question&quot;&gt;Can you use CC and BCC at the same time?&lt;/strong&gt; &lt;p class=&quot;schema-faq-answer&quot;&gt;Yes. People in the To and CC fields can see each other, while BCC recipients are hidden from everyone else. BCC recipients can still see who is in the To and CC fields, but they do not receive replies from those recipients.&lt;/p&gt; &lt;/div&gt; &lt;div class=&quot;schema-faq-section&quot; id=&quot;faq-question-1789131855002&quot;&gt;&lt;strong class=&quot;schema-faq-question&quot;&gt;What happens if someone I BCC’d replies to all?&lt;/strong&gt; &lt;p class=&quot;schema-faq-answer&quot;&gt;Their reply is sent to the sender and everyone in the To and CC fields. Their address is still not shown as a BCC recipient, but the reply can reveal that they were included in the original email.&lt;/p&gt; &lt;/div&gt; &lt;div class=&quot;schema-faq-section&quot; id=&quot;faq-question-1785510387282&quot;&gt;&lt;strong class=&quot;schema-faq-question&quot;&gt;Can you tell if you were BCC’d on an email?&lt;/strong&gt; &lt;p class=&quot;schema-faq-answer&quot;&gt;Usually no. BCC recipients are hidden from other recipients. If you receive an email but your address does not appear in the To or CC fields, you were likely BCC’d.&lt;/p&gt; &lt;/div&gt; &lt;div class=&quot;schema-faq-section&quot; id=&quot;faq-question-1785510400942&quot;&gt;&lt;strong class=&quot;schema-faq-question&quot;&gt;Does CC or BCC affect email delivery?&lt;/strong&gt; &lt;p class=&quot;schema-faq-answer&quot;&gt;Not directly. However, sending emails to large numbers of recipients using CC or BCC can trigger spam filters. For large groups, it’s better to use a mailing list or newsletter service.&lt;/p&gt; &lt;/div&gt; &lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;/p&gt;
</content:encoded><category>For business</category><author>Alanna Alexander</author></item><item><title>What is cyberstalking? How to protect yourself and what the law says</title><link>https://proton.me/blog/cyberstalking</link><guid isPermaLink="true">https://proton.me/blog/cyberstalking</guid><description>What is cyberstalking, and is it a crime? Learn the warning signs, how to protect your privacy, and how cyberstalking laws work around the world.</description><pubDate>Wed, 09 Sep 2026 17:18:53 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Cyberstalking is fundamentally an invasion of privacy. It often starts with &lt;a href=&quot;https://proton.me/blog/how-to-remove-personal-information-from-the-internet-and-protect-your-privacy&quot;&gt;information you share online&lt;/a&gt; voluntarily, from social media posts to tagged photos.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;About &lt;a href=&quot;https://www.cdc.gov/nisvs/media/pdfs/stalking-brief.pdf&quot;&gt;one in five women and one in 10 men&lt;/a&gt; in the US will experience stalking at some point in their lives, and a growing share of that stalking happens through a phone or a laptop rather than in person.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Most importantly, cyberstalking is a crime. But the laws that define it vary around the world.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This guide covers what cyberstalking is and how it differs from other forms of online harassment. We also examine what the law says in major jurisdictions. And you’ll learn what you can do to recognize it, respond to it, and make yourself a harder target in the first place.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What is cyberstalking?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Cyberstalking is the repeated use of the internet, email, social media, or other electronic means to harass someone with the intent to intimidate or control them. As with offline stalkers, most cyberstalkers have had some prior relationship with their target, whether as a former partner, coworker, or acquaintance.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The kinds of harassment that can be considered cyberstalking are varied. In 2025, a man in the US &lt;a href=&quot;https://www.theguardian.com/technology/2025/feb/01/stalking-ai-chatbot-impersonator&quot;&gt;used an AI chatbot&lt;/a&gt; to lure people to the home of his victim as part of a seven-year-long cyberstalking attack. In the UK, a woman was &lt;a href=&quot;https://www.gmp.police.uk/news/greater-manchester/news/news/2025/october/woman-sentenced-to-over-2-years-after-subjecting-victims-to-years-of-online-abuse/&quot;&gt;sentenced to 28 months in prison&lt;/a&gt; for posting harmful, false allegations online.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;“Cyberstalking” gets used loosely alongside a few related terms:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Online harassment&lt;/strong&gt; is broader than cyberstalking. Cyberstalking laws usually require proof that the behavior caused fear of physical danger; online harassment laws often only require that the person intended to annoy or alarm you, with &lt;a href=&quot;https://www.womenslaw.org/about-abuse/abuse-using-technology/ways-survivors-use-and-abusers-misuse-technology/cyberstalking-6#node-68482&quot;&gt;no legitimate reason&lt;/a&gt; for the contact.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Cyberbullying&lt;/strong&gt; is a related pattern of aggressive, unwanted contact, but the term is generally associated with minors and schools rather than adults.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Doxing&lt;/strong&gt; is the act of publishing someone&amp;#8217;s address, phone number, or other identifying details to scare or endanger them. It’s usually a tactic within a broader stalking or harassment case, and few countries treat it as a standalone crime.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Legally speaking, the distinctions matter if you&amp;#8217;re trying to figure out what protections apply to you.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Cyberstalking laws around the world&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Cyberstalking is seldom its own standalone offense. Instead, it&amp;#8217;s typically prosecuted under general stalking or harassment laws. Nearly every legal system covered here also shares one requirement: proof of a repeated pattern of behavior, not a single incident.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;United States&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;There&amp;#8217;s no single federal &amp;#8220;cyberstalking law.&amp;#8221; Most prosecutions happen at the state level, under stalking or harassment statutes that have been extended to cover electronic communications.&amp;nbsp; California passed the first state law explicitly naming cyberstalking as an offense in 1999, and &lt;a href=&quot;https://cyberbullying.org/cyberstalking-laws&quot;&gt;most other states have since followed&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;At the federal level, &lt;a href=&quot;https://legalclarity.org/18-u-s-c-2261a-federal-stalking-and-harassment-laws-explained/&quot;&gt;18 U.S.C. § 2261A&lt;/a&gt; criminalizes using interstate travel or electronic communications with intent to kill, injure, harass, intimidate, or surveil someone, when that conduct causes substantial emotional distress or a reasonable fear of serious harm. A conviction carries up to five years in prison as a base penalty.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;United Kingdom&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The UK prosecutes cyberstalking under Section 2A of the &lt;a href=&quot;https://www.legislation.gov.uk/ukpga/1997/40/contents&quot;&gt;Protection from Harassment Act 1997&lt;/a&gt;, the same law that covers offline stalking. A stalking conviction can carry up to 10 years in prison. For single threatening or grossly offensive messages that don&amp;#8217;t meet the bar for an ongoing stalking pattern, prosecutors can instead use the &lt;a href=&quot;https://www.legislation.gov.uk/ukpga/1988/27/contents&quot;&gt;Malicious Communications Act 1988&lt;/a&gt; or the &lt;a href=&quot;https://www.legislation.gov.uk/ukpga/2003/21/section/127&quot;&gt;Communications Act 2003&lt;/a&gt;. More recently, the &lt;a href=&quot;https://www.gov.uk/government/publications/online-safety-act-explainer/online-safety-act-explainer&quot;&gt;Online Safety Act 2023&lt;/a&gt; introduced statutory duties for platforms operating in the UK, naming stalking and harassment as among the kinds of illegal content that platforms are specifically required to address.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Germany&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Germany criminalizes stalking under &lt;a href=&quot;https://se-legal.de/rechtsanwalt/strafrecht/stalking-cyberstalking/?lang=en%3B%20LexMea%2C%20%C2%A7238%20StGB%20%E2%80%94&quot;&gt;Section 238 of the Criminal Code&lt;/a&gt; (StGB), amended in 2017 specifically to strengthen protections. The law explicitly covers conduct carried out &amp;#8220;by means of telecommunications or by using [a victim&amp;#8217;s] personal data&amp;#8221; — including impersonating the person — which is the direct bridge to cyberstalking. A conviction carries up to three years in prison, rising to five in severe cases. Cyberstalking cases in Germany are also often prosecuted alongside related offenses like online threats (Section 241 StGB) or insult and defamation (Sections 185–187 StGB).&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;France&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;France addresses cyberstalking under &lt;a href=&quot;https://www.legifrance.gouv.fr/codes/article_lc/LEGIARTI000049312743&quot;&gt;Article 222-33-2-2 of the Penal Code&lt;/a&gt;, which defines a form of moral harassment as repeated behavior that degrades a person&amp;#8217;s living conditions and harms their physical or mental health. A conviction carries up to one year in prison and a €15,000 fine. France’s 2016 Digital Republic Act strengthened the law with &lt;a href=&quot;https://www.coe.int/en/web/cyberviolence/-/france-digital-republic-law-sanctions-against-revenge-porn&quot;&gt;harsher penalties for “revenge porn,”&lt;/a&gt; doubling the jail time and increasing the fine to €60,000.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Canada&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In Canada, online stalking is prosecuted under &lt;a href=&quot;https://laws-lois.justice.gc.ca/eng/acts/c-46/section-264.html&quot;&gt;Section 264 of the Criminal Code&lt;/a&gt;, the criminal harassment provision enacted in 1993. A conviction requires proving the behavior caused the victim to reasonably fear for their safety or the safety of someone they know, and it carries up to 10 years in prison. Cyberstalking can also be prosecuted under &lt;a href=&quot;https://www.kruselaw.ca/blog/sexual-assault-blog/is-cyberstalking-a-crime/&quot;&gt;Bill C-13&lt;/a&gt; (Protecting Canadians from Online Crime Act), which stipulates that the “contact was both repetitive and unwanted” and that “victims must reasonably fear for their safety or the safety of someone known to them”.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Italy&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Italy criminalizes stalking as &amp;#8220;atti persecutori&amp;#8221; (persecutory acts) under &lt;a href=&quot;https://www.poliziadistato.it/statics/21/stalking.pdf&quot;&gt;Article 612-bis of the Criminal Code&lt;/a&gt;, introduced in 2009. The law covers repeated conduct that causes lasting anxiety or fear, a reasonable fear for someone&amp;#8217;s safety, or forces a victim to change their daily habits. The provision specifically mentions email and text messages as examples. The base penalty ranges from one to six-and-a-half years in prison, and the law has been strengthened twice since, in 2019 and again in 2023. It’s necessary for the victim to file a charge within six months of the occurrence of the crime.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Brazil&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Brazil made stalking a standalone crime relatively recently, through &lt;a href=&quot;https://www.jusbrasil.com.br/artigos/o-stalking-agora-e-crime-atraves-da-lei-14-132-2021-crime-de-perseguicao-a-perturbacao-a-liberdade-ou-privacidade-da-vitima/1188261045&quot;&gt;Law 14.132/2021&lt;/a&gt;, which added Article 147-A to the Penal Code. It defines the offense as repeatedly pursuing someone, by any means, in a way that threatens their physical or psychological safety, restricts their freedom of movement, or invades their privacy. Brazilian legal commentary treats cyberstalking as squarely covered under &amp;#8220;by any means”. The penalty is six months to two years in prison plus a fine, increased by half when the crime targets a child, someone elderly, or a woman because of her sex.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Australia&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Australia prosecutes cyberstalking under &lt;a href=&quot;https://www.sydneycriminallawyers.com.au/criminal/legislation/criminal-code-act/use-carriage-service-to-menace-harass-or-cause-offence/&quot;&gt;Section 474.17 of the Criminal Code&lt;/a&gt;, which criminalizes using a &amp;#8220;carriage service&amp;#8221; — any phone or internet service — to menace, harass, or cause offense, carrying up to five years in prison, and notably doesn&amp;#8217;t require prosecutors to prove the victim actually feared physical harm.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;India&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;India&amp;#8217;s &lt;a href=&quot;https://restthecase.com/knowledge-bank/ipc/section-354d&quot;&gt;Section 354D of the Penal Code&lt;/a&gt;, added in 2013, explicitly criminalizes a man monitoring a woman&amp;#8217;s use of the internet, email, or other electronic communication as a form of stalking — one of the more direct statutory references to cyberstalking-style conduct found anywhere. Though the law protects women from men specifically rather than applying generally, men have protection under a &lt;a href=&quot;https://devgan.in/bns/section/351/&quot;&gt;separate law on intimidation&lt;/a&gt;. A first conviction carries up to three years in prison, rising to five for a repeat offense.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;The Philippines&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The Philippines&amp;#8217; &lt;a href=&quot;https://pcw.gov.ph/faq-republic-act-no-11313/&quot;&gt;Safe Spaces Act of 2019&lt;/a&gt; goes further than most, naming &amp;#8220;cyberstalking&amp;#8221; outright as one of several forms of gender-based online sexual harassment, alongside unwanted sexual messaging and non-consensual sharing of images. This is possibly the most direct reference to cyberstalking as a standalone crime in the world.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Rest of the world&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The legal picture is uneven and often incomplete internationally. A &lt;a href=&quot;https://blogs.worldbank.org/en/developmenttalk/protecting-women-and-girls-cyber-harassment-global-assessment&quot;&gt;2020 World Bank assessment&lt;/a&gt; found that only 30% of economies worldwide have legal protections addressing online harassment, and just 12% protect against cyber sexual harassment specifically. Only 21 out of the 190 economies analyzed have laws explicitly protecting children from online harassment. More &lt;a href=&quot;https://openknowledge.worldbank.org/entities/publication/01a0d4bd-e85e-4d36-8133-2d2b889cbff6&quot;&gt;recent research&lt;/a&gt; suggests the legislative coverage hasn’t dramatically improved.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Why cyberstalking is a privacy problem&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Every form of cyberstalking depends on a stalker getting hold of some piece of digital information. But whatever the case, information is what they weaponize against their victim, and there are many possible sources:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;a href=&quot;https://proton.me/blog/data-brokers&quot;&gt;&lt;strong&gt;Data brokers&lt;/strong&gt;&lt;/a&gt; &lt;strong&gt;and people-search sites.&lt;/strong&gt; These sites scrape and resell your address, phone number, workplace, and family details, often without your knowledge, and they&amp;#8217;re frequently the easiest starting point for a stalker building a profile of you.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Photo and location metadata.&lt;/strong&gt; Photos taken with location services turned on carry embedded GPS coordinates in their &lt;a href=&quot;https://proton.me/blog/exif-data&quot;&gt;image metadata&lt;/a&gt;. Stalkers have used metadata from dating-app and social media photos to identify victims&amp;#8217; homes and workplaces.&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;https://proton.me/blog/what-is-spyware&quot;&gt;&lt;strong&gt;Stalkerware&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;.&lt;/strong&gt; This is commercial monitoring software installed on a device, usually by someone who had physical access to it, that lets an abuser track messages, calls, browsing, and location. &lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;https://proton.me/business/blog/password-fatigue&quot;&gt;&lt;strong&gt;Reused or weak passwords&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;.&lt;/strong&gt; A single breached password from an old, unrelated account can be the opening that lets someone take over your email or social media.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Cleaning up your &lt;a href=&quot;https://proton.me/blog/what-is-digital-footprint&quot;&gt;digital footprint&lt;/a&gt; is the most effective thing you can do to stay safe.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Recognize cyberstalking, respond to it, protect yourself against it&lt;/h2&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img width=&quot;1024&quot; height=&quot;684&quot; data-public-id=&quot;wp-pme/20260731-how-to-protect-yourselfagainst-cyberstalking_diagram_2/20260731-how-to-protect-yourselfagainst-cyberstalking_diagram_2.jpg&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_684,c_scale/f_auto,q_auto/v1788966872/wp-pme/20260731-how-to-protect-yourselfagainst-cyberstalking_diagram_2/20260731-how-to-protect-yourselfagainst-cyberstalking_diagram_2.jpg?_i=AA&quot; alt=&quot;If you notice these signs, someone may be cyberstalking you&quot; class=&quot;wp-post-294698 wp-image-294699&quot; data-format=&quot;jpg&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;795 KB&quot; data-optsize=&quot;114 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;85.6&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=294699&quot; data-version=&quot;1788966872&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_684,c_scale/f_auto,q_auto/v1788966872/wp-pme/20260731-how-to-protect-yourselfagainst-cyberstalking_diagram_2/20260731-how-to-protect-yourselfagainst-cyberstalking_diagram_2.jpg?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_200,c_scale/f_auto,q_auto/v1788966872/wp-pme/20260731-how-to-protect-yourselfagainst-cyberstalking_diagram_2/20260731-how-to-protect-yourselfagainst-cyberstalking_diagram_2.jpg?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_513,c_scale/f_auto,q_auto/v1788966872/wp-pme/20260731-how-to-protect-yourselfagainst-cyberstalking_diagram_2/20260731-how-to-protect-yourselfagainst-cyberstalking_diagram_2.jpg?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_1025,c_scale/f_auto,q_auto/v1788966872/wp-pme/20260731-how-to-protect-yourselfagainst-cyberstalking_diagram_2/20260731-how-to-protect-yourselfagainst-cyberstalking_diagram_2.jpg?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_2048,h_1367,c_scale/f_auto,q_auto/v1788966872/wp-pme/20260731-how-to-protect-yourselfagainst-cyberstalking_diagram_2/20260731-how-to-protect-yourselfagainst-cyberstalking_diagram_2.jpg?_i=AA 2048w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_1047,c_scale/f_auto,q_auto/v1788966872/wp-pme/20260731-how-to-protect-yourselfagainst-cyberstalking_diagram_2/20260731-how-to-protect-yourselfagainst-cyberstalking_diagram_2.jpg?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;/figure&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;If you notice these signs, someone may be cyberstalking you:&amp;nbsp;&lt;/h3&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Contact that&amp;#8217;s excessive or arrives in sudden bursts&lt;/li&gt;



&lt;li&gt;Engagement with old social media posts that would have taken real effort to dig up&lt;/li&gt;



&lt;li&gt;Threats or blackmail, including threats to release private information or images&lt;/li&gt;



&lt;li&gt;Attempts to access your accounts or devices, or a fake profile making contact after you&amp;#8217;ve blocked the real one&lt;/li&gt;



&lt;li&gt;Unwanted sexual messaging&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The clearest signal that something has crossed from unwanted attention into stalking is if the contact continues after you&amp;#8217;ve clearly said to stop.&amp;nbsp;&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img width=&quot;1024&quot; height=&quot;684&quot; data-public-id=&quot;wp-pme/20260731-how-to-protect-yourselfagainst-cyberstalking_diagram_3/20260731-how-to-protect-yourselfagainst-cyberstalking_diagram_3.jpg&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_684,c_scale/f_auto,q_auto/v1788966885/wp-pme/20260731-how-to-protect-yourselfagainst-cyberstalking_diagram_3/20260731-how-to-protect-yourselfagainst-cyberstalking_diagram_3.jpg?_i=AA&quot; alt=&quot;What to do if someone is cyberstalking you&quot; class=&quot;wp-post-294698 wp-image-294725&quot; data-format=&quot;jpg&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;729 KB&quot; data-optsize=&quot;92 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;87.4&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=294725&quot; data-version=&quot;1788966885&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_684,c_scale/f_auto,q_auto/v1788966885/wp-pme/20260731-how-to-protect-yourselfagainst-cyberstalking_diagram_3/20260731-how-to-protect-yourselfagainst-cyberstalking_diagram_3.jpg?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_200,c_scale/f_auto,q_auto/v1788966885/wp-pme/20260731-how-to-protect-yourselfagainst-cyberstalking_diagram_3/20260731-how-to-protect-yourselfagainst-cyberstalking_diagram_3.jpg?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_513,c_scale/f_auto,q_auto/v1788966885/wp-pme/20260731-how-to-protect-yourselfagainst-cyberstalking_diagram_3/20260731-how-to-protect-yourselfagainst-cyberstalking_diagram_3.jpg?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_1025,c_scale/f_auto,q_auto/v1788966885/wp-pme/20260731-how-to-protect-yourselfagainst-cyberstalking_diagram_3/20260731-how-to-protect-yourselfagainst-cyberstalking_diagram_3.jpg?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_2048,h_1367,c_scale/f_auto,q_auto/v1788966885/wp-pme/20260731-how-to-protect-yourselfagainst-cyberstalking_diagram_3/20260731-how-to-protect-yourselfagainst-cyberstalking_diagram_3.jpg?_i=AA 2048w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_1047,c_scale/f_auto,q_auto/v1788966885/wp-pme/20260731-how-to-protect-yourselfagainst-cyberstalking_diagram_3/20260731-how-to-protect-yourselfagainst-cyberstalking_diagram_3.jpg?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;/figure&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;If you’re being cyberstalked:&lt;/h3&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Send one clear, written message saying the contact is unwanted, then stop engaging entirely.&lt;/li&gt;



&lt;li&gt;Document everything: dates, screenshots, descriptions of each incident.&lt;/li&gt;



&lt;li&gt;Report the person to the platform where the contact happened.&lt;/li&gt;



&lt;li&gt;Block them across every channel you use.&lt;/li&gt;



&lt;li&gt;Tell people you trust rather than handling it alone.&lt;/li&gt;



&lt;li&gt;If it continues, file a police report and consider a restraining or protective order. &lt;/li&gt;
&lt;/ol&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;A note on stalkerware:&lt;/strong&gt; If you suspect stalkerware on your phone, removing it can alert whoever installed it and potentially escalate the situation. If you&amp;#8217;re in an ongoing abusive relationship, it&amp;#8217;s worth getting support from a domestic violence advocate before you act.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;em&gt;See this in-depth explainer on stalkerware from the&lt;/em&gt; &lt;a href=&quot;https://stopstalkerware.org/information-for-survivors/&quot;&gt;&lt;em&gt;Coalition Against Stalkerware&lt;/em&gt;&lt;/a&gt;&lt;em&gt;.&lt;/em&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;To protect your privacy:&lt;/h3&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Search your own name to see what&amp;#8217;s already findable, and opt out of data broker and people-search sites. (Note: This isn&amp;#8217;t a one-time fix, since new listings resurface over time.)&lt;/li&gt;



&lt;li&gt;Review your &lt;a href=&quot;https://proton.me/blog/google-privacy-settings&quot;&gt;online privacy settings&lt;/a&gt; and turn off geolocation tagging on your camera and apps, so photos stop carrying GPS data.&lt;/li&gt;



&lt;li&gt;Use a &lt;a href=&quot;https://protonvpn.com/&quot;&gt;VPN&lt;/a&gt; to &lt;a href=&quot;https://protonvpn.com/features/hide-ip&quot;&gt;hide your IP address&lt;/a&gt;, keeping your general location hidden from anyone trying to trace your connection back to you — but be aware that a VPN won&amp;#8217;t hide GPS data or protect information you willingly enter into an account.&lt;/li&gt;



&lt;li&gt;Use a &lt;a href=&quot;https://proton.me/pass&quot;&gt;password manager&lt;/a&gt; to generate unique passwords for every account, and turn on &lt;a href=&quot;https://proton.me/authenticator&quot;&gt;two-factor authentication&lt;/a&gt; for an extra layer of security.&lt;/li&gt;



&lt;li&gt;Use &lt;a href=&quot;https://proton.me/blog/what-is-email-alias&quot;&gt;email aliases&lt;/a&gt; instead of your real email address when signing up for anything, so services and data brokers never connect a new account back to your identity.&lt;/li&gt;



&lt;li&gt;Watch your devices for signs of stalkerware: fast battery drain, unrecognized apps, or permission changes you didn&amp;#8217;t make.&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Privacy is your best defense against cyberstalking&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Cyberstalking is a crime, and many countries give you a legal path to respond to it. But the law works after the fact; the more effective move is making your personal data harder to find in the first place.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That starts with the basics: an &lt;a href=&quot;https://proton.me/mail&quot;&gt;email address&lt;/a&gt; that isn&amp;#8217;t tied to your real name, passwords a stalker can&amp;#8217;t guess or reuse from an old breach, and an internet connection that doesn&amp;#8217;t broadcast your location to anyone watching.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Our &lt;a href=&quot;https://proton.me/about&quot;&gt;mission at Proton&lt;/a&gt; is to help you protect your privacy from Big Tech surveillance. But doing so is also a good step toward protecting your personal safety.&lt;/p&gt;
</content:encoded><category>Guides</category><author>Ben Wolford</author></item><item><title>Deepfake fraud targeting businesses: How to recognize and respond to AI-generated scams</title><link>https://proton.me/business/blog/deepfake-business-fraud</link><guid isPermaLink="true">https://proton.me/business/blog/deepfake-business-fraud</guid><description>Deepfake video calls now let attackers impersonate executives in real time. Learn how they work and the verification protocols that stop them.</description><pubDate>Wed, 09 Sep 2026 16:51:11 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Deepfake technology has made it significantly easier for scammers to impersonate business professionals. A scammer can now join a call on camera and respond to questions in real time convincingly as another person.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is the third channel of AI-enabled impersonation, after email and voice, and it&amp;#8217;s the one businesses are least prepared for: A face on a video call feels completely human and impossible to fake.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;We&amp;#8217;ve covered how &lt;a href=&quot;https://proton.me/business/blog/ai-phishing-attacks&quot;&gt;AI phishing campaigns&lt;/a&gt; are faster and easier to launch, and how voice cloning is increasing &lt;a href=&quot;https://proton.me/business/blog/vishing-attacks-business&quot;&gt;vishing&lt;/a&gt; attempts. In this article, we’ll explore what happens when a person’s identity is co-opted with deepfake videos and how to prevent team members from falling for deepfake scams.&amp;nbsp;&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What makes deepfake video fraud different&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Email deception relies on written detail: the right tone, the right context, and a reasonable-sounding but urgent request. Voice cloning relies on the ear: a familiar voice saying something urgent enough to bypass a moment of doubt. Deepfake video fraud goes a step further and compromises the one verification instinct most people never think to question: seeing someone&amp;#8217;s face and hearing them speak, in real time, on a call that looks exactly like every other video meeting on the calendar.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Employees are trained to be skeptical of an email and to double-check an unexpected phone call. Almost nobody is trained to question a face-to-face video call, because video has always been as trustworthy as a physical meeting.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This new frontier of fraud requires a re-evaluation of what can be trusted at work, as well as how easily processes can be overridden by urgency.&amp;nbsp;&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How deepfake scams work in practice&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Deepfake video fraud can take a few different forms. The simplest is a pre-recorded deepfake video played into a live call, sometimes with the attacker muting their own camera and claiming connectivity issues to explain why the &amp;#8220;executive&amp;#8221; doesn&amp;#8217;t respond naturally to follow-up questions.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;More sophisticated attacks use real-time face-swapping tools during an actual live call, letting the attacker respond, nod, and react in the moment, which is far harder to detect.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A third pattern has emerged, which relies on &lt;a href=&quot;https://proton.me/business/drive/templates/onboarding-checklist&quot;&gt;onboarding&lt;/a&gt; and compliance meetings specifically. A synthetic video persona posing as an auditor, a new starter, or an HR contact can sit through an entire meeting designed to extract system access, security answers, or credentials, precisely because those meetings are built around the assumption that a video call with a real person is inherently trustworthy.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;A real-world deepfake fraud example&amp;nbsp;&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In 2024, a finance employee at the Hong Kong office of &lt;a href=&quot;https://www.cnn.com/2024/05/16/tech/arup-deepfake-scam-loss-hong-kong-intl-hnk&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Arup&lt;/a&gt;, a UK-headquartered engineering firm, joined a video call with people who appeared to be the company&amp;#8217;s CFO and several colleagues. Every person on that call was an AI-generated deepfake, built from publicly available footage of real executives. &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Believing the request was genuine, the employee authorized fifteen transfers totaling roughly $25 million before the fraud was discovered, and only then because he happened to follow up with the company&amp;#8217;s actual head office about the &amp;#8220;confidential transaction&amp;#8221; he&amp;#8217;d just completed.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The Arup case remains the clearest illustration of what this attack looks like at scale, but it&amp;#8217;s not a unique incident. &lt;a href=&quot;https://www.ibtimes.co.uk/ai-driven-fraud-costs-uk-1-28-billion-1808188&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;UK Finance&amp;#8217;s Fraud Report 2026&lt;/a&gt; found that overall payment fraud losses reached £1.28 billion in 2025, and specifically flagged organized criminal groups increasingly using deepfakes, cloned voices, and synthetic identities to impersonate trusted individuals and bypass identity checks. &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Separate industry research from &lt;a href=&quot;https://sumsub.com/blog/fraud-trends/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Sumsub&lt;/a&gt; recorded a 94% year-on-year rise in UK deepfake attempts, and a &lt;a href=&quot;https://keepnetlabs.com/blog/deepfake-statistics-and-trends&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Gartner survey of security leaders&lt;/a&gt; found that 62% of organizations had experienced some form of deepfake attack in the prior twelve months. Any business that still treats this as a future problem is behind where the data already is.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The Arup incident is particularly instructive of what to watch out for. The employee&amp;#8217;s initial instinct was sound: he treated the original email as a probable phishing attempt and asked for a video call specifically to confirm it, which is exactly the verification step most security training would recommend.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The failure happened at the next step, when the video call itself was treated as sufficient proof, because nobody had told him that a convincing face on screen is no longer reliable. At that moment, the failure was caused by insufficient business training, not by the employee.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What are some potential deepfake fraud scenarios?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The mechanics described above manifest in a handful of recurring scenarios, each aimed at a different point of leverage inside a business. They share the same underlying trick; a convincing face and voice on a call that looks entirely normal, but the target and the payoff can differ.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;A CFO&amp;#8217;s face authorizing a wire transfer&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A deepfake of a senior finance executive appears on a call and instructs a subordinate to process an urgent, confidential payment. The presence of a familiar, apparently live face overrides doubts that an email alone would have triggered.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;A fake auditor extracting system credentials&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A synthetic persona posing as an external auditor or compliance reviewer conducts a video interview with IT or finance staff, framed as a routine review, and asks questions specifically designed to surface system access details, security question answers, or login information.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;A synthetic HR manager onboarding a new employee&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A deepfake HR contact hosts an onboarding call with a genuinely new starter, or with an existing employee under the guise of a policy update, and uses the session to capture details about internal systems, access permissions, or credential recovery information.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Board member impersonation to a financial officer&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A deepfake of a board member or senior non-executive joins a call with a financial officer to authorize a transaction or request sensitive financial information, leaning on the authority of a role that a finance team is culturally trained not to question.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Why deepfake fraud is harder to catch&amp;nbsp;&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Most anti-phishing and anti-vishing training programs work by teaching people to add friction to a process that someone’s trying to rush through: an email can be forwarded to IT for double-checking, a phone call can be ended in order to verify a phone number.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Video calls don&amp;#8217;t get the same instinctive scrutiny, because for years a video call has been the closest digital substitute for being in a room with someone. Employees are rarely told to be suspicious of a colleague&amp;#8217;s face, because the cultural assumption behind video conferencing is that it’s totally reliable.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This assumption is what deepfake video fraud exploits. An attacker doesn&amp;#8217;t need to defeat an employee&amp;#8217;s skepticism about the request itself. They need only supply the one thing that has always ended skepticism in the past; a familiar face responding naturally in real time.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That&amp;#8217;s a much higher bar for an employee to meet, which is why the verification protocols for this channel need to be procedural rather than relying on someone simply noticing something is off.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;There&amp;#8217;s also a social dynamic that has to be challenged. Questioning a written request feels like ordinary diligence. Questioning a phone call feels reasonable, since impersonating a voice has been a known risk for years.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;But questioning a face on a video call, particularly a senior colleague&amp;#8217;s, can feel closer to an accusation, which is precisely why employees hesitate to do it even when something about the interaction feels slightly off. Removing that social cost, making the question routine and expected rather than awkward, is as much a part of &lt;a href=&quot;https://proton.me/blog/deepfake-prevention&quot;&gt;deepfake prevention&lt;/a&gt; and defense as any technical control.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Verification protocols that work specifically for video&lt;/h2&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Create a code&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Pre-agreed code words or gestures, established in advance through a separate channel, are one of the few things a deepfake genuinely can’t produce, because they don&amp;#8217;t exist in any public footage an attacker could train a model on.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A simple, changeable phrase or physical signal, confirmed periodically among senior staff and finance teams, gives employees something concrete to ask for rather than relying on a subjective sense that a call feels wrong.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Set authorization rules in stone&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;No financial authorization or credential disclosure should ever take place via video call alone. This has to be a concrete policy, not a judgement call left to whoever is on the call at the time: any request of that kind, regardless of who appears to be asking, requires a second confirmation through a genuinely separate channel, using contact details already on file rather than anything supplied during the call itself.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Employees need explicit, repeated permission to ask &amp;#8220;is this really you?&amp;#8221; on any call, regardless of who appears to be on screen. They should also feel comfortable to ask for proof via another channel that the person is who they say they are.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The instinct that stops people from questioning a senior figure is precisely what this attack relies on, and that instinct only goes away when leadership makes it unambiguous that the question is always acceptable.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Keep records&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Recording and logging sensitive video meetings, particularly anything involving financial authorization, credential access, or onboarding, gives a business something to review after the fact if a request turns out to have been fraudulent, and the knowledge that a meeting is logged is itself a mild deterrent against attackers who prefer to operate without a trail.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Treat video calls the same as you treat an email&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Deepfake video fraud succeeds because it exploits the one channel businesses have never trained employees to question. Email deception is covered by &lt;a href=&quot;https://proton.me/blog/phishing-attacks&quot;&gt;phishing awareness&lt;/a&gt;, and voice deception is covered by callback verification and the training we&amp;#8217;ve written about for &lt;a href=&quot;https://proton.me/business/blog/social-engineering-training-employees&quot;&gt;social engineering more broadly&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Being aware of deepfake video calls doesn’t require employees to become forensic analysts capable of spotting a synthetic video frame by frame. It requires a business to accept that a convincing face and voice are no longer proof of anything on their own, and to build verification habits that don&amp;#8217;t depend on anyone becoming suspicious in the moment.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Reinforcing that culture alongside the wider practices covered in our guide to &lt;a href=&quot;https://proton.me/blog/small-business-cyber-security-culture-workplace&quot;&gt;building a strong workplace security culture&lt;/a&gt; gives a team the same instinct for video that good training already builds for email and phone calls.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;The credential connection: limiting what a failed verification can reach&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Whatever form a deepfake video attack takes, CFO fraud, a fake auditor, a synthetic HR contact, it&amp;#8217;s ultimately aiming at one of two things: a financial transaction or a set of credentials. The video is simply the delivery mechanism for a request that, if it succeeds, either moves money directly or gives the attacker a login that lets them cause damage on their own terms.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is why credential hygiene is important, even when the attack itself has nothing to do with a stolen password at first. If a deepfake call tricks someone into handing over a credential, unique passwords and multi-factor authentication limit what that single credential can actually reach.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The same containment principle we&amp;#8217;ve covered in relation to &lt;a href=&quot;https://proton.me/business/blog/business-email-compromise-ceo-fraud&quot;&gt;business email compromise&lt;/a&gt; applies here: The goal isn&amp;#8217;t to make every employee individually unbeatable against a sophisticated attack, it&amp;#8217;s to make sure that when verification fails once, the damage stays contained.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt; like Proton Pass for Business makes containment realistic to maintain: It removes the pressure to reuse familiar passwords across accounts and makes it easy for employees to adhere to your &lt;a href=&quot;https://proton.me/business/pass/password-policy&quot;&gt;password policies&lt;/a&gt;. Paired with a secure platform for &lt;a href=&quot;https://proton.me/business/meet&quot;&gt;video conferencing&lt;/a&gt; and a workplace culture that treats pausing to verify as normal rather than suspicious, that combination is what actually limits the damage when video calls themselves can no longer be fully trusted.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Reduce your team&amp;#8217;s exposure to impersonation fraud with a &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt;.&lt;/p&gt;
</content:encoded><category>For business</category><author>Ben Wolford</author></item><item><title>Password health checks: how to continuously audit your business credentials</title><link>https://proton.me/business/blog/password-health-check</link><guid isPermaLink="true">https://proton.me/business/blog/password-health-check</guid><description>Learn how password health monitoring helps businesses detect weak, reused, and breached credentials before they become security risks.</description><pubDate>Wed, 09 Sep 2026 16:19:49 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Businesses often face many small risks like reused passwords, active accounts for ex-employees, and accounts for services you don’t use anymore. On their own they don’t seem dangerous, but as they build they create a credential environment that is harder to trust.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The antidote to this issue is regular password health checks. A one-time audit can show what needs fixing at that moment, but password risk keeps changing as employees create new accounts, teams adopt new software, and fresh breach data appears online.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Password health monitoring turns credential security into an ongoing practice your business can rely on. Instead of waiting for the next annual review, admins can keep track of weak, reused, breached, and inactive credentials across the business immediately, then fix the most urgent risks before they become an entry point.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For small and mid-sized businesses (SMEs), this visibility is especially useful because people often work across multiple disciplines and departments. They may share access to move faster, reuse passwords so there is less to remember, or leave old accounts active even though no one uses them anymore. Without continuous monitoring and strong &lt;a href=&quot;https://proton.me/business/pass/data-breach-protection&quot;&gt;data breach protection&lt;/a&gt; procedures in place, these helpful but risky habits can stay hidden for months.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What is password health monitoring?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Password health monitoring means continuously checking business credentials for signs of risk. In modern &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password managers&lt;/a&gt; it works as a built-in feature rather than a manual process teams have to run.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Unlike a one-time &lt;a href=&quot;https://proton.me/business/blog/password-audit-business&quot;&gt;password audit&lt;/a&gt;, monitoring is ongoing rather than limited to an annual security review or a compliance request. This gives admins a regular view of credential health, so weak password detection and breach response become part of normal, quick operations.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In practice, password health monitoring gives admins a way to see credential problems while they are still manageable. Weak and repeated passwords, exposed logins, or accounts with no clear owner can all look like separate issues. Together, they show whether a business is keeping credential risk under control or letting it accumulate quietly.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A secure &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt; like Proton Pass for Business gives teams the visibility they need. It continuously checks password strength, detects reuse across accounts, and monitors the dark web for compromised credentials, so admins see problems without running manual reviews.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The UK’s &lt;a href=&quot;https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2024&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Cyber Security Breaches Survey 2024&lt;/a&gt; found that half of UK businesses reported identifying a cyber security breach or attack in the previous 12 months. Not every incident begins with a password, but this finding reinforces that basic security hygiene has to be maintained continuously.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For credentials, that means checking password health often enough to catch weak, reused, breached, or forgotten, or inactive accounts before they become part of a larger problem.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;The four dimensions of password health&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A password health report should show more than whether credentials are stored in the right place. A &lt;a href=&quot;https://proton.me/business/pass/password-vault&quot;&gt;password vault&lt;/a&gt; can keep passwords from being scattered across chats and spreadsheets (vaults can also be shared securely across the team using Proton Pass), but just because a credential is stored securely doesn’t mean it is itself secure.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Some may still be too weak, reused across services, exposed in breach data, or attached to accounts the business no longer needs. Monitoring those signals is what turns password management from a passive vault into an active security tool.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For that reason, password health is best understood across four areas:&amp;nbsp;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Strength&lt;/li&gt;



&lt;li&gt;Uniqueness&lt;/li&gt;



&lt;li&gt;Breach exposure&lt;/li&gt;



&lt;li&gt;Account activity&lt;/li&gt;
&lt;/ul&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Password strength&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A &lt;a href=&quot;https://proton.me/blog/how-to-create-a-strong-password&quot;&gt;strong password&lt;/a&gt; is long, unpredictable, and difficult to guess or crack. Weak passwords often come from habit: a company name with a year, a familiar phrase with a number, or a variation of an old password that feels easier to remember.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton’s &lt;a href=&quot;https://proton.me/pass/password-strength-tester&quot;&gt;password strength tester&lt;/a&gt; can help people understand what makes a password stronger, but for business use, it’s also important to understand whether weak credentials are being created and stored across your business network.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If weak passwords keep appearing, the business may need a stronger &lt;a href=&quot;https://proton.me/business/pass/password-policy&quot;&gt;password policy&lt;/a&gt;, clearer &lt;a href=&quot;https://proton.me/business/drive/templates/onboarding-checklist&quot;&gt;onboarding&lt;/a&gt;, or better employee guidance. Proton Pass for Business makes this easier: its built-in &lt;a href=&quot;https://proton.me/pass/password-generator&quot;&gt;password generator&lt;/a&gt; creates a strong, random password whenever an employee needs one, so meeting the policy won’t create extra effort.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Password uniqueness&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Password reuse is one of the most common credential risks because it feels convenient. It’s easy to create an account for a new service, reuse a password, and move on. The issue with this is that one exposed password can then open more than one door.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In a business, reuse can happen across work tools, between personal and work accounts, or across shared credentials. Monitoring helps admins see where the same password appears more than once and which accounts need to be changed first.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is especially important for admin portals, finance accounts, email, CRM systems, cloud services, and any tool that stores customer or employee information. A reused password in a low-risk tool can become much more serious if the same password also protects a sensitive account.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Breach status&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A password may be strong and unique when it is created, then become risky later because it appears in breach data. Regular password monitoring helps you identify this issue if and when it occurs.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;New breaches are discovered constantly, and credential exposure doesn’t always become visible at the moment an incident happens. A password can appear in public datasets months later, an employee may have used a business email address on a service the company doesn’t manage, or a credential that was marked as safe during the last review may no longer be safe due to breach exposure.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton’s &lt;a href=&quot;https://proton.me/business/pass/breach-observatory&quot;&gt;Data Breach Observatory&lt;/a&gt; shows how exposed credentials can create risk across companies, teams, and industries. Continuous monitoring shortens the time between exposure and action. It also helps admins judge urgency. A breached credential for an old newsletter platform may need to be replaced, but it does not carry the same weight as exposure tied to payroll, cloud hosting, a domain registrar, or any account with admin privileges.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Account activity&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Account activity is different from password quality. A password can be strong, reused, or exposed regardless of how often the account is used; this dimension looks at whether the account itself is still active, owned, and needed. An inactive account is one that has not been used recently. A forgotten account is one nobody claims ownership of, or even remembers exists.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Both are easy to overlook. They may belong to former employees, temporary contractors, legacy software, or tools a team stopped using. Even if nobody uses them anymore, they can still create risk if the credentials remain valid.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Health monitoring can surface accounts that have gone unused for a long time, but deciding what happens to them is a management task. Based on that review, admins may remove credentials from the vault, assign ownership, adjust access, or close the account directly in the service. Others may need ownership assigned, access reviewed, or the account closed directly in the service.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Inactivity is not always dangerous in isolation. Some credentials are rarely used because they belong to backup systems, emergency accounts, or annual renewal portals. But if the business cannot explain why an account exists, who owns it, and whether it is still needed, that account deserves review.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What credentials and accounts businesses should monitor continuously&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Not every password issue carries the same risk. Continuous monitoring should help separate urgent problems from lower-priority clean-up.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A practical password health check should monitor:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Weak passwords below policy thresholds.&lt;/strong&gt; These should be replaced with strong, generated passwords, especially for accounts connected to customer data, finance, admin settings, or infrastructure.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Reused passwords across multiple services.&lt;/strong&gt; Reuse should be removed quickly when it affects sensitive systems or accounts with broad access.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Credentials linked to breach exposure.&lt;/strong&gt; Breached credentials should be treated as urgent, even if the account looks low risk. The same password may have been used somewhere else.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Accounts with no MFA enabled.&lt;/strong&gt; Password health is stronger when important accounts are protected by &lt;a href=&quot;https://proton.me/business/blog/multi-factor-authentication-business&quot;&gt;multi-factor authentication&lt;/a&gt; (MFA). Monitoring should highlight high-value accounts that still depend on a password alone.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Inactive or unclear accounts.&lt;/strong&gt; Credentials with no clear owner or current purpose should be reviewed, reassigned, archived, or removed where appropriate.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Privileged credentials.&lt;/strong&gt; Admin accounts, finance portals, HR systems, backup services, and infrastructure logins deserve a stricter standard than everyday operational accounts.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is where a clear policy helps. Proton’s guide to &lt;a href=&quot;https://proton.me/blog/creating-password-policy&quot;&gt;creating a password policy&lt;/a&gt; explains how businesses can define rules for password creation, secure sharing, MFA, and access management. Monitoring is what turns those rules into an ongoing practice. Without it, a policy can exist on paper while weak or reused passwords continue to appear in daily work.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How to build a password health monitoring cadence&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Continuous monitoring does not mean every issue needs to be reviewed every day. For most businesses, the right cadence combines regular reports with faster action when a critical incident occurs.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Here’s a simple starting point for monitoring cadence:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Critical alerts as soon as possible:&lt;/strong&gt; breached credentials, reused passwords on sensitive accounts, or weak passwords connected to admin, finance, HR, customer, or infrastructure systems.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Monthly password health reports:&lt;/strong&gt; overall score, number of weak passwords, number of reused passwords, breached credentials, inactive accounts, MFA coverage, and progress since the previous month.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Quarterly full reviews:&lt;/strong&gt; deeper review of shared credentials, privileged vaults, inactive accounts, and department-level access.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Event-based checks:&lt;/strong&gt; onboarding, offboarding, role changes, vendor changes, mergers, new software adoption, or major breach announcements.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This cadence keeps password health visible without turning it into a constant manual burden. It also creates a rhythm for accountability. IT can see where risk is increasing. Managers can review credentials owned by their teams. Leadership can track whether credential hygiene is improving or drifting.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What a useful password health report should show&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A password health report should help people decide what to fix first. If it only shows raw numbers, it becomes easy to ignore. If it gives every issue the same weight, it can send teams in the wrong direction.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The most useful view is one that combines status, urgency, and progress. Admins need to see where weak, reused, breached, or inactive credentials exist, but they also need to understand which of those issues create the greatest risk for the business. A weak password on an old test account still deserves attention, but it should not compete with a breached credential tied to payroll, cloud hosting, email, or a domain registrar.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Group management in Proton Pass for Business supports this kind of prioritization. IT can create &lt;a href=&quot;https://proton.me/blog/pass-groups&quot;&gt;groups&lt;/a&gt; that map to departments, teams, or client accounts and assign vault access at the group level, so when someone joins or leaves a team, their vault access updates automatically, and the health report reflects a structure that matches how the business actually works.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The report should also show whether credential security is improving. A rising number of reused passwords may point to poor adoption of the password manager. Slow remediation of breached credentials may show that ownership is unclear. Too many inactive accounts may suggest that offboarding and software review processes need work.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Overall, password health should be a clear indicator of your business’s credential hygiene: where risk is building, how quickly teams respond, and whether password policy is changing behavior over time.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How Proton Pass Monitor makes credential risk visible&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton Pass for Business is a secure &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt; that helps teams store, generate, autofill, and share credentials securely. For password health monitoring, businesses can use Pass Monitor.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Pass Monitor gives admins visibility into weak, reused, and breached credentials across the team. Instead of waiting for a manual review, businesses can see which passwords need attention and where the most serious risks are. That makes password health easier to manage as part of day-to-day security operations.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For businesses with growing teams, this visibility is important because credential risk is rarely concentrated in one place. Some issues come from old shared passwords. Others come from personal habits, rushed onboarding, abandoned accounts, or tools adopted without IT involvement. Pass Monitor helps surface those issues so teams can act before a weak or exposed credential becomes a larger incident.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton Pass for Business gives teams the foundations for stronger &lt;a href=&quot;https://proton.me/business/pass/credential-management&quot;&gt;credential management&lt;/a&gt;: encrypted vaults, secure sharing, strong password generation, autofill, built-in two-factor authentication, passkeys, admin policies, logs, role-based access control, SCIM provisioning, and SSO integration. For IT teams, Proton’s &lt;a href=&quot;https://proton.me/business/pass/for-it-teams&quot;&gt;Pass for IT teams&lt;/a&gt; page explains how these features support centralized credential management across the business.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Pass Monitor should not replace policy, training, MFA, or access reviews. It makes those controls easier to enforce because admins are no longer relying on guesswork. It also closes the gap between policy and practice: rules that would otherwise exist only on paper become measurable and enforceable, and credentials spread across dozens of platforms stop accumulating invisible risk. They can see which credentials are weak, reused, or breached, then use that information to guide remediation.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Monitor your team’s credential health continuously with a &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt;.&lt;/p&gt;
</content:encoded><category>For business</category><author>Kate Menzies</author></item><item><title>Australia&amp;#8217;s opt-out law could change how social media algorithms work</title><link>https://proton.me/blog/social-media-algorithm</link><guid isPermaLink="true">https://proton.me/blog/social-media-algorithm</guid><description>Draft Australian legislation could let people switch off social media algorithms on apps like Instagram and TikTok. See why opt-out matters.</description><pubDate>Wed, 09 Sep 2026 11:39:20 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Australians may soon be able to switch off social media algorithms and see only posts from accounts they follow.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Australia plans to introduce new online safety laws that would give social media users ages 16 and older the option to turn off algorithm-driven feeds under a “&lt;a href=&quot;https://www.pm.gov.au/media/my-feed-my-way&quot;&gt;My Feed, My Way&lt;/a&gt;” initiative, while also imposing a digital duty of care on platforms to better protect children from harmful content.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The proposed laws would give the eSafety Commissioner (Australia’s online safety regulator) stronger enforcement powers and expose companies to fines of more than A$100 million for non-compliance, though the legislation is expected to face political debate before passing parliament. Communications Minister Anika Wells called it “&lt;a href=&quot;https://www.theguardian.com/australia-news/2026/sep/08/australia-social-media-algorithm-switch-off-opt-out-digital-duty-of-care&quot;&gt;a global reckoning for big tech&lt;/a&gt;.”&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The law raises a question every internet user lives with: what is a social media algorithm, and why does controlling it matter?&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;a href=&quot;#what-is&quot;&gt;What is an algorithm in social media?&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#how-it-works&quot;&gt;How do social media algorithms work?&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#australia&quot;&gt;What would Australia&amp;#8217;s social media law change?&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#control&quot;&gt;How to take back control of your social media feed&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#privacy&quot;&gt;Algorithmic control starts with privacy&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 id=&quot;what-is&quot; class=&quot;wp-block-heading&quot;&gt;What is an algorithm in social media?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;An algorithm in social media is the system a platform uses to decide which posts, videos, ads, or recommendations to show you, and in what order.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Instead of showing only the newest posts from accounts you follow, the algorithm may rank content based on things like what you click, watch, like, share, search for, or spend time viewing. Its goal is usually to predict what will keep you on the platform.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Early social media feeds were much simpler than today’s. They were mostly chronological and based on people you had deliberately connected with, such as friends, pages, or accounts you followed. If someone posted something recently, it appeared near the top, with older posts moved down. Today, all major platforms, including &lt;a href=&quot;https://proton.me/blog/instagram-parental-controls&quot;&gt;Instagram&lt;/a&gt;, &lt;a href=&quot;https://protonvpn.com/blog/is-tiktok-safe&quot;&gt;TikTok&lt;/a&gt;, &lt;a href=&quot;https://protonvpn.com/blog/youtube-alternatives&quot;&gt;YouTube&lt;/a&gt;, &lt;a href=&quot;https://proton.me/blog/facebook-data-privacy-revelation&quot;&gt;Facebook&lt;/a&gt;, and X, use a recommendation algorithm.&lt;/p&gt;



&lt;h2 id=&quot;how-it-works&quot; class=&quot;wp-block-heading&quot;&gt;How do social media algorithms work?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Social media algorithms work by constantly making predictions about what you’re most likely to engage with. Platforms keep their ranking systems secret, but the mechanics are consistent across the industry. Candidate posts are scored on signals like popularity, engagement speed, and your history with a creator. Machine learning models predict how likely you are to like, share, or watch to the end. The highest-scoring content fills your feed. Your reaction becomes training data, so tomorrow&amp;#8217;s feed is essentially tuned to yesterday&amp;#8217;s behavior.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The goal of a social media platform is to keep you engaged. That business model has also come under growing legal scrutiny: In 2026, &lt;a href=&quot;https://proton.me/blog/meta-teen-addiction-settlement&quot;&gt;Meta agreed to an $18 billion settlement&lt;/a&gt; over claims that Facebook and Instagram were designed to addict children and teenagers, while admitting no wrongdoing.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Generally, content that triggers outrage, envy, or anxiety generates more engagement, so it gets amplified. To find out which content is most likely to engage individual people, platforms collect&amp;nbsp;vast amounts of &lt;a href=&quot;https://proton.me/blog/personal-data&quot;&gt;personal data&lt;/a&gt;.&lt;/p&gt;



&lt;h2 id=&quot;australia&quot; class=&quot;wp-block-heading&quot;&gt;What would Australia&amp;#8217;s social media law change?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Turning off the algorithm would mean seeing a simpler feed made up mainly of content from the people and groups you have deliberately chosen to follow. Australia&amp;#8217;s social media law would:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Allow people over 16 to &lt;strong&gt;opt out of algorithmic feeds&lt;/strong&gt;. Platforms must notify everyone and ask them to choose a default feed.&lt;/li&gt;



&lt;li&gt;Require online services (including games, apps, and AI chatbots) to protect children (under 18) from specific harms, including pornography, content promoting eating disorders, misogynistic content, glorification of crime, and content causing serious mental stress.&lt;/li&gt;



&lt;li&gt;Give the eSafety Commissioner power to issue removal notices, including for &amp;#8220;&lt;a href=&quot;https://minister.infrastructure.gov.au/wells/media-release/taking-stand-against-abusive-technology&quot;&gt;nudify&lt;/a&gt;&amp;#8221; apps used to create non-consensual intimate images (&lt;a href=&quot;https://proton.me/blog/deepfake-prevention&quot;&gt;deepfakes&lt;/a&gt;).&lt;/li&gt;



&lt;li&gt;Impose fines above &lt;strong&gt;A$100 million&lt;/strong&gt; for non-compliance.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Australia follows in the footsteps of the EU&amp;#8217;s Digital Services Act, which requires the largest platforms to offer users a recommender option that is not based on profiling. The rollout has not always been smooth, however, with regulators arguing that some platforms have made opting out unnecessarily difficult.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The proposed law also builds on &lt;a href=&quot;https://proton.me/blog/australia-social-media-ban-privacy&quot;&gt;Australia&amp;#8217;s world-first under-16 social media ban&lt;/a&gt;, which took effect in December 2025. Similar measures are now being pursued in &lt;a href=&quot;https://proton.me/blog/france-social-media-ban&quot;&gt;France&lt;/a&gt;, the &lt;a href=&quot;https://proton.me/blog/uk-social-media-ban-privacy&quot;&gt;UK&lt;/a&gt;, and &lt;a href=&quot;https://www.bbc.com/news/articles/cj068q7qj19o&quot;&gt;New Zealand&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Whether Australia&amp;#8217;s new approach to social media algorithms will have a similar influence remains to be seen, but if the legislation passes, other governments are likely to watch closely. &amp;#8220;This is not about giving government control, it is about giving people control,&amp;#8221; Prime Minister Anthony Albanese said.&lt;/p&gt;



&lt;h2 id=&quot;control&quot; class=&quot;wp-block-heading&quot;&gt;How to take back control of your social media feed&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You do not have to wait for new legislation to take some control over what appears in your feed. Most major platforms already offer a few ways to reduce algorithmic recommendations, although they will not be eliminated entirely:&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Use Following or chronological feeds where available.&lt;/strong&gt; Instagram, Facebook, X, and other platforms offer views that prioritize accounts you already follow rather than recommended posts.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Turn off or limit personalization.&lt;/strong&gt; Check your privacy, ad, and recommendation settings for options to reduce personalized content, targeted ads, or activity-based recommendations.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Tell the algorithm what you do not want.&lt;/strong&gt; Use controls such as “Not interested,” “Show fewer posts like this,” or “Mute” instead of simply scrolling past unwanted content.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Be selective about what you engage with.&lt;/strong&gt; Watching, liking, commenting on, or repeatedly viewing a post can signal that you want more of that kind of content, even when you are engaging because it makes you angry.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Unfollow, mute, and block aggressively.&lt;/strong&gt; Curating the accounts you follow can make following-only feeds much more useful and reduce exposure to content you never asked to see.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Disable autoplay and unnecessary notifications.&lt;/strong&gt; These features are designed to draw you back into the app and keep content flowing with as little friction as possible.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Use the web version or alternative clients when possible.&lt;/strong&gt; Some interfaces make it easier to avoid recommendation-heavy features such as Shorts, Reels, or For You feeds.&lt;/p&gt;



&lt;blockquote class=&quot;wp-block-quote is-layout-flow wp-block-quote-is-layout-flow&quot;&gt;
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Explore &lt;a href=&quot;https://proton.me/learn/european-alternatives/european-social-media-apps&quot;&gt;European social media alternatives&lt;/a&gt; designed around greater user control and privacy rather than profiling-based feeds.&lt;/p&gt;
&lt;/blockquote&gt;



&lt;h2 id=&quot;privacy&quot; class=&quot;wp-block-heading&quot;&gt;Algorithmic control starts with privacy&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Australia’s proposal addresses one part of a much bigger problem. Algorithmic feeds are powerful because platforms know so much about the people using them. Giving users control over what appears in their feed is a meaningful step, but real digital autonomy also means having control over the data used to profile them in the first place.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;At Proton, we believe people should be able to use the internet without surrendering their privacy, whether that means choosing what appears in their feed or choosing services that don’t build their business around tracking them.&lt;/p&gt;
</content:encoded><category>News</category><author>Edward Komenda</author></item><item><title>7 privacy tools experts actually use</title><link>https://proton.me/blog/privacy-tools-experts-use</link><guid isPermaLink="true">https://proton.me/blog/privacy-tools-experts-use</guid><description>Explore privacy tools that privacy experts use for everyda, from GrapheneOS and Organic Maps to Qubes OS, F-Droid, Cape, Tor, and VPNs.</description><pubDate>Tue, 08 Sep 2026 18:11:26 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Privacy software can get complicated quickly. There are operating systems to replace, apps to swap, networks to understand, and settings buried several menus deep.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You don&amp;#8217;t need to use all of them. But the tools below show how one privacy expert approaches everyday technology: reduce unnecessary data collection, separate sensitive activity, and make more deliberate choices about who gets access to your information.&lt;/p&gt;



&lt;figure class=&quot;wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio&quot;&gt;&lt;div class=&quot;wp-block-embed__wrapper&quot;&gt;
&lt;iframe loading=&quot;lazy&quot; title=&quot;Seven Digital Tools Experts Use To Vanish Online&quot; width=&quot;750&quot; height=&quot;422&quot; src=&quot;https://www.youtube-nocookie.com/embed/5mq_7IMJF6g?feature=oembed&quot; frameborder=&quot;0&quot; allow=&quot;accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share&quot; referrerpolicy=&quot;strict-origin-when-cross-origin&quot; allowfullscreen&gt;&lt;/iframe&gt;
&lt;/div&gt;&lt;/figure&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;GrapheneOS gives you more control over Android&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://grapheneos.org/&quot;&gt;GrapheneOS&lt;/a&gt; is an alternative operating system for Android phones that puts more control over privacy and security in the user&amp;#8217;s hands. It doesn&amp;#8217;t come with Google apps and services by default, although Google Play can be installed as sandboxed apps when needed.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;One of the useful differences is how granular the permissions can be. You can control whether an app has access to your location, camera, microphone, network, and other device features. An app can remain installed while having its ability to communicate over the internet turned off.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;GrapheneOS also includes features designed to protect sensitive data if a device is compromised or handed over under pressure. Its duress PIN can wipe the device when entered at the appropriate credential prompt.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The appeal is simple: you can keep using a smartphone without giving every app the same level of access.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For a full list of its privacy and security features, see the official &lt;a href=&quot;https://grapheneos.org/features&quot;&gt;&lt;u&gt;GrapheneOS features overview&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Organic Maps works without a connection&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Maps are one of those phone features that can quietly involve location data. &lt;a href=&quot;https://organicmaps.app/&quot;&gt;&lt;u&gt;Organic Maps&lt;/u&gt;&lt;/a&gt; takes a different approach by allowing maps to be downloaded to your device for offline use.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Once a map is stored locally, you can search for places, see your position, and get directions without repeatedly sending your location to a remote server. That also makes the app useful when you have little or no connectivity.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For someone trying to reduce their reliance on Google or Apple services, it is a straightforward change. You still get a practical navigation tool, but more of the information needed to use it stays on your phone.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you&amp;#8217;re keeping your existing apps, it&amp;#8217;s also worth reviewing your &lt;a href=&quot;https://protonvpn.com/blog/how-to-disable-location-services&quot;&gt;&lt;u&gt;location services&lt;/u&gt;&lt;/a&gt; and deciding which ones actually need access to your location.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Qubes OS separates your digital life&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Imagine keeping one computer for work, another for personal activity, another for banking, and another for tinkering. Qubes OS tries to provide that separation on a single machine and uses virtual machines to create isolated environments, or &amp;#8220;qubes,&amp;#8221; for different parts of your life.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The benefit is containment. If you open something malicious inside one environment, the goal is to stop that activity from automatically gaining access to everything else on the computer.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It&amp;#8217;s a digital version of keeping your eggs in different baskets.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You can learn more about the model in the &lt;a href=&quot;https://www.qubes-os.org/intro/&quot;&gt;&lt;u&gt;official Qubes OS documentation&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;RSS puts you in charge of your feed&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;An RSS reader may seem like an odd choice for a privacy toolkit, but it solves a different problem: who decides what information you see?&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Most major platforms use recommendation systems to select content for you. An RSS reader lets you choose the sources yourself. You can follow news sites, blogs, YouTube channels, and other websites, then bring their updates together in one feed.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That means you can check the sources you care about without opening several apps and letting each one decide what deserves your attention.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It is a small change, but it gives you more control over your information diet.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;F-Droid offers an alternative app store&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;On Android, you&amp;#8217;re not limited to the Google Play Store. &lt;a href=&quot;https://f-droid.org/en/about/&quot;&gt;&lt;u&gt;F-Droid&lt;/u&gt;&lt;/a&gt; is an app distribution platform focused on free and open-source software.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Open-source software makes its underlying code publicly available. That doesn&amp;#8217;t automatically make an app safe or private, but it gives researchers and other developers the opportunity to inspect how it works. They can potentially spot security problems, identify unexpected behavior, and contribute fixes.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;F-Droid also doesn&amp;#8217;t require an account just to download apps. That makes it another example of a small default you can change if you want more control over how software reaches your phone.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton has also made its Android app available through F-Droid, explaining that the repository provides another way to download the app without registering for a Google account. &lt;a href=&quot;https://protonvpn.com/blog/f-droid-download&quot;&gt;&lt;u&gt;Learn more about Proton VPN on F-Droid&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Cape puts privacy at the carrier level&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Your mobile carrier sits in a sensitive position because it has to handle information needed to provide cellular service. That makes the carrier itself part of your privacy equation.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://www.cape.co/&quot;&gt;Cape&lt;/a&gt; is a mobile carrier designed with privacy and security as major considerations. Its approach is to minimize the personal information it collects and retains. For example, Cape says it doesn&amp;#8217;t require details such as your name or home address when you sign up.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The underlying idea is broader than one carrier. Your phone company needs enough information to provide service. That doesn&amp;#8217;t mean it needs every detail about you.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Tor Browser adds another layer of anonymity&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Tor is often associated with the dark web, but its privacy uses are much broader. Journalists, activists, and people facing serious threats can use the network to make it harder to connect their identity with their online activity.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Tor Browser sends traffic through multiple relays. Each relay has a limited view of the connection, so no single relay needs to know both where the traffic originated and where it is going. The route also changes rather than relying on the same three servers every time.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Tor Browser takes another step by making browsing sessions look more alike. Techniques such as letterboxing standardize the browser window, while consistent settings make individual users harder to distinguish.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;There is a trade-off. Tor can be slow, and it&amp;#8217;s designed for a different privacy model than a conventional VPN. That extra privacy can come at the cost of speed and convenience.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The &lt;a href=&quot;https://support.torproject.org/tor-browser/getting-started/about-tor-browser/&quot;&gt;&lt;u&gt;Tor Project&amp;#8217;s explanation of Tor Browser&lt;/u&gt;&lt;/a&gt; goes into more detail about how the browser works and why it is designed this way.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Where a VPN fits in&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A &lt;a href=&quot;https://protonvpn.com/blog/tor-vpn&quot;&gt;VPN and Tor&lt;/a&gt; can both improve online privacy, but they solve different problems.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A VPN creates an encrypted connection between your device and a VPN server and hides your IP address from the websites you visit. That makes it useful for everyday browsing, particularly when you want to protect traffic on an untrusted network or keep your IP address private.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A VPN can also help reduce IP-based &lt;a href=&quot;https://protonvpn.com/blog/how-to-disable-location-services&quot;&gt;location tracking&lt;/a&gt;. This is handy as just relying on turning off GPS and other device-level location services doesn&amp;#8217;t prevent websites from estimating your location from your IP address.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Tor uses a network of relays to make it harder to connect your identity with your destination. It&amp;#8217;s generally slower and is primarily designed for anonymity rather than everyday convenience.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For most people, a VPN can be a practical privacy layer that works across the device. Tor is an option when you need stronger anonymity and can accept the performance trade-off.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Start with one change&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You don&amp;#8217;t need to replace your phone, abandon every major platform, or build a computer full of virtual machines to make a difference.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The more useful lesson from this toolkit is that privacy improvements can be incremental. You might start by switching to an offline maps app, using an RSS reader, installing apps from a different source, or reviewing which permissions your existing apps have. Even a single change can reduce the amount of information you hand over by default.&lt;/p&gt;
</content:encoded><category>Guides</category><category>Videos</category><author>Proton Team</author></item><item><title>A Gmail scam is exploiting Google Account recovery emails</title><link>https://proton.me/blog/google-account-recovery-gmail-scam</link><guid isPermaLink="true">https://proton.me/blog/google-account-recovery-gmail-scam</guid><description>See how the Google Account recovery Gmail scam uses real security emails and a fake Google call to trick victims, and learn the warning signs.</description><pubDate>Fri, 04 Sep 2026 11:59:42 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;One morning in August, a member of our team answered a call from a California number.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The caller, polished and speaking with a flawless American accent, claimed to be from Google. An attempt had been made, the caller said, to change the account recovery address on the employee&amp;#8217;s &lt;a href=&quot;https://proton.me/blog/is-gmail-secure&quot;&gt;Gmail&lt;/a&gt; account, and an email about it was sitting in his inbox at that very moment.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Upon further investigation, however, our team member soon learned things were not as they seemed.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This was a &lt;a href=&quot;https://proton.me/blog/what-is-phishing&quot;&gt;phishing&lt;/a&gt; scam, and a more sophisticated form of &lt;a href=&quot;https://proton.me/blog/what-is-social-engineering&quot;&gt;social engineering&lt;/a&gt;. It used a carefully scripted conversation designed to build just enough trust that you believe the caller really is Google, ultimately persuading you to hand over some form of access.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Our colleague ended the call before reaching that moment, so the exact ask went unheard. But the structure of the scam tells you exactly where it was headed.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;a href=&quot;#how&quot;&gt;How this Google account recovery scam works&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#tells&quot;&gt;The tells, annotated&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#why&quot;&gt;Why this Gmail scam is so convincing&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#protect&quot;&gt;How to protect yourself from account takeover attempts&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#safer-inbox&quot;&gt;A safer inbox starts with better email security&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 id=&quot;how&quot; class=&quot;wp-block-heading&quot;&gt;How this Google account recovery scam works&lt;/h2&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;The setup&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Before the phone rings, the scammer creates a fresh, anonymous Gmail address, which consists of random letters and digits. Using Google&amp;#8217;s legitimate &amp;#8220;add a recovery email&amp;#8221; flow, they try to add the victim&amp;#8217;s address as the&amp;nbsp;recovery email for the scammer&amp;#8217;s own throwaway account.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;The first real email&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Google&amp;#8217;s system needs the victim&amp;#8217;s confirmation, so an authentic message arrives asking them to verify the recovery email. The sender, branding, and code are real.&amp;nbsp;&lt;em&gt;(Figure 1&lt;/em&gt; &lt;em&gt;below&lt;/em&gt;&lt;em&gt;)&lt;/em&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;The call&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The scammer makes a call, poses as a member of Google&amp;#8217;s security team, and describes a suspicious account access attempt that was supposedly blocked, even claiming to have intercepted the victim&amp;#8217;s &lt;a href=&quot;https://proton.me/authenticator&quot;&gt;authenticator&lt;/a&gt; code. The word &amp;#8220;blocked&amp;#8221; casts the caller as the hero. In reality, the attack&amp;nbsp;&lt;em&gt;is&lt;/em&gt;&amp;nbsp;the phone call.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;The second real email&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Still on the line, the victim receives a genuine &amp;#8220;Security alert&amp;#8221; announcing that a recovery email was changed on a linked &lt;a href=&quot;https://proton.me/blog/delete-gmail-account#delete-google-account&quot;&gt;Google Account&lt;/a&gt;. Skimmed, it looks like a compromise. Read carefully, the fine print reveals it&amp;#8217;s a copy of an alert sent to the&amp;nbsp;&lt;em&gt;scammer&amp;#8217;s&lt;/em&gt;&amp;nbsp;address.&amp;nbsp;&lt;em&gt;(Figure 2 below)&lt;/em&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;The vanishing act&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The first email offers a legitimate escape: removing your address from the stranger&amp;#8217;s account. But the moment our colleague hung up, the scammer withdrew the recovery request, erasing the trail, and likely moved on to the next target.&lt;/p&gt;



&lt;h2 id=&quot;tells&quot; class=&quot;wp-block-heading&quot;&gt;The tells, annotated&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Figure 1 shows the first Google email, which contains a security code needed to confirm your address as the recovery email for the scammer’s account.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full is-resized&quot;&gt;&lt;img width=&quot;1338&quot; height=&quot;2229&quot; data-public-id=&quot;wp-pme/google-account-recovery-gmail-scam-1/google-account-recovery-gmail-scam-1.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1338,h_2229,c_scale/f_auto,q_auto/v1788514992/wp-pme/google-account-recovery-gmail-scam-1/google-account-recovery-gmail-scam-1.png?_i=AA&quot; alt=&quot;A Google Account recovery email scam on Gmail, explained&quot; class=&quot;wp-post-280021 wp-image-280022&quot; style=&quot;width:500px;height:auto&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;390 KB&quot; data-optsize=&quot;73 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;81.3&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=280022&quot; data-version=&quot;1788514992&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1788514992/wp-pme/google-account-recovery-gmail-scam-1/google-account-recovery-gmail-scam-1.png?_i=AA 1338w, https://res.cloudinary.com/dbulfrlrz/images/w_180,h_300,c_scale/f_auto,q_auto/v1788514992/wp-pme/google-account-recovery-gmail-scam-1/google-account-recovery-gmail-scam-1.png?_i=AA 180w, https://res.cloudinary.com/dbulfrlrz/images/w_615,h_1024,c_scale/f_auto,q_auto/v1788514992/wp-pme/google-account-recovery-gmail-scam-1/google-account-recovery-gmail-scam-1.png?_i=AA 615w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_1279,c_scale/f_auto,q_auto/v1788514992/wp-pme/google-account-recovery-gmail-scam-1/google-account-recovery-gmail-scam-1.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_922,h_1536,c_scale/f_auto,q_auto/v1788514992/wp-pme/google-account-recovery-gmail-scam-1/google-account-recovery-gmail-scam-1.png?_i=AA 922w, https://res.cloudinary.com/dbulfrlrz/images/w_1229,h_2048,c_scale/f_auto,q_auto/v1788514992/wp-pme/google-account-recovery-gmail-scam-1/google-account-recovery-gmail-scam-1.png?_i=AA 1229w&quot; sizes=&quot;auto, (max-width: 1338px) 100vw, 1338px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;The genuine Google sender&lt;/strong&gt;&amp;nbsp;— real, which is precisely what makes it dangerous.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;&amp;#8220;Wants to use your email address as their recovery email&amp;#8221;&lt;/strong&gt;&amp;nbsp;— the reversed logic, as this is about someone else&amp;#8217;s account.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;The anonymous throwaway address&lt;/strong&gt;&amp;nbsp;— no way to verify who&amp;#8217;s behind it.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;The expiring code&lt;/strong&gt;&amp;nbsp;— manufactured urgency, keeping you stressed and compliant.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;&amp;#8220;Remove email&amp;#8221;&lt;/strong&gt;&amp;nbsp;— the one action that stops it, and exactly what the scammer cancels when you hang up.&lt;/li&gt;
&lt;/ol&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Figure 2 shows how a genuine Google security alert can appear alarming at first.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full is-resized&quot;&gt;&lt;img width=&quot;1318&quot; height=&quot;2229&quot; data-public-id=&quot;wp-pme/google-account-recovery-gmail-scam-2/google-account-recovery-gmail-scam-2.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1318,h_2229,c_scale/f_auto,q_auto/v1788515000/wp-pme/google-account-recovery-gmail-scam-2/google-account-recovery-gmail-scam-2.png?_i=AA&quot; alt=&quot;A Google Account security alert scam on Gmail, explained&quot; class=&quot;wp-post-280021 wp-image-280046&quot; style=&quot;width:500px;height:auto&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;391 KB&quot; data-optsize=&quot;76 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;80.5&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=280046&quot; data-version=&quot;1788515000&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1788515000/wp-pme/google-account-recovery-gmail-scam-2/google-account-recovery-gmail-scam-2.png?_i=AA 1318w, https://res.cloudinary.com/dbulfrlrz/images/w_177,h_300,c_scale/f_auto,q_auto/v1788515000/wp-pme/google-account-recovery-gmail-scam-2/google-account-recovery-gmail-scam-2.png?_i=AA 177w, https://res.cloudinary.com/dbulfrlrz/images/w_605,h_1024,c_scale/f_auto,q_auto/v1788515000/wp-pme/google-account-recovery-gmail-scam-2/google-account-recovery-gmail-scam-2.png?_i=AA 605w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_1299,c_scale/f_auto,q_auto/v1788515000/wp-pme/google-account-recovery-gmail-scam-2/google-account-recovery-gmail-scam-2.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_908,h_1536,c_scale/f_auto,q_auto/v1788515000/wp-pme/google-account-recovery-gmail-scam-2/google-account-recovery-gmail-scam-2.png?_i=AA 908w, https://res.cloudinary.com/dbulfrlrz/images/w_1211,h_2048,c_scale/f_auto,q_auto/v1788515000/wp-pme/google-account-recovery-gmail-scam-2/google-account-recovery-gmail-scam-2.png?_i=AA 1211w&quot; sizes=&quot;auto, (max-width: 1318px) 100vw, 1318px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;The subject addresses the scammer&amp;#8217;s inbox, not yours&lt;/strong&gt;&amp;nbsp;— the first sign this alert isn&amp;#8217;t about you.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;&amp;#8220;A copy of a security alert sent to&amp;#8221; the throwaway address&lt;/strong&gt;&amp;nbsp;— the biggest tell, and the easiest to miss on a skim.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;The alarming headline&lt;/strong&gt;&amp;nbsp;— designed to scare before you read the fine print.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;&amp;#8220;If you didn&amp;#8217;t change it, check what happened&amp;#8221;&lt;/strong&gt;&amp;nbsp;— planted doubt that primes you to trust the caller.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;The &amp;#8220;Check activity&amp;#8221; button&lt;/strong&gt;&amp;nbsp;— a prompt to act fast instead of read carefully.&lt;/li&gt;
&lt;/ol&gt;



&lt;h2 id=&quot;why&quot; class=&quot;wp-block-heading&quot;&gt;Why this Gmail scam is so convincing&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Both &lt;a href=&quot;https://proton.me/business/mail/phishing-email&quot;&gt;phishing emails&lt;/a&gt; come from Google&amp;#8217;s real servers, so every conventional anti-phishing check passes.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Each element corroborates the others: real notifications, plus a caller who knows exactly what just landed in your inbox. At the same time, the conversation can discourage any attempt you may have to click &amp;#8220;Remove email&amp;#8221;, keeping you focused on the caller&amp;#8217;s instructions.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A &lt;a href=&quot;https://proton.me/blog/google-data-breach-gmail-warning&quot;&gt;Google data breach&lt;/a&gt; can make scams like this more convincing if exposed information gives attackers details they can use to personalize &lt;a href=&quot;https://proton.me/business/blog/vishing-attacks-business&quot;&gt;vishing&lt;/a&gt; or &lt;a href=&quot;https://proton.me/business/blog/phishing-attacks&quot;&gt;phishing attacks&lt;/a&gt;. Even when passwords aren’t leaked, names, contact details, or account-related information can help scammers sound more credible and build trust.&lt;/p&gt;



&lt;h2 id=&quot;protect&quot; class=&quot;wp-block-heading&quot;&gt;How to protect yourself from account takeover attempts&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You can protect yourself by slowing the interaction down and verifying what’s happening through Google directly:&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Hang up and verify independently.&lt;/strong&gt; If someone calls claiming to be from Google, end the call and check your account directly rather than following their instructions.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Read Google security emails carefully.&lt;/strong&gt; Pay attention to which account the alert actually refers to, especially any line saying the message is a copy of an alert sent to another address.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Do not share verification codes.&lt;/strong&gt; Google will not need you to read out an authenticator code, recovery code, or other sign-in credential over the phone.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Use “Remove email” if you do not recognize the account.&lt;/strong&gt; If Google says someone wants to use your address as their recovery email, remove it from that account.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Do not let the caller rush you.&lt;/strong&gt; Scammers rely on urgency to keep you reacting instead of checking what the notification actually says.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Review your Google Account security directly.&lt;/strong&gt; Open your account settings yourself and check recent activity, signed-in devices, recovery details, and security alerts.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Report suspicious calls and messages.&lt;/strong&gt; Reporting the attempt can help Google and your phone provider identify repeated abuse.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Review your&lt;/strong&gt; &lt;a href=&quot;https://proton.me/blog/google-privacy-settings&quot;&gt;&lt;strong&gt;Google privacy settings&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;.&lt;/strong&gt; While privacy settings won’t stop this particular scam, regularly checking what data you share and which apps and services have access to your Google Account can reduce your exposure.&lt;/p&gt;



&lt;h2 id=&quot;safer-inbox&quot; class=&quot;wp-block-heading&quot;&gt;A safer inbox starts with better email security&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Scams like this are a reminder that even legitimate security emails can be turned into tools for social engineering. Staying skeptical of unexpected calls, checking account activity independently, and reading alerts carefully can help you avoid falling for them.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Looking for a better &lt;a href=&quot;https://proton.me/mail/best-gmail-alternative&quot;&gt;alternative to Gmail&lt;/a&gt;? Proton Mail gives you a &lt;a href=&quot;https://proton.me/mail/&quot;&gt;secure email&lt;/a&gt; service built around protecting your data and communications with &lt;a href=&quot;https://proton.me/learn/encryption/types-of-encryption/what-is-end-to-end&quot;&gt;end-to-end&lt;/a&gt; and &lt;a href=&quot;https://proton.me/learn/encryption/types-of-encryption/zero-access&quot;&gt;zero-access encryption&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If someone tries a similar scam while pretending to be Proton, there’s a simple rule to remember: &lt;a href=&quot;https://proton.me/support/scam-call-alert&quot;&gt;Proton will never call you&lt;/a&gt; about an account security issue. You can protect your account from takeover by enabling &lt;a href=&quot;https://proton.me/support/two-factor-authentication-2fa&quot;&gt;two-factor authentication&lt;/a&gt;. On paid plans, &lt;a href=&quot;https://proton.me/support/proton-sentinel&quot;&gt;Proton Sentinel&lt;/a&gt; combines automated detection with human security analysis.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton Mail also includes protections against more conventional phishing attempts, such as &lt;a href=&quot;https://proton.me/blog/cloud-storage-email-scam&quot;&gt;cloud storage email scams&lt;/a&gt;. PhishGuard blocks and flags suspected phishing emails, while &lt;a href=&quot;https://proton.me/support/link-confirmation&quot;&gt;link confirmation&lt;/a&gt; prompts you to verify before opening external links from an email.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;No email service can provide perfect protection against &lt;a href=&quot;https://proton.me/business/blog/account-takeover-attacks&quot;&gt;account takeover&lt;/a&gt;. However, if someone does manage to break into your Proton account using email or SMS recovery, they won&amp;#8217;t automatically gain access to your emails and contacts, thanks to &lt;a href=&quot;https://proton.me/support/set-account-recovery-methods&quot;&gt;separate data recovery protections&lt;/a&gt;.&lt;/p&gt;
</content:encoded><category>News</category><author>Edward Komenda</author></item></channel></rss>