<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>The Proton Blog</title><description>News from the front lines of privacy and security</description><link>https://proton.me/</link><language>en</language><feed_url>https://proton.me/feed</feed_url><item><title>Hacker tech tools: What they do and how to stay safe</title><link>https://proton.me/blog/hacker-tech-tools</link><guid isPermaLink="true">https://proton.me/blog/hacker-tech-tools</guid><description>Learn how hacker tools such as malicious USB cables, keyloggers, and RFID readers can target systems and what you can do to stay safe.</description><pubDate>Tue, 29 Sep 2026 18:07:00 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;A hacker does not always need sophisticated malware or a complicated exploit. Sometimes the hardware is the trick.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;An ordinary looking USB cable can hide electronics. An HDMI device can capture what is on a screen. A small box can imitate a Wi-Fi network, while another can pretend to be a keyboard and send commands faster than a person could.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;These tools have legitimate uses in security testing and research. They also show why cybersecurity is not only about passwords and software. Physical access, wireless networks, and the devices we connect to our computers can create opportunities for an attacker.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Here are some of the tools that illustrate those risks, along with practical ways to reduce your exposure.&lt;/p&gt;



&lt;figure class=&quot;wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio&quot;&gt;&lt;div class=&quot;wp-block-embed__wrapper&quot;&gt;
&lt;iframe loading=&quot;lazy&quot; title=&quot;Real Hacker Tools (And How to Defend Yourself)&quot; width=&quot;750&quot; height=&quot;422&quot; src=&quot;https://www.youtube-nocookie.com/embed/gJaX5h92kbw?feature=oembed&quot; frameborder=&quot;0&quot; allow=&quot;accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share&quot; referrerpolicy=&quot;strict-origin-when-cross-origin&quot; allowfullscreen&gt;&lt;/iframe&gt;
&lt;/div&gt;&lt;/figure&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;O.MG cables can hide a second purpose&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;An O.MG Cable looks like an ordinary USB cable. Hidden inside, however, is hardware that gives it capabilities a normal cable does not have.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A modified cable can target a computer while the person using it thinks they have connected a normal accessory. However, a tiny Wi-Fi chip in the plug can receive a signal and activate the cable, after which it can present itself as a keyboard and send commands.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The hardware can also record what a person types and sends that information back to a bad actor over Wi-Fi. That could include passwords, messages, or other sensitive information. Security researchers have documented &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/usbharpoon-is-a-badusb-attack-with-a-twist&quot;&gt;similar attacks&lt;/a&gt; using seemingly ordinary USB charging cables.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The risk is easy to overlook because the cable looks familiar. You may borrow one at an airport, office, or hotel without thinking twice. A USB data blocker can allow power through for charging while blocking data transfer.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Fake Wi-Fi networks can look completely real&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The WiFi Pineapple is designed for wireless network auditing, but it also demonstrates a problem with &lt;a href=&quot;https://protonvpn.com/blog/public-wifi-safety&quot;&gt;public Wi-Fi&lt;/a&gt;: a network name does not prove that the network is trustworthy.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Imagine staying at a hotel called Proton Hotel and connecting to a network innocuously named “PROTON HOTEL GUEST WIFI.” The name looks convincing, so you connect. However, it could very well be that an attacker has created the network and designed it to resemble a legitimate one.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If your connection passes through infrastructure controlled by this attacker, they may be able to place themselves between you and the real network and attempt to observe or manipulate traffic that is not otherwise protected.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Treat unfamiliar networks with caution and use additional protection when connecting to them. A &lt;a href=&quot;https://protonvpn.com/blog/how-does-a-vpn-work&quot;&gt;VPN&lt;/a&gt; can help protect your traffic when the network itself cannot be trusted.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Hardware keyloggers record what you type&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A &lt;a href=&quot;https://protonvpn.com/blog/keylogger&quot;&gt;hardware keylogger&lt;/a&gt; can sit between a keyboard and a computer, recording keystrokes without requiring software to be installed.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The keyboard can continue working normally, which makes the device easy to overlook. If someone types a password, message, email, payment information, or anything else through the keyboard, a keylogger may be able to capture it.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;These devices are small enough to look like ordinary computer hardware. If you found one attached to the back of a computer, you might assume it was installed by IT.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Check what is physically connected to your computer from time to time. An unfamiliar adapter or device deserves a closer look.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Flipper Zero can test many wireless systems&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Flipper Zero is a portable multi-tool that can work with &lt;a href=&quot;https://www.wired.com/story/what-is-flipper-zero-tiktok&quot;&gt;several types of wireless technology&lt;/a&gt;. Depending on the system, it can read, store, clone, or emulate signals used by RFID and NFC devices, infrared remotes, sub-GHz radios, and some Bluetooth devices. That makes it useful for security research. It also highlights how much older wireless technology can reveal.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Whether an attack works depends on the target. Newer car key fobs and access systems may use encryption and rolling codes designed to prevent replay or cloning. Older or poorly protected systems can be more exposed.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Replace outdated hardware where practical, especially when newer versions offer stronger security. Turning off Bluetooth when you are not using it can also reduce unnecessary wireless exposure.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;A USB Rubber Ducky can type for an attacker&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The USB Rubber Ducky looks like a normal USB drive, but a computer can recognize it as a keyboard. That lets it send a programmed sequence of keystrokes at high speed. To clarify, while a hardware keylogger records what you type, a Rubber Ducky can do the typing itself.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A device treated as a keyboard may be able to open a command window and execute actions with the privileges available to the logged-in user. Depending on the computer and payload, that could include &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/heres-a-list-of-29-different-types-of-usb-attacks&quot;&gt;downloading malicious software&lt;/a&gt; or accessing information stored on the machine.&lt;a href=&quot;https://www.bleepingcomputer.com/news/security/heres-a-list-of-29-different-types-of-usb-attacks/?utm_source=chatgpt.com&quot;&gt;&amp;nbsp;&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The attack can happen quickly, so an unknown USB device should never be treated as a free storage drive. If you find a mystery USB stick, leave it alone.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;HDMI capture devices can watch your screen&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A Screen Crab is designed to sit between a device and its display over HDMI. The display can continue working normally while a capture device records what is being shown. A computer might display emails, documents, financial information, or passwords. A meeting room could show confidential presentations or internal documents.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Check the connections behind your computer, monitor, and shared AV equipment. An unfamiliar HDMI adapter deserves attention. In higher-security environments, physical port locks and tamper seals can make unauthorized devices harder to insert unnoticed.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;RFID tools can target older access systems&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Many offices, hotels, and other buildings use RFID or NFC cards and key fobs for access. RFID readers and writers can examine certain cards and tags and, with older or weaker systems, may potentially copy information needed to imitate them.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That does not mean every access badge can simply be copied. RFID covers many technologies, and newer systems can include protections designed to prevent this type of attack.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;An RFID-blocking sleeve or wallet can prevent a compatible card from being read while stored. It also helps to avoid leaving an access badge unattended or visible when it is not being used.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;The Bash Bunny can impersonate USB devices&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The Bash Bunny can be configured to present itself to a computer as &lt;a href=&quot;https://www.sciencedirect.com/science/article/pii/S0167404817301578&quot;&gt;different types of USB hardware&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A computer has to determine what a connected device actually is. You may think you have plugged in a flash drive, keyboard, or cable, but the computer identifies the device based on what it reports itself to be. That is the weakness these devices can exploit. A configured Bash Bunny can behave differently depending on the target and intended task.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The simplest defense remains one of the most effective: do not connect unfamiliar USB devices to your computer. A device that looks harmless can behave very differently from what its appearance suggests.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;The simplest security advice still matters&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The tools in this list vary widely. Some are designed for security testing, while others can be used in attacks. What they have in common is that they take advantage of trust in a cable, USB device, Wi-Fi network, badge, or connection that looks ordinary.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You cannot eliminate every physical or wireless risk. You can, however, make it harder for an attacker to take advantage of the things your devices are designed to trust.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Sometimes that starts with a simple question: Do you actually know what you just plugged in?&lt;/p&gt;
</content:encoded><category>Videos</category><author>Proton Team</author></item><item><title>How to communicate a security incident to your team, customers, and regulators</title><link>https://proton.me/business/blog/security-incident-communication</link><guid isPermaLink="true">https://proton.me/business/blog/security-incident-communication</guid><description>Learn how to communicate a security incident to employees, customers, and regulators without losing trust or creating compliance risk.</description><pubDate>Tue, 29 Sep 2026 12:44:05 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;In the first hours of a security incident, you can’t complete a technical picture of what happened. Your team may still be trying to understand which account was compromised, what data was accessed, how far the attacker got, or whether the incident is still active.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Alongside your investigation, the pressure to act starts immediately. Employees hear fragments and need to know what to do. Meanwhile, customers may notice service disruption, suspicious activity, or unusual password reset requests. Business partners may ask whether their systems or data are involved, and leadership needs to decide who speaks, what can be confirmed, and when silence becomes a risk of its own.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Security incident communication is difficult because a business has to be transparent before it has every answer, but informed enough not to guess. Communications sent too early can create confusion, but if they’re sent too late they can damage trust, slow down protective action, and raise regulatory questions.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It’s unlikely that &lt;a href=&quot;https://proton.me/business/pass/for-small-business&quot;&gt;small and mid-sized businesses&lt;/a&gt; have created or rehearsed their &lt;a href=&quot;https://proton.me/business/blog/incident-response&quot;&gt;incident response plan&lt;/a&gt;, and this can cause additional chaos. Even for larger businesses with a plan, the technical steps may be documented: contain the incident, reset access, preserve evidence, restore systems. Communication may be left for later, until suddenly the incident escalates or changes.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Part of preparing for an incident means knowing who needs to hear from you, what they need to know, who approves the message, and how to communicate facts clearly while the investigation is still moving.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#communication-planning&quot;&gt;Communication planning belongs inside incident response&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#two-track&quot;&gt;The two-track structure for your response&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#audience-not-announcement&quot;&gt;Start with the audience, not the announcement&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#communicate-internally&quot;&gt;What to communicate internally&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#notify-customers&quot;&gt;How to notify customers of a breach&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#regulatory-agencies&quot;&gt;When to notify regulatory agencies&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#prepare-messages&quot;&gt;Prepare messages before you need them&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#proton-pass-business&quot;&gt;How Proton Pass for Business can help&lt;/a&gt;&lt;/p&gt;



&lt;h2 id=&quot;communication-planning&quot; class=&quot;wp-block-heading&quot;&gt;Communication planning belongs inside incident response&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Incident response is often described as a technical process, but a real incident quickly becomes cross-functional. &lt;a href=&quot;https://proton.me/business/pass/for-it-teams&quot;&gt;IT teams&lt;/a&gt; may contain the threat, but leadership, legal, customer support, HR, communications, and operations all need to know what is happening and what they are allowed to say.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The NCSC’s guidance on &lt;a href=&quot;https://www.ncsc.gov.uk/guidance/effective-communications-in-a-cyber-incident&quot;&gt;effective communications in a cyber incident&lt;/a&gt; — general best practice that applies well beyond the UK — makes this point clearly: organizations often prioritize technical response and push communication into the background, even though communication shapes how staff, customers, stakeholders, and the media perceive the organization during a crisis.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Not every incident needs a public statement. But the business should know in advance who decides what to communicate, who approves external messages, who speaks to customers, and who handles regulatory reporting.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A strong &lt;a href=&quot;https://proton.me/business/blog/data-breach-response-plan&quot;&gt;data breach response plan&lt;/a&gt; needs to include a communication layer. This should include practical details:&amp;nbsp;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Contact lists&lt;/li&gt;



&lt;li&gt;Draft templates&lt;/li&gt;



&lt;li&gt;Approval routes&lt;/li&gt;



&lt;li&gt;Legal review&lt;/li&gt;



&lt;li&gt;Customer support talking points&lt;/li&gt;



&lt;li&gt;Regulator notification responsibilities&lt;/li&gt;



&lt;li&gt;Records of what was sent, when, and to whom.&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 id=&quot;two-track&quot; class=&quot;wp-block-heading&quot;&gt;&amp;nbsp;The two-track structure for your response&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Incident response needs two tracks: technical response and communication response. They run parallel to each other and the incident lead/ response owner connects them both.&amp;nbsp;&lt;/p&gt;



&lt;figure class=&quot;wp-block-table&quot;&gt;&lt;table class=&quot;has-fixed-layout&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Left track: Technical response&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Right track: Communication response&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Contain the incident&lt;/td&gt;&lt;td&gt;Update the internal team&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Secure affected accounts&lt;/td&gt;&lt;td&gt;Notify affected customers or partners&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Preserve evidence&lt;/td&gt;&lt;td&gt;Assess regulator notification&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Restore systems&lt;/td&gt;&lt;td&gt;Keep messages consistent as facts change&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/figure&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This allows you to structure your response and ensure that collaboration continues as team members take on different tasks.&amp;nbsp;&lt;/p&gt;



&lt;h2 id=&quot;audience-not-announcement&quot; class=&quot;wp-block-heading&quot;&gt;Start with the audience, not the announcement&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Security incident communication fails when one message tries to serve everyone. Employees, customers, partners, and regulators need different levels of detail because they have different decisions to make.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Your internal team needs clarity first&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;They don&amp;#8217;t need every detail — especially while the investigation is ongoing — but they do need clarity on what&amp;#8217;s confirmed, what to do right now, and who&amp;#8217;s leading the response. That means knowing which systems or accounts to avoid, what action to take immediately, and which questions are still open.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Employees also need to know what not to do. For example:&amp;nbsp;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Do not discuss the incident publicly&lt;/li&gt;



&lt;li&gt;Do not reset credentials outside the approved process&lt;/li&gt;



&lt;li&gt;Do not contact customers with improvised explanations&lt;/li&gt;



&lt;li&gt;Do not forward suspicious messages without guidance.&lt;/li&gt;
&lt;/ul&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Customers and partners need to know how they’re affected&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;They want to know whether their data, access, payments, service, or operations are affected. A good customer notification should explain:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;What is known&lt;/li&gt;



&lt;li&gt;What type of data may be involved&lt;/li&gt;



&lt;li&gt;What the business is doing&lt;/li&gt;



&lt;li&gt;What customers should do now, if anything&lt;/li&gt;



&lt;li&gt;Where they can get updates. &lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The tone should be plain and direct. A customer also doesn’t need forensic detail, they&amp;nbsp; only need enough information to protect themselves.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Regulators need a factual record&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A GDPR breach notification to the relevant supervisory authority (the &lt;a href=&quot;https://ico.org.uk/for-organisations/report-a-breach/&quot;&gt;ICO&lt;/a&gt; in the UK, the national data protection authority in each EU member state) is not a marketing message or a customer reassurance note. Instead, it needs to be a factual record of what happened, who is affected, and what you&amp;#8217;re doing about it. We cover exactly what to include in the section on notifying regulators below.&lt;/p&gt;



&lt;h2 id=&quot;communicate-internally&quot; class=&quot;wp-block-heading&quot;&gt;What to communicate internally&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Your employees are part of the response, even when they aren’t on the incident team. A confused team can accidentally create more noise, share inaccurate information, or slow down containment. On the other hand, a well-informed team can help protect accounts, direct customers to the right channel, and avoid speculation growing.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;An internal security incident announcement should cover:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;A clear summary of what has been confirmed so far, in plain language&lt;/li&gt;



&lt;li&gt;Which systems, accounts, teams, or data are potentially affected&lt;/li&gt;



&lt;li&gt;What the business is doing now&lt;/li&gt;



&lt;li&gt;What employees should do immediately&lt;/li&gt;



&lt;li&gt;Who is allowed to communicate externally&lt;/li&gt;



&lt;li&gt;Where updates will be posted&lt;/li&gt;



&lt;li&gt;How to report related suspicious activity&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;There are aspects that shouldn’t be included: attack vectors, root cause analysis, and specific vulnerabilities are generally not shared internally while an incident is live, and often not afterwards either, since those details can help other attackers, create legal exposure, or expose gaps that have not yet been closed.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The first internal message doesn’t need to answer every question, it needs to create order. For example, employees may need to reset passwords only through an approved process, avoid using a specific system, preserve suspicious emails, or stop using shared credentials until the response team finishes review.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Assessing your existing access controls against &lt;a href=&quot;https://proton.me/business/pass/password-management-best-practices&quot;&gt;best practices for password management&lt;/a&gt; is also essential. During an incident, outdated or informal credential sharing can make it harder to understand what was exposed.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton’s guides to &lt;a href=&quot;https://proton.me/blog/data-breach-prevention-for-businesses&quot;&gt;&lt;/a&gt;&lt;a href=&quot;https://proton.me/business/pass/data-breach-protection&quot;&gt;data breach protection&lt;/a&gt; &lt;a href=&quot;https://proton.me/blog/data-breach-prevention-for-businesses&quot;&gt;and data breach prevention for businesses&lt;/a&gt; explains how layered controls reduce exposure before a breach occurs. Secure &lt;a href=&quot;https://proton.me/business/pass/credential-management&quot;&gt;credential management&lt;/a&gt; is one of those layers because it helps the business know which accounts exist, who can access them, and what needs to be changed quickly.&lt;/p&gt;



&lt;h2 id=&quot;notify-customers&quot; class=&quot;wp-block-heading&quot;&gt;How to notify customers of a breach&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A data breach notification to customers is harder because it carries reputational and legal weight. People may be worried about identity theft, account takeover, financial fraud, or exposure of private information. They may also be frustrated that the company did not prevent the incident.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A good customer message should be honest without being alarming. It should avoid technical jargon, but be clear. Customers need to understand what data was involved, what risk that creates, and what they should do next.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A useful structure is:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;What happened, at a level of detail appropriate for customers&lt;/li&gt;



&lt;li&gt;When the business became aware&lt;/li&gt;



&lt;li&gt;What information or services may be affected&lt;/li&gt;



&lt;li&gt;What steps the business has taken&lt;/li&gt;



&lt;li&gt;What customers should do now&lt;/li&gt;



&lt;li&gt;How the business will provide updates&lt;/li&gt;



&lt;li&gt;Who customers can contact with questions&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Where the investigation is still active, this should be disclosed. Accuracy and transparency help restore trust. Being open about impact doesn’t require disclosing technical detail that would help someone repeat the attack.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For serious incidents, customers may need practical instructions: change a password, enable MFA, watch for &lt;a href=&quot;https://proton.me/business/mail/phishing-email&quot;&gt;phishing emails&lt;/a&gt;, contact their bank, and ignore messages claiming to be from the company unless they come through an official channel. The notification should make those steps easy to understand.&lt;/p&gt;



&lt;h2 id=&quot;regulatory-agencies&quot; class=&quot;wp-block-heading&quot;&gt;When and how to notify regulatory agencies&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Not every security incident needs to be reported to the supervisory authorities. A reportable breach under UK and EU GDPR depends on whether a personal data breach is likely to result in a risk to people’s rights and freedoms.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The ICO’s &lt;a href=&quot;https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach/personal-data-breaches-a-guide/&quot;&gt;personal data breach guidance&lt;/a&gt; reflects a requirement common to both UK and EU GDPR:&amp;nbsp; organizations must report a notifiable breach without undue delay and no later than 72 hours after becoming aware of it. A late report needs reasons for the delay.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That 72-hour window can create pressure, especially when the investigation is still incomplete. The GDPR recognizes that organizations may not have every detail within the first 72 hours, so information can be provided in phases, as long as further updates are given without undue delay.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A notification to the relevant supervisory authority (the ICO in the UK, or the national data protection authority in the EU) should usually include:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;The nature of the personal data breach&lt;/li&gt;



&lt;li&gt;The categories and approximate number of individuals affected&lt;/li&gt;



&lt;li&gt;The categories and approximate number of personal data records affected&lt;/li&gt;



&lt;li&gt;The name and contact details of the DPO or another contact point&lt;/li&gt;



&lt;li&gt;The likely consequences of the breach&lt;/li&gt;



&lt;li&gt;The measures taken or proposed to address it&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The ICO also provides a central page to &lt;a href=&quot;https://ico.org.uk/for-organisations/report-a-breach/&quot;&gt;report a breach&lt;/a&gt; and route organizations to the appropriate reporting process.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For affected individuals, the threshold is different. Where a personal data breach is likely to result in a high risk to people’s rights and freedoms, they must be informed without undue delay. This is a situation in which legal, privacy, and leadership teams should be involved early, even in a small business.&lt;/p&gt;



&lt;h2 id=&quot;prepare-messages&quot; class=&quot;wp-block-heading&quot;&gt;Prepare messages before you need them&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The worst time to design a communication process is during an incident. It’s not helpful to issue statements or guidance that need to be updated and changed.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That is why it’s helpful to prepare the structure of your messages before you need them. Not the final wording, because every incident will be different, but the structure: who needs to approve the message, which details must be included, where updates will be recorded, and who is responsible for each audience.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A simple communication kit is enough to make the first hour less chaotic. It can include:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;An internal incident announcement template&lt;/li&gt;



&lt;li&gt;A customer notification template&lt;/li&gt;



&lt;li&gt;A partner or vendor update template&lt;/li&gt;



&lt;li&gt;Customer support talking points&lt;/li&gt;



&lt;li&gt;Supervisory authority notification checklist&lt;/li&gt;



&lt;li&gt;Approved spokesperson list&lt;/li&gt;



&lt;li&gt;Escalation contacts for legal, IT, privacy, leadership, and communications&lt;/li&gt;



&lt;li&gt;A place to record all updates and decisions&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Preparation gives a team a safe starting point when speed and accuracy are both important. A prepared template leaves more attention for the facts of the incident: what happened, who is affected, what has already been done, and what people need to do next.&lt;/p&gt;



&lt;h2 id=&quot;proton-pass-business&quot; class=&quot;wp-block-heading&quot;&gt;How Proton Pass for Business can help&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Security incident communication depends on facts. The more clearly a business manages access before an incident, the easier it is to explain what happened, what may be affected, and what has been changed.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt; like Proton Pass for Business helps teams reduce credential-related exposure. Employees can generate strong passwords, store them in encrypted &lt;a href=&quot;https://proton.me/business/pass/password-vault&quot;&gt;password vaults&lt;/a&gt;, use autofill, &lt;a href=&quot;https://proton.me/pass/password-sharing&quot;&gt;share credentials securely&lt;/a&gt;, manage &lt;a href=&quot;https://proton.me/pass/passkeys&quot;&gt;passkeys&lt;/a&gt;, and use built-in two-factor authentication. Admins can apply &lt;a href=&quot;https://proton.me/business/pass/password-policy&quot;&gt;password policies&lt;/a&gt;, review activity logs, manage access with role-based controls, and support provisioning through &lt;a href=&quot;https://proton.me/business/pass/integrations&quot;&gt;SCIM and SSO integrations&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;During an incident, these features can help businesses act with more confidence. If an employee account is compromised, admins can review access, identify shared credentials that may need rotation, enforce stronger authentication, and reduce reliance on passwords copied through chat or spreadsheets.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Be ready to respond before a breach happens with a &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt;.&lt;/p&gt;
</content:encoded><category>For business</category><author>Ben Wolford</author></item><item><title>Your OSINT business security strategy: how attackers research companies</title><link>https://proton.me/business/blog/osint-business-security</link><guid isPermaLink="true">https://proton.me/business/blog/osint-business-security</guid><description>Learn how attackers use public information to research your business before targeted attacks, and how to reduce credential and data exposure.</description><pubDate>Tue, 29 Sep 2026 12:09:55 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;A targeted attack often begins with a search. Hackers look for information like an employee&amp;#8217;s job title, a hiring post that names your business tools, an exposed email address, or an old subdomain. In isolation, these details don’t seem dangerous. But attackers purposefully collect many small clues and pieces of information to build a &lt;a href=&quot;https://proton.me/business/mail/phishing-email&quot;&gt;phishing email campaign&lt;/a&gt;, fake login page, or impersonation call that feels believable.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Open source intelligence (OSINT) turns public information into preparation for a more targeted attack. Your OSINT business security strategy is how your business protects itself. For businesses, the challenge is twofold: auditing what is already out there and knowing what exists in the first place, then judging which public details help customers, candidates, and partners, and which ones quietly help attackers map your people, tools, credentials, and access points.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What OSINT means in cybersecurity&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In a cybersecurity context, OSINT is the use of publicly available information to identify possible attack paths. The information may come from search engines, social media, company websites, job boards, public code repositories, and other sources that do not require breaking into a system.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Attackers use OSINT to answer practical questions about a business, like:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Who works here? &lt;/li&gt;



&lt;li&gt;Who approves payments? &lt;/li&gt;



&lt;li&gt;What tools does the company use? &lt;/li&gt;



&lt;li&gt;What does the email format look like? &lt;/li&gt;



&lt;li&gt;Which suppliers or customers might be trusted? &lt;/li&gt;



&lt;li&gt;Which accounts may already be exposed? &lt;/li&gt;



&lt;li&gt;Which systems face the internet?&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;OSINT gives hackers details that make their attacks believable. A generic scam simply asks for action, but a researched scam is targeted at a specific person, sent from a person they know or have reason to trust, and mentions a real work project or non-public information.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The UK’s &lt;a href=&quot;https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2024&quot;&gt;Cyber Security Breaches Survey 2024&lt;/a&gt;⁠ found that half of UK businesses reported identifying a cyber security breach or attack in the previous 12 months. &lt;a href=&quot;https://proton.me/blog/what-is-phishing&quot;&gt;Phishing&lt;/a&gt; remained the most common type of breach or attack among affected businesses. OSINT isn’t the same as phishing, but it is an asset hackers can use to make phishing more convincing and harder for employees to dismiss.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What attackers can learn about your business&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Hackers use a variety of different methods to collect information. Here are some of the most common and effective paths.&amp;nbsp;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;People&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;LinkedIn, company bio pages, conference agendas, podcasts, webinars, and press mentions can reveal names, job titles, reporting lines, seniority, locations, and areas of responsibility. That helps attackers choose who to impersonate and who to pressure.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For example, an attacker who knows a CFO’s name, the company’s email format, and the finance team’s current software can build a message that feels much less generic than ordinary spam. The request may mention a real supplier, refer to a payment process that exists inside the business, or arrive at a moment when the team is already expecting invoice-related communication. None of this information requires access to a private system.&amp;nbsp;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Tools&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Job listings often mention the platforms candidates are expected to know: CRMs, payroll tools, helpdesk software, analytics platforms, collaboration tools, and developer environments. Public reviews, case studies, integrations, and employee profiles can reveal even more.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Tool exposure helps attackers tailor their phishing pretext. A phishing email that says “your account has been flagged” isn’t convincing, but a message that names the exact CRM, HR system, or collaboration tool the team uses is.&amp;nbsp;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Technical footprint&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Subdomains, exposed services, certificate records, old staging environments, and misconfigured login pages can reveal where a business has online systems. Attackers may also look for public repositories that include old credentials, API keys, internal URLs, or configuration files accidentally committed during development.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Breach data&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Email addresses, usernames, passwords, phone numbers, and other personal or business details exposed in previous breaches can become raw material for a later attack. Proton’s &lt;a href=&quot;https://proton.me/business/pass/breach-observatory&quot;&gt;Data Breach Observatory&lt;/a&gt;⁠ shows how leaked data can continue to create risk after the original incident, especially when credentials, contact details, and employee information can be linked back to a business.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How OSINT powers targeted attacks&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;OSINT becomes dangerous when attackers use collected data to build a believable story. Consider a business that publishes staff profiles, lists customer logos, mentions a recent CRM migration in job ads, and uses a predictable email format. A finance employee then receives a message that appears to come from a senior leader, references a real supplier, and asks for urgent payment support. The email only needs to contain enough familiar details to lower suspicion.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The same pattern applies to credential attacks. An attacker finds an employee’s business email in breach data, sees on LinkedIn that the person works in operations, and learns from job listings that the company uses a specific SaaS platform. The next phishing message can imitate that platform and arrive with language that matches the employee’s role.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Phone scams can be shaped by OSINT too. A caller who knows the company’s IT provider, the name of a department head, or the timing of a project sounds legitimate. This is why OSINT and &lt;a href=&quot;https://proton.me/blog/what-is-social-engineering&quot;&gt;social engineering&lt;/a&gt; are intertwined: public information gives attackers the confidence and detail needed to manipulate people in real time.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The business may experience the final attack as &lt;a href=&quot;https://proton.me/business/blog/phishing-attacks&quot;&gt;phishing&lt;/a&gt;, &lt;a href=&quot;https://proton.me/business/blog/vishing-attacks-business&quot;&gt;vishing&lt;/a&gt;, &lt;a href=&quot;https://proton.me/business/blog/account-takeover-attacks&quot;&gt;account takeover&lt;/a&gt;, invoice fraud, or credential theft. The groundwork may have been OSINT all along.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Leaked credentials are OSINT too&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Breach data is often discussed as a direct account takeover risk: when a password leaks, attackers can try it across multiple entry points. That is still a serious problem, especially when employees reuse passwords across services.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;But leaked credentials can also help attackers understand the business behind the account. An exposed email address may confirm which services an employee has used, while old passwords, phone numbers, and repeated company domains can add context for future phishing, vishing, or account takeover attempts. The breach may have happened somewhere else, but the information can still help an attacker build a more accurate picture of your team.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton’s &lt;a href=&quot;https://proton.me/blog/data-breach-observatory-2026&quot;&gt;Data Breach Observatory&lt;/a&gt; highlights how exposed data can support phishing, credential attacks, and broader social engineering. It also highlights that leaked data does not stop being useful to attackers after the first breach is reported. That data can be reused, combined, and reshaped for future targeting.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Monitoring exposed business emails and credentials helps organizations see more than the password that needs to be changed. It can reveal where employees have used work addresses, which services may be connected to the business, and whether the same identity appears across multiple leaks.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is essential because attackers can reuse information, not only to try old passwords, but to make future phishing, vishing, or impersonation attempts feel more specific. A leaked credential is rarely just an isolated credential. It can become part of the background research that makes the next attack more effective.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Reduce what attackers can learn from public sources&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;No business can remove itself from public view, and that should not be anyone’s aim. Customers, candidates, and partners still need enough information to understand who you are and how to work with you.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The risk is in publishing details that go beyond that purpose: internal tool names, direct contact patterns, approval workflows, or technical clues that give attackers a sharper picture of how the business operates.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Start with your public-facing information.&lt;/strong&gt; Review company pages, team bios, press releases, case studies, help center articles, job listings, social media posts, and public documents. Look for details that reveal internal systems, approval processes, access routes, or sensitive workflows.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Job listings deserve special attention.&lt;/strong&gt; Candidates may need to know the broad categories of tools they will use, but public ads don’t always need to name every SaaS platform, security product, CRM, payment tool, cloud provider, or internal workflow. The more specific the tool list, the easier it becomes to craft a fake login prompt, support message, or vendor request.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Employee information also needs balance.&lt;/strong&gt; Seniority, role, and expertise may be appropriate to share, but direct phone numbers, personal details, travel patterns, internal project names, or unnecessary reporting structure details can give attackers more to work with.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Public code repositories should be reviewed regularly.&lt;/strong&gt; Old projects, test files, documentation, or configuration examples may contain secrets that were not meant to be public. Even when credentials have expired, internal URLs, naming conventions, and service references can still help attackers understand the environment.&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Reduce the value of what attackers find&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;OSINT will always exist because businesses need to be visible. The goal is to reduce the amount of unnecessary information available and limit what attackers can do with the details they find.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Public information is the first place to reduce unnecessary exposure. Job ads, company profiles, employee pages, repositories, subdomains, and old documents should give people enough context to trust and understand the business, not a detailed view of how it operates behind the scenes. When internal tool names, technical clues, or process details are not needed publicly, they are better kept out of view.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Credential controls are just as important. Exposed email addresses and leaked passwords are some of the easiest OSINT signals to turn into action. Unique passwords, &lt;a href=&quot;https://proton.me/business/blog/multi-factor-authentication-business&quot;&gt;MFA&lt;/a&gt;, passkeys, &lt;a href=&quot;https://proton.me/pass/password-sharing&quot;&gt;secure sharing&lt;/a&gt;, breach monitoring, and controlled access all make reconnaissance less useful.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Review your technical footprint without publishing a roadmap&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Technical exposure is part of OSINT, too. Domains, subdomains, login portals, cloud services, development environments, API endpoints, and public repositories can all help attackers understand how a business is structured online.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A regular review helps separate what is intentionally public from what has been published and forgotten. Old staging pages, unused subdomains, default service screens, outdated documentation, exposed configuration notes, and public repositories with internal references may not seem urgent, but they can make reconnaissance easier.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Many fixes are simple: remove old pages, restrict access, update documentation, rotate exposed secrets, or move internal details out of public repositories. Other findings may only need a clear owner and a reason to remain visible. Public exposure becomes a decision, rather than an omission.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Build OSINT checks into security routines&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;OSINT exposure isn’t static. It grows every time a business publishes something new, changes a workflow, hires for a role, launches a project, appears on a supplier page, or has employee data exposed in a breach. Each update seems harmless in isolation, but over time it can give attackers a clearer view of the company’s people, tools, relationships, and access points.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A simple set of checks and reviews can help:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Review public-facing business information quarterly&lt;/li&gt;



&lt;li&gt;Check job listings before publication for unnecessary tool or workflow details&lt;/li&gt;



&lt;li&gt;Monitor breach exposure for business email addresses&lt;/li&gt;



&lt;li&gt;Review public repositories and exposed services&lt;/li&gt;



&lt;li&gt;Ask department leads whether any public information reveals sensitive processes or access patterns.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Before information goes public, someone should always ask: could this help an attacker create a more convincing message, call, or login attempt?&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Make credentials harder to connect with aliases&amp;nbsp;&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/pass/aliases&quot;&gt;Email aliases&lt;/a&gt; can help reduce the amount of information attackers can connect across services. When the same email address is used for every service, it becomes easier to link accounts, search breach data, guess login portals, and build a profile of the employee or business.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For some business workflows, a standard email address is necessary. Employees need stable identities for work, customers, and collaboration. But aliases can be useful for signups, newsletters, trials, vendor testing, events, or services that don’t require a person’s primary business address.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Email aliases are useful because they separate accounts that attackers would otherwise connect to the same employee, team, or business address. They can also make exposure easier to trace. When an alias created for one vendor starts receiving unrelated login attempts or phishing messages, the business has a clearer signal of where that address may have been exposed.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Aliases work best when they are paired with a &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt; such as Proton Pass for Business. Each account still needs a unique password, controlled storage, and clear ownership. Without that structure, aliases can become another manual habit for employees to manage on their own.&amp;nbsp;&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Manage OSINT with Proton Pass for Business&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt; like Proton Pass for Business can help you monitor for breaches and protect your network with credential health features. With Proton Pass for Business⁠, teams can create unique passwords, store them in encrypted &lt;a href=&quot;https://proton.me/business/pass/password-vault&quot;&gt;password vaults&lt;/a&gt;, use autofill, share credentials securely, manage &lt;a href=&quot;https://proton.me/pass/passkeys&quot;&gt;passkeys&lt;/a&gt;, and use built-in &lt;a href=&quot;https://proton.me/blog/what-is-two-factor-authentication-2fa&quot;&gt;two-factor authentication&lt;/a&gt; (2FA).&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Admin features such as policies, reporting, logs, role-based access control, &lt;a href=&quot;https://proton.me/business/pass/integrations&quot;&gt;SCIM provisioning, and SSO integration&lt;/a&gt; help businesses keep credential access more controlled as they grow.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A business password manager doesn’t eliminate OSINT exposure, but it can make the information attackers find less useful. When credentials are unique, stored in encrypted vaults, shared through approved spaces, and protected with 2FA or passkeys, a leaked password or convincing fake login page has less room to turn into wider access. It also gives employees a clearer rule to follow: business credentials should stay inside the password manager, not in emails, chats, spreadsheets, or phone conversations.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Attackers will still research your business. The question is how much they can learn, how accurate that picture is, and how far they can go with it.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Reduce your business’s credential exposure with a &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt;⁠.&lt;/p&gt;
</content:encoded><category>For business</category><author>Kate Menzies</author></item><item><title>How the CLOUD Act gives the US access to foreign data</title><link>https://proton.me/business/blog/cloud-act</link><guid isPermaLink="true">https://proton.me/business/blog/cloud-act</guid><description>The CLOUD Act lets US authorities demand data from US-based cloud providers, wherever it&apos;s stored. Here&apos;s how it works.</description><pubDate>Mon, 28 Sep 2026 16:19:02 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;If your cloud provider is based in the US, a valid US court order can compel that company to retrieve your company&amp;#8217;s data on servers anywhere in the world.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Companies including Google, Microsoft, and Amazon are vulnerable to this intrusion, made possible by the CLOUD Act, a 2018 law that gives American law enforcement officials global tentacles.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It&amp;#8217;s especially a problem for EU businesses. If your US provider hands over your emails or files, that could constitute a violation of the &lt;a href=&quot;https://proton.me/business/gdpr&quot;&gt;GDPR&lt;/a&gt; for leaking personal data, which can impose penalties of up to €20 million or 4% of global annual revenue, whichever is higher.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That’s the reality that American companies obscure when they say &amp;#8220;GDPR-compliant&amp;#8221; and &amp;#8220;&lt;a href=&quot;https://proton.me/business/blog/tech-investment-not-cost&quot;&gt;European sovereign cloud&lt;/a&gt;&amp;#8221; in their marketing. A US provider&amp;#8217;s EU data center is still run by a company under US jurisdiction. For your business, this means that procurement decisions carry a compliance liability you may not have priced in. For your customers, it means the personal data they entrusted to you may end up in a legal process they have no say in (and may never even learn about).&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Here&amp;#8217;s a plain explanation of the CLOUD Act, why this invasive legislation matters for businesses, and how to limit your exposure. your data sits no longer decides who can reach it.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What is the CLOUD Act?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The Clarifying Lawful Overseas Use of Data Act (&lt;a href=&quot;https://www.congress.gov/bill/115th-congress/house-bill/4943&quot;&gt;&lt;u&gt;CLOUD Act&lt;/u&gt;&lt;/a&gt;) is a US federal law that came into force in 2018. It allows federal law enforcement — primarily the Department of Justice and FBI, but also federal, state, and local police — to obtain a warrant, court order, or subpoena compelling technology companies under US jurisdiction to hand over data, regardless of where in the world that data is physically stored.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For example, if the FBI obtains a warrant compelling Microsoft to hand over a European business&amp;#8217;s emails, Microsoft must comply — even if a European court disagrees with the request.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The CLOUD Act has a legitimate policing purpose. It&amp;#8217;s designed to help federal law enforcement to investigate serious crimes such as terrorism, child exploitation, and cybercrime. It&amp;#8217;s not designed for intelligence-gathering, which runs through a separate US authority (&lt;a href=&quot;https://proton.me/blog/us-warrantless-surveillance&quot;&gt;FISA Section 702&lt;/a&gt;), often confused with it.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That legitimate purpose doesn&amp;#8217;t, however, remove the structural problem for businesses: &lt;strong&gt;The CLOUD Act can put a US-jurisdiction provider in a position where fulfilling a lawful US order means breaching EU law.&lt;/strong&gt; It leaves businesses caught between two compliance regimes with no way to satisfy both.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What’s the origin of the CLOUD Act?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The CLOUD Act was passed in 2018 by the US government to amend the Stored Communications Act (SCA) of 1986. This amendment was, in large part, a response to &lt;a href=&quot;https://www.stanfordlawreview.org/online/microsoft-ireland-cloud-act-international-lawmaking-2-0/&quot;&gt;&lt;u&gt;an ongoing court case&lt;/u&gt;&lt;/a&gt;, the ‘Microsoft-Ireland’ case.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In 2013, Microsoft challenged a federal warrant demanding the emails of a customer under investigation for drug trafficking — emails stored by Microsoft on servers in Ireland. This case hinged on a thorny legal question: Could a US warrant issued under the SCA reach digital communications controlled by a US-based company, but stored on a data server outside the US?&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In 2018, the case was pending appeal in the Supreme Court when the US Congress passed the CLOUD Act. This both mooted the ‘Microsoft-Ireland’ case and resolved the question of the US government’s extraterritorial powers over data stored on foreign soil, at least on paper.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What powers does the CLOUD Act give the US government?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The CLOUD Act empowered the US government to request targeted data, wherever it was stored, by strengthening extraterritorial SCA orders to US providers. The Act clarified that US law enforcement can use warrants, subpoenas, and court orders to access electronically stored communications data located outside the US, if the storage provider is subject to US jurisdiction, and the requested data is relevant and material to an ongoing criminal investigation. &lt;strong&gt;A CLOUD Act request goes straight to the provider&lt;/strong&gt;, bypassing the much slower &lt;a href=&quot;https://www.gov.uk/guidance/mutual-legal-assistance-mla-requests&quot;&gt;&lt;u&gt;MLAT (Mutual Legal Assistance Treaty)&lt;/u&gt;&lt;/a&gt; process that the US government relied on previously.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The CLOUD Act also empowered governments who were willing to sign up to a bilateral executive agreement with the US government, which would let law enforcement in partner countries make direct, cross-border, case-specific requests for data from US-based service providers.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Executive agreements speed up evidence-gathering in serious criminal cases like terrorism and child exploitation, where the MLAT process could take months. At time of writing, only two executive agreements exist: between the US and the UK (entered into force &lt;a href=&quot;https://www.justice.gov/archives/opa/pr/landmark-us-uk-data-access-agreement-enters-force&quot;&gt;&lt;u&gt;in October 2022&lt;/u&gt;&lt;/a&gt;), and between the US and Australia (entered into force &lt;a href=&quot;https://www.justice.gov/archives/opa/pr/united-states-and-australia-enter-cloud-act-agreement-facilitate-investigations-serious-crime&quot;&gt;&lt;u&gt;January 2024&lt;/u&gt;&lt;/a&gt;). Negotiations between &lt;a href=&quot;https://techpost.bsa.org/2025/04/04/seven-years-of-the-cloud-act-how-its-modernizing-access-to-digital-evidence/&quot;&gt;&lt;u&gt;the US government and the EU and Canada&lt;/u&gt;&lt;/a&gt; have been initiated but are not yet concluded.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Tech providers do have one safety mechanism: They can challenge or ask to modify a US order under “comity” — the legal principle that courts defer to other jurisdictions&amp;#8217; laws — if complying would mean breaking a foreign law, particularly one covered by an executive agreement. Outside the UK and Australia, this common-law comity challenge is the only option on the table.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;However, as &lt;a href=&quot;https://epic.org/the-cloud-act/&quot;&gt;&lt;u&gt;The Electronic Privacy Information Center (EPIC) argues&lt;/u&gt;&lt;/a&gt;, even with comity, &lt;strong&gt;the CLOUD Act leaves customers, businesses included, with little real recourse&lt;/strong&gt;. Providers aren&amp;#8217;t required to notify a customer whose data was accessed, customers have no independent right to challenge a request (that depends entirely on the provider choosing to object), and executive agreements explicitly rule out creating any new remedy for the people affected.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;The CLOUD Act vs GDPR&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In Europe, where Proton’s own research shows &lt;a href=&quot;https://proton.me/business/blog/us-tech-risk-report-for-europe&quot;&gt;&lt;u&gt;over 74% of all publicly listed companies depend on US-based tech services&lt;/u&gt;&lt;/a&gt;, the CLOUD Act is of particular concern because it clashes with the EU’s General Data Protection Regulation (GDPR).&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Under &lt;a href=&quot;https://gdpr.eu/article-48-unauthorized-transfers-or-disclosures-of-personal-data/&quot;&gt;&lt;u&gt;Article 48&lt;/u&gt;&lt;/a&gt; of the GDPR, a foreign court order or decision of an administrative authority (including an SCA order) to transfer or disclose personal data will not be automatically recognized or enforced in the EU, unless made under an international agreement, such as an MLAT.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;While there hasn&amp;#8217;t been a case of GDPR fining a company in connection with a CLOUD Act order, there is precedent for &lt;strong&gt;&lt;/strong&gt;regulators acting on this category of risk: In 2023, Ireland&amp;#8217;s Data Protection Commission &lt;a href=&quot;https://www.dataprotection.ie/en/news-media/press-releases/DPC-announces-91-million-fine-of-Meta&quot;&gt;fined Meta a record €1.2 billion&lt;/a&gt; for EU-US transfers exposed to US surveillance law — specifically FISA Section 702, not the CLOUD Act.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For US-based cloud providers, this means that if the US government requests data that they process but that’s controlled by European businesses, to comply with the CLOUD Act might mean breaching GDPR.&amp;nbsp;Under &lt;a href=&quot;https://gdpr.eu/article-28-processor/&quot;&gt;Article 28&lt;/a&gt;, the provider (processor) may only act on the controller&amp;#8217;s documented instructions, and &amp;#8220;disclosing data to a foreign government&amp;#8221; isn&amp;#8217;t among those instructions.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The exposure isn&amp;#8217;t limited to the provider. If the provider discloses a customer&amp;#8217;s data in response to a compelled order without the international-agreement basis Article 48 requires (which, since no CLOUD Act executive agreement exists between the US and the EU at present, means an MLAT) &lt;strong&gt;the business that owns that data carries its own liability, not just the vendor it hired to store it&lt;/strong&gt;.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Why data location doesn’t mean data sovereignty&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In &lt;a href=&quot;https://www.theregister.com/off-prem/2025/07/25/microsoft-exec-admits-it-cannot-guarantee-data-sovereignty/458553&quot;&gt;&lt;u&gt;June 2025&lt;/u&gt;&lt;/a&gt;, Microsoft France&amp;#8217;s own director of public and legal affairs, Anton Carniaux, was asked under oath &lt;a href=&quot;https://www.senat.fr/actualite/commande-publique-audition-de-microsoft-5344.html&quot;&gt;&lt;u&gt;in the French Senate&lt;/u&gt;&lt;/a&gt; whether he could guarantee French citizens&amp;#8217; data would never be handed to US authorities without French consent.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;His answer: &amp;#8220;No. I cannot guarantee that.” He added that “it has never happened before”, which doesn’t, of course, mean it couldn’t happen in the future.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;The message was clear:&lt;/strong&gt; &lt;a href=&quot;https://proton.me/business/blog/data-sovereignty-for-european-businesses&quot;&gt;&lt;u&gt;&lt;strong&gt;Data sovereignty&lt;/strong&gt;&lt;/u&gt;&lt;/a&gt; &lt;strong&gt;is no longer about where data is stored, but who controls that data.&lt;/strong&gt; The location of your data servers and the governments which have authority over them are no longer necessarily the same thing.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This fact sits uncomfortably next to the “GDPR compliant” cloud offerings US cloud giants (or ‘hyperscalers’) are marketing to European businesses. These “European sovereign cloud” products are run by companies headquartered in the US, or controlled by a US parent company, and GDPR’s protections only extend as far as US law allows.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How zero-access encryption architecture mitigates exposure to the CLOUD Act&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If your cloud storage provider is subject to US jurisdiction and US law enforcement demands access to your data (with legitimate legal reasons), neither you nor your provider can stop it from happening. At this point, your data’s only defense is encryption.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Encryption makes data unreadable and unusable by cybercriminals and governments alike, scrambling it into ‘&lt;a href=&quot;https://proton.me/learn/encryption/glossary/what-is-ciphertext&quot;&gt;&lt;u&gt;cipher text&lt;/u&gt;&lt;/a&gt;’ that only someone with the right key can read.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;However, the encryption offered by most US cloud providers comes with a fatal caveat: They retain the decryption keys themselves.&lt;/strong&gt; That means they can read your data, or be compelled to hand over a readable copy to a third party such as US law enforcement.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For real protection against file and message data exposure, either to cybercriminals or governments, you need &lt;a href=&quot;https://proton.me/security/end-to-end-encryption&quot;&gt;end-to-end encryption&lt;/a&gt; or &lt;a href=&quot;https://proton.me/learn/encryption/types-of-encryption/zero-access&quot;&gt;&lt;u&gt;zero-access encryption&lt;/u&gt;&lt;/a&gt;, which prevents the provider from accessing the data.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A provider that uses zero-access encryption doesn&amp;#8217;t have the key to decrypt files it handles and stores on its servers. It may still be forced to disclose data when law enforcement demands it, even if data is stored in a jurisdiction that enforces a strict standard of data protection, &lt;a href=&quot;https://proton.me/blog/switzerland&quot;&gt;&lt;u&gt;such as Switzerland&lt;/u&gt;&lt;/a&gt;. But the files handed over would be encrypted and unreadable.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How Proton protects businesses from the CLOUD Act&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton is shielded from the CLOUD Act in two key ways:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Swiss jurisdiction&lt;/strong&gt;, which limits who can compel Proton to hand over data&lt;/li&gt;



&lt;li&gt;And &lt;strong&gt;strong encryption&lt;/strong&gt;, which limits what they can do with whatever Proton hands over&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton is headquartered in Geneva, Switzerland, outside of US jurisdiction and the reach of CLOUD Act orders. US authorities can&amp;#8217;t resort to a bilateral shortcut, either: Switzerland isn&amp;#8217;t party to any CLOUD Act executive agreement.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This doesn&amp;#8217;t remove legal process altogether. Switzerland has its own mutual legal assistance framework, which lets Swiss authorities cooperate with foreign investigations. But any request has to clear Swiss law first, under Swiss courts — it can&amp;#8217;t be a warrant served directly on the provider.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton&amp;#8217;s legal history shows that we&amp;#8217;re willing and able to challenge Swiss law. In 2020, &lt;a href=&quot;https://proton.me/blog/court-strengthens-email-privacy&quot;&gt;we challenged a Swiss data retention law&lt;/a&gt; that we believed to be an improper attempt to use telecommunications laws to undermine privacy. In 2021, the Federal Administrative Court ruled that email services aren&amp;#8217;t telecommunications providers, and therefore aren&amp;#8217;t subject to the law&amp;#8217;s retention requirements.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;And even a successful Swiss order has limits on what it can get. Proton&amp;#8217;s end-to-end and zero-access encryption means message content and files are unreadable to Proton itself, and there&amp;#8217;s no key to hand over, regardless of who&amp;#8217;s asking. The content of your emails, docs, files, and other data stays out of reach.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business&quot;&gt;&amp;lt;Explore Proton for Business&amp;gt;&lt;/a&gt;&lt;/p&gt;



&lt;div class=&quot;flex flex-wrap justify-center gap-2&quot;&gt;
  &lt;a class=&quot;btn inline-block rounded-full font-bold btn-small btn-solid-purple&quot; href=&quot;https://proton.me/business&quot;&gt;Try Proton for Business&lt;/a&gt;
&lt;/div&gt;



&lt;hr class=&quot;wp-block-separator has-alpha-channel-opacity&quot;/&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Frequently asked questions about the CLOUD Act&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Does the CLOUD Act override GDPR?&lt;/strong&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The CLOUD Act doesn’t override GDPR, but it does conflict with it. A CLOUD Act order can put a US provider in a position where complying breaches GDPR Article 48 (no automatic recognition of a foreign order without an international agreement). Neither law defers to the other, and the provider — and any European company they serve — is caught between them.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Is the CLOUD Act only for US companies?&lt;/strong&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The CLOUD Act doesn’t only apply to businesses headquartered in the US, or controlled by a US parent company. It also reaches any provider with sufficient US legal presence or business nexus. A US subsidiary, US-based staff or offices, or businesses purposefully directed at US customers can be enough to bring an organization headquartered outside the US within reach of the CLOUD Act.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Can I refuse a CLOUD Act request?&lt;/strong&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The customer (controller) generally isn&amp;#8217;t the one served — the provider is. The provider can raise a comity challenge if complying breaks foreign law, or push back if a request is legally deficient. But if legal remedies are exhausted and the order remains valid, a provider would be forced to comply.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;What&amp;#8217;s the difference between the CLOUD Act and an MLAT?&lt;/strong&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When digital evidence is requested via a Mutual Legal Assistance Treaty (MLAT), this request is judicially reviewed, a thorough and slow process. The executive agreements enabled by the CLOUD Act let law enforcement bypass the MLAT process if requesting data from a partner country. So far, only the UK and Australia have executive agreements with the US. &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Does encryption stop CLOUD Act requests?&lt;/strong&gt; &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Encryption doesn’t stop a legal order, but if a provider stores customer data with end-to-end encryption or zero-access encryption then they will not have any readable data to give to the authorities because they don&amp;#8217;t have the decryption keys. They would thus hand over only encrypted files.&lt;/p&gt;
</content:encoded><category>For business</category><author>Ben Wolford</author></item><item><title>Survey: People don&amp;#8217;t trust AI, but they tell it everything</title><link>https://proton.me/blog/ai-chatbot-survey</link><guid isPermaLink="true">https://proton.me/blog/ai-chatbot-survey</guid><description>New research finds that most AI chatbot users have shared something sensitive, but few trust the companies behind them.</description><pubDate>Thu, 24 Sep 2026 11:55:56 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Money worries at 2 a.m.. A medical symptom too embarrassing to see a doctor about. The best way to ask someone on a date.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;People discuss their most private thoughts with AI chatbots. But their revelations to the apps doesn&amp;#8217;t mean they trust the Big Tech companies behind them, according to new research from Proton.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Roughly two-thirds of AI chatbot users have discussed at least one sensitive topic. But at the same time, fewer than one in five say they have a high level of trust in AI companies to protect their private information.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;“AI is learning far more about us than a search engine ever could. Search knows what you looked for. AI gets the hesitation, the follow-up questions, and the personal context between the lines,” said Eamonn Maguire, director of AI engineering at Proton. “We’re handing over more than questions now. And when technology knows that much about us, privacy can’t be an afterthought.”&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;To understand more about how people use and perceive AI, we surveyed 4,014 current AI chatbot users across France, Germany, the UK, and the US. We asked what they&amp;#8217;ve shared, why they chose to do so, and what would make them more or less willing to share it.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Key findings&lt;/h2&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;66% of AI chatbot users have discussed at least one sensitive topic with a chatbot, including personal finances, sexual health, and relationships.&lt;/li&gt;



&lt;li&gt;42% of users have little or no trust in AI companies to protect sensitive information shared with chatbots.&lt;/li&gt;



&lt;li&gt;Money, mental health, and career problems are the three most commonly discussed sensitive topics.&lt;/li&gt;



&lt;li&gt;AI users would still rather discuss sensitive topics with friends and family, ahead of AI chatbots and therapists.&lt;/li&gt;



&lt;li&gt;Convenience and freedom from judgment are the most commonly cited reasons for choosing AI over a person.&lt;/li&gt;



&lt;li&gt;48% of users say they would be more willing to share sensitive information if their conversations were guaranteed to not be used to train AI models.&lt;/li&gt;



&lt;li&gt;Eight in 10 users express interest in an AI chatbot specifically designed for privacy.&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Most chatbot users have already shared something sensitive&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;66% of respondents said they discussed at least one sensitive topic with an AI chatbot. The eight topics covered personal finances, relationships, mental health, sex, secrets, romantic attraction, work, and family conflict.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Of the surveyed countries, Americans reported the highest rate of disclosing sensitive information to chatbots at 68.4%, with France being the lowest at 60.3%. This gap suggests openness to confiding in AI isn&amp;#8217;t just a personal choice, but could be influenced by broader cultural attitudes toward privacy and technology.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Money, mental health, and work dominate sensitive topics&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Personal finances, mental health, and career problems were the three sensitive topics respondents most commonly reported discussing with AI.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The most commonly discussed topic varied by country. Mental health ranked first in Germany, while career problems ranked first in the US, and personal finances ranked first in France and the UK.&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img width=&quot;1024&quot; height=&quot;730&quot; data-public-id=&quot;wp-pme/20260819_infographics_1-3/20260819_infographics_1-3.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_730,c_scale/f_auto,q_auto/v1787827171/wp-pme/20260819_infographics_1-3/20260819_infographics_1-3.png?_i=AA&quot; alt=&quot;&quot; class=&quot;wp-post-276815 wp-image-277012&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;73 KB&quot; data-optsize=&quot;15 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;78.9&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=277012&quot; data-version=&quot;1787827171&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_730,c_scale/f_auto,q_auto/v1787827171/wp-pme/20260819_infographics_1-3/20260819_infographics_1-3.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_214,c_scale/f_auto,q_auto/v1787827171/wp-pme/20260819_infographics_1-3/20260819_infographics_1-3.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_547,c_scale/f_auto,q_auto/v1787827171/wp-pme/20260819_infographics_1-3/20260819_infographics_1-3.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_1094,c_scale/f_auto,q_auto/v1787827171/wp-pme/20260819_infographics_1-3/20260819_infographics_1-3.png?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_2048,h_1459,c_scale/f_auto,q_auto/v1787827171/wp-pme/20260819_infographics_1-3/20260819_infographics_1-3.png?_i=AA 2048w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_1117,c_scale/f_auto,q_auto/v1787827171/wp-pme/20260819_infographics_1-3/20260819_infographics_1-3.png?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;/figure&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;These results show which sensitive topics respondents have discussed with AI, but not &lt;em&gt;why&lt;/em&gt; they chose to discuss them.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Friends and family are the top choice, even as AI use grows&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Friends and family were the preferred choice for discussing every sensitive topic surveyed, ahead of AI chatbots, therapists, and religious advisors. But AI is already competing with traditional sources of support in some areas — particularly money and work.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The gap between AI and human advice is smallest when it comes to money. In France, AI came within just 2 percentage points of friends and family as the preferred choice for discussing personal finances.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;And AI’s influence doesn’t stop at conversation. People are using it to make decisions about their money, health, relationships, careers, and purchases.&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img width=&quot;1024&quot; height=&quot;998&quot; data-public-id=&quot;wp-pme/20260819_infographics_8-1/20260819_infographics_8-1.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_998,c_scale/f_auto,q_auto/v1787827182/wp-pme/20260819_infographics_8-1/20260819_infographics_8-1.png?_i=AA&quot; alt=&quot;&quot; class=&quot;wp-post-276815 wp-image-276840&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;2 MB&quot; data-optsize=&quot;170 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;91.8&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=276840&quot; data-version=&quot;1787827182&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_998,c_scale/f_auto,q_auto/v1787827182/wp-pme/20260819_infographics_8-1/20260819_infographics_8-1.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_293,c_scale/f_auto,q_auto/v1787827182/wp-pme/20260819_infographics_8-1/20260819_infographics_8-1.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_749,c_scale/f_auto,q_auto/v1787827182/wp-pme/20260819_infographics_8-1/20260819_infographics_8-1.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_1498,c_scale/f_auto,q_auto/v1787827182/wp-pme/20260819_infographics_8-1/20260819_infographics_8-1.png?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_2048,h_1997,c_scale/f_auto,q_auto/v1787827182/wp-pme/20260819_infographics_8-1/20260819_infographics_8-1.png?_i=AA 2048w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_1529,c_scale/f_auto,q_auto/v1787827182/wp-pme/20260819_infographics_8-1/20260819_infographics_8-1.png?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;/figure&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Convenience and freedom from judgment are biggest draws for using AI&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Convenience and freedom from judgment were the most commonly cited reasons for choosing an AI chatbot over a person to discuss a sensitive topic. Privacy was also a common reason, but ranked lower.&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img width=&quot;1024&quot; height=&quot;552&quot; data-public-id=&quot;wp-pme/20260819_infographics_4/20260819_infographics_4.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_552,c_scale/f_auto,q_auto/v1787827163/wp-pme/20260819_infographics_4/20260819_infographics_4.png?_i=AA&quot; alt=&quot;&quot; class=&quot;wp-post-276815 wp-image-277036&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;66 KB&quot; data-optsize=&quot;16 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;75.6&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=277036&quot; data-version=&quot;1787827163&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_552,c_scale/f_auto,q_auto/v1787827163/wp-pme/20260819_infographics_4/20260819_infographics_4.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_162,c_scale/f_auto,q_auto/v1787827163/wp-pme/20260819_infographics_4/20260819_infographics_4.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_414,c_scale/f_auto,q_auto/v1787827163/wp-pme/20260819_infographics_4/20260819_infographics_4.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_828,c_scale/f_auto,q_auto/v1787827163/wp-pme/20260819_infographics_4/20260819_infographics_4.png?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_2048,h_1104,c_scale/f_auto,q_auto/v1787827163/wp-pme/20260819_infographics_4/20260819_infographics_4.png?_i=AA 2048w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_845,c_scale/f_auto,q_auto/v1787827163/wp-pme/20260819_infographics_4/20260819_infographics_4.png?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;/figure&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Reasons generally varied by country and topic. Of the top three most-discussed sensitive topics, work and career problems was the only one where all four countries agreed on the same top reason: convenience. Personal finances came close, with every country except the UK favoring convenience too. Mental health was split down the middle: France and Germany both chose convenience as the top reason, while the US and UK valued freedom from judgment more highly. Meanwhile, romantic attraction had trust and privacy as the top choice across Germany, the UK, and the US, while sexual health had judgment-free as the top reason across France, the US, and the UK.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Together, this suggests convenience wins out for practical topics, while privacy and freedom from judgment matter more for personal conversations.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Ad profiling raises more concern than AI model training&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Respondents expressed more concern about their conversations being used for advertising profiles than being used to train AI models.&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img width=&quot;1024&quot; height=&quot;565&quot; data-public-id=&quot;wp-pme/20260819_infographics_5/20260819_infographics_5.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_565,c_scale/f_auto,q_auto/v1787827152/wp-pme/20260819_infographics_5/20260819_infographics_5.png?_i=AA&quot; alt=&quot;&quot; class=&quot;wp-post-276815 wp-image-277060&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;75 KB&quot; data-optsize=&quot;19 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;74.5&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=277060&quot; data-version=&quot;1787827152&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_565,c_scale/f_auto,q_auto/v1787827152/wp-pme/20260819_infographics_5/20260819_infographics_5.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_166,c_scale/f_auto,q_auto/v1787827152/wp-pme/20260819_infographics_5/20260819_infographics_5.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_424,c_scale/f_auto,q_auto/v1787827152/wp-pme/20260819_infographics_5/20260819_infographics_5.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_847,c_scale/f_auto,q_auto/v1787827152/wp-pme/20260819_infographics_5/20260819_infographics_5.png?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_2048,h_1130,c_scale/f_auto,q_auto/v1787827152/wp-pme/20260819_infographics_5/20260819_infographics_5.png?_i=AA 2048w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_865,c_scale/f_auto,q_auto/v1787827152/wp-pme/20260819_infographics_5/20260819_infographics_5.png?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;/figure&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The difference was largest in the US, where 65.3% were more worried about ad profiling compared with 57.6% for model training. The results suggest that how conversation data is used matters, with key concerns being less about having conversations saved and remembered than having that data turned into a commercial asset used for monetary profit.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Trust in AI companies stays low across the board&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Despite widespread sharing of sensitive topics with AI chatbots, only 11% to 20% of respondents reported a high level of trust in AI companies with their private information. Low trust was most common in France at 47.7%, with 41.6% in the UK, 40.5% in Germany, and 38.8 in the US.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Privacy commitment increases willingness to share&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A guarantee that conversations wouldn&amp;#8217;t be used to train AI models would make 44% of respondents more likely to share sensitive information. This was highest in the US at 47.7%, followed by the UK at 44.3%, Germany at 43.9%, and France at 40.7%.&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img width=&quot;1024&quot; height=&quot;588&quot; data-public-id=&quot;wp-pme/20260819_infographics_6/20260819_infographics_6.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_588,c_scale/f_auto,q_auto/v1787827142/wp-pme/20260819_infographics_6/20260819_infographics_6.png?_i=AA&quot; alt=&quot;&quot; class=&quot;wp-post-276815 wp-image-277084&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;66 KB&quot; data-optsize=&quot;14 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;78.5&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=277084&quot; data-version=&quot;1787827142&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_588,c_scale/f_auto,q_auto/v1787827142/wp-pme/20260819_infographics_6/20260819_infographics_6.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_172,c_scale/f_auto,q_auto/v1787827142/wp-pme/20260819_infographics_6/20260819_infographics_6.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_441,c_scale/f_auto,q_auto/v1787827142/wp-pme/20260819_infographics_6/20260819_infographics_6.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_882,c_scale/f_auto,q_auto/v1787827142/wp-pme/20260819_infographics_6/20260819_infographics_6.png?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_2048,h_1176,c_scale/f_auto,q_auto/v1787827142/wp-pme/20260819_infographics_6/20260819_infographics_6.png?_i=AA 2048w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_900,c_scale/f_auto,q_auto/v1787827142/wp-pme/20260819_infographics_6/20260819_infographics_6.png?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;/figure&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Interest was also high in AI chatbots designed around privacy. Over 70% of people said they would be more likely to use one, ranging from 71.1% in Germany to 82% in the UK.&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img width=&quot;1024&quot; height=&quot;497&quot; data-public-id=&quot;wp-pme/20260819_infographics_7/20260819_infographics_7.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_497,c_scale/f_auto,q_auto/v1787827104/wp-pme/20260819_infographics_7/20260819_infographics_7.png?_i=AA&quot; alt=&quot;&quot; class=&quot;wp-post-276815 wp-image-277108&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;42 KB&quot; data-optsize=&quot;10 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;77.4&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=277108&quot; data-version=&quot;1787827104&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_497,c_scale/f_auto,q_auto/v1787827104/wp-pme/20260819_infographics_7/20260819_infographics_7.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_146,c_scale/f_auto,q_auto/v1787827104/wp-pme/20260819_infographics_7/20260819_infographics_7.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_372,c_scale/f_auto,q_auto/v1787827104/wp-pme/20260819_infographics_7/20260819_infographics_7.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_745,c_scale/f_auto,q_auto/v1787827104/wp-pme/20260819_infographics_7/20260819_infographics_7.png?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_2048,h_993,c_scale/f_auto,q_auto/v1787827104/wp-pme/20260819_infographics_7/20260819_infographics_7.png?_i=AA 2048w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_760,c_scale/f_auto,q_auto/v1787827104/wp-pme/20260819_infographics_7/20260819_infographics_7.png?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;/figure&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;These findings suggest that a commitment to privacy is still highly regarded for AI chatbot users, even if it wasn&amp;#8217;t the initial reason that a user would choose to use AI.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Conclusion: AI must earn the trust of its users&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Personal conversations with AI chatbots are already common. More than two-thirds of respondents across the four countries surveyed had discussed at least one sensitive topic with an an AI chatbot, from money worries to personal secrets. Yet only one in five reported a high level of trust in AI companies with their private information.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;People are confiding in AI much faster than they trust it, but not because AI has replaced human connection — friends and family remain the first choice for every sensitive topic. Rather, AI is the option that people reach for when convenience and freedom from judgment matter more.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;While convenience opens the door for someone to use AI, it&amp;#8217;s trust that decides how far they&amp;#8217;ll go with it. A no-training guarantee was enough to make 44% of users more willing to share, and eight in 10 said they&amp;#8217;d be more likely to choose &lt;a href=&quot;https://proton.me/lumo&quot;&gt;private AI&lt;/a&gt;. People have already decided AI is useful enough to hear their money troubles, doubts, and everyday concerns. The providers who prove, not just promise, that they can keep this information safe will be the ones people trust with the rest.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Methodology&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This survey included 4,014 respondents across France, Germany, the UK, and the US. All respondents were screened to confirm they currently use an AI chatbot or assistant.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The survey was administered online and consisted of approximately 12 questions on AI chatbot usage. Respondents were not told which company commissioned the research. This unbranded design was intended to reduce the influence shaped by any company&amp;#8217;s reputation.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Limitations&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This survey captures self-reported attitudes, preferences, and past behaviors. It doesn&amp;#8217;t observe respondents&amp;#8217; actual chatbot conversations or independently verify what they have shared. The survey covers current chatbot users in four countries, and shouldn&amp;#8217;t be interpreted as representative of other countries nor of people who don&amp;#8217;t currently use AI chatbots.&lt;/p&gt;
</content:encoded><category>News</category><author>Risa Tang</author></item><item><title>Are Meta’s smart glasses training AI for robots?</title><link>https://proton.me/blog/meta-smart-glasses-ai-robots</link><guid isPermaLink="true">https://proton.me/blog/meta-smart-glasses-ai-robots</guid><description>Meta’s smart glasses capture first-person data that helps AI understand the physical world. Here’s what that means for robots, privacy, and users.</description><pubDate>Tue, 22 Sep 2026 17:56:14 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Smart glasses can look like a simple consumer gadget: a camera on your face, speakers in your ears, and an AI assistant that can answer questions about what you see. But the same device can give an AI system something it has always lacked: a first-person view of everyday human life.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That matters because teaching AI to write or generate images is very different from teaching a machine to move through the physical world. A robot needs to understand where objects are, what happens when they move, and how hands interact with things that bend, break, spill, or change shape.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/blog/stop-meta-tracking&quot;&gt;Meta&lt;/a&gt; has spent years researching wearable devices that capture this kind of information. Its Ray-Ban Meta glasses put some of that technology into a consumer product, giving the company access to data generated during ordinary activities.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A 72-hour test of the glasses, using their AI features throughout the day and requesting the associated data, offered a glimpse into why first-person recordings could be valuable for training AI, and why privacy becomes harder to separate from the technology itself.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How AI learns from the real world&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Large language models learn from enormous collections of written material. That works well for systems built around language, but text can&amp;#8217;t fully describe how people might do things like move through a kitchen, pick up a bottle, crack an egg, or find their keys.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Human beings learn those things through years of sensory experience. Meta&amp;#8217;s former chief AI scientist Yann LeCun has argued that by age four, a child has seen 50 times more data than even the largest language models. His broader point is that machines need richer sensory input if they are going to understand the physical world.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For a robot, that means learning from more than instructions. It needs data on what people actually do, including the small variations that are difficult to describe in words. So for example, someone doing the dishes may look mundane. But once that footage is labeled and annotated, it can show an AI system where objects are, how hands move, and what happens when something unexpected occurs.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That kind of training data is difficult to collect at scale. A wearable camera offers one possible solution because it can capture the world from the same perspective as the person performing the task. As LeCun&amp;#8217;s argument puts it, &amp;#8220;It needs eyes.&amp;#8221;&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Why Meta is using smart glasses&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Meta has been working on this problem for years through &lt;a href=&quot;https://about.fb.com/news/2020/09/privacy-matters-project-aria/&quot;&gt;Project Aria&lt;/a&gt;, a research program built around wearable computers in a glasses form factor. The research devices use cameras and other sensors to study how people interact with the world.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Project Aria also shows how different the privacy expectations can be between research and consumer use. Meta&amp;#8217;s published guidelines say research participants are trained on appropriate recording practices, people in private homes must consent, and a visible light indicates when audio and video are being collected.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Consumer smart glasses operate in a much less controlled environment. A person can wear them while walking down a street, shopping, making coffee, or doing household chores. That creates a useful source of first-person data. It also means people around the wearer may appear in recordings without knowing that a camera is active.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The distinction matters because the value of this data comes from its ordinary nature. Its value comes from capturing the small details of everyday life.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What robots need to learn&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Researchers are working on several problems that look simple to humans but are difficult for machines. One is episodic memory. Asking an AI where you left your keys sounds easy, but the system has to recognize the object, understand when it was last seen, and keep track of what happened between then and now.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Another is intuitive physics. If you roll a ball toward a table, you already have an expectation about what will happen. Humans develop these predictions through years of observing the physical world.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The third involves hand-object interactions. Tying shoelaces, buttoning a shirt, picking something up, or handling a piece of cloth all require a machine to deal with objects that can bend and deform. Those are the kinds of situations that first-person recordings can capture.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;During the 72-hour test, ordinary activities mapped surprisingly well onto these research problems. Driving involved predicting how objects move through space. Picking up a bottle or cracking an egg involved hand-object interaction. Watching an egg roll off a counter involved intuitive physics. Asking where the keys had been left was an episodic-memory task.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The point is not that every mundane recording immediately becomes useful training data. It is that ordinary human activity contains the examples that embodied AI needs.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What Meta’s glasses can capture&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Meta says Ray-Ban Meta glasses do not continuously record everything around the wearer for AI training. According to the company, the data used to train its AI and potentially reviewed by humans includes the vocal commands and video captured when a user asks the AI to do something.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When the AI needs to analyze what the camera sees, the relevant footage can be sent to Meta&amp;#8217;s servers for processing. The company can then use that information to improve its AI systems. A person can ask the glasses about an object, a location, a task, or something happening in front of them, creating a record of those interactions from a first-person perspective.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Meta has also introduced Live AI, which makes the assistant available without requiring the usual wake phrase. That makes the glasses more useful as a real-time assistant, while also increasing the amount of time in which their camera and microphone can be active.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;There is another &lt;a href=&quot;https://proton.me/blog/ai-privacy-concerns&quot;&gt;privacy&lt;/a&gt; problem that is harder to solve through settings. The wearer controls the device, but &lt;a href=&quot;https://proton.me/blog/smart-glasses-real-time-doxxing&quot;&gt;everyone around them does not&lt;/a&gt;. During the test, faces were blurred in the material that was reviewed, but people around the wearer did not know they were being recorded. That is different from Meta&amp;#8217;s Project Aria research process, where participants and people in certain private environments are subject to explicit consent requirements.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What points to Meta’s robotics plans&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The idea that Meta could use wearable data to help build robots is still a hypothesis about the company&amp;#8217;s broader strategy, rather than something the glasses alone prove. There are, however, several pieces of evidence behind it.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In February 2025, Meta created a humanoid robotics division within Reality Labs, the same broader organization responsible for its smart glasses. In May 2026, Meta also acquired Assured Robot Intelligence, a robotics lab co-founded by Lerrel Pinto.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Meta has also said it wants its technology to serve as the software layer for humanoid robots. Its research has already explored how egocentric recordings can help robots learn physical tasks. That makes the glasses relevant beyond their role as an AI assistant. They put cameras, microphones, and AI into a device people can wear throughout the day.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Meta&amp;#8217;s next-generation wearable prototypes are described as moving toward more continuous sensing and stronger object tracking. Those capabilities could produce more useful data about how people interact with the physical world.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;None of this establishes that Meta is secretly collecting every moment of its customers&amp;#8217; lives to build an army of robots. It does show why first-person wearable data could be strategically valuable to a company investing heavily in both AI and robotics.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;The bigger question&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Smart glasses make AI more useful because they give it access to the world around us. That same capability makes them different from the AI assistants most people are used to. The question is who gets to decide how this increasingly personal source of data is collected, processed, and used.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;As AI moves from the screen into the physical world, first-person data becomes more valuable.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That makes it increasingly important to understand what a device can see, hear, store, and send away.&lt;/p&gt;
</content:encoded><category>Opinion</category><author>Edward Komenda</author></item><item><title>Proton partners with Apertus, Switzerland&amp;#8217;s sovereign AI model</title><link>https://proton.me/blog/lumo-apertus-partnership</link><guid isPermaLink="true">https://proton.me/blog/lumo-apertus-partnership</guid><description>Proton has partnered with the team behind Apertus, adding their sovereign AI model to its privacy-first AI chatbot Lumo.</description><pubDate>Thu, 17 Sep 2026 11:56:33 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton is partnering with the team behind Apertus to bring its new Apertus 1.5 model to Lumo, Proton&amp;#8217;s privacy-focused alternative to ChatGPT. The partnership will also give researchers behind Apertus access to real-world feedback that can help them improve it more quickly.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Apertus is a fully open large language model developed by researchers at &lt;a href=&quot;https://actu.epfl.ch/news/apertus-s-associe-a-lumo-l-assistant-ia-de-proton/&quot;&gt;EPFL&lt;/a&gt;, &lt;a href=&quot;https://ethz.ch/de/news-und-veranstaltungen/eth-news/news/2026/09/apertus-arbeitet-neu-mit-dem-ki-assistenten-lumo-von-proton-zusammen.html&quot;&gt;ETH Zurich&lt;/a&gt;, and the Swiss National Supercomputing Centre (CSCS). Its architecture, training data, and methods are open, and it’s trained on publicly available data, respecting opt-out requests and filtering out personal details. It fills an important role in today&amp;#8217;s AI landscape by providing a fully open source model with a transparent and reproducible training pipeline. In a world dominated by US and Chinese models, Apertus is instrumental in Europe&amp;#8217;s tech sovereignty.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The world’s leading AI models have millions of people using them every day, creating real-world feedback loops that help make them better. Fully open models developed in an academic context do not have access to feedback at the same scale, limiting their ability to compete at the frontier.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;With this partnership, that could start to change. Proton is introducing a feedback mechanism that connects people using Apertus in Lumo with the researchers building it. Tens of millions of Lumo users around the world can now choose to contribute feedback, helping independent, ethical, and truly open source AI become more competitive.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Building a European alternative&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Europe now has the pieces of an independent AI stack: infrastructure it controls, a model open by design, and a product that puts it directly in people’s hands.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&amp;#8220;We don’t want to spend the next decade relying on other countries for the AI we use every day,&amp;#8221; said Eamonn Maguire, Director of AI at Proton. &amp;#8220;Having our own AI isn’t enough. It needs to be competitive so that people actually use it. This partnership with the Swiss AI Initiative gives Europe a path to get there.&amp;#8221;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;One of the biggest advantages leading AI labs have is a constant stream of feedback from millions of people using their models. Bringing Apertus to Lumo gives the university research teams behind it access to this feedback at scale, helping level the playing field.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Apertus in Lumo today&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;To start using Apertus in Lumo, select Apertus 1.5 from the model dropdown, and start chatting as normal. Like other conversations in Lumo, your chats are protected by zero-access encryption and stay private by default.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you choose to give feedback on an Apertus response, tap the thumbs-up or thumbs-down button to send in your feedback. Your contribution will be anonymized, and made available to the university research teams behind Apertus.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;“Real-world feedback is the one ingredient that open models have been missing. Thanks to Proton, Lumo users will be able to voluntarily provide feedback that contributes to Apertus research. For a fully open, publicly developed model, that is a game changer,” says Imanol Schlag, Research Scientist at the ETH AI Center and co-lead of the Apertus project.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;“Making Apertus available in Lumo gives us valuable insights into how the model performs in real-world settings. Voluntary feedback also helps us identify where it can be made more useful and more robust,” says Martin Jaggi, Professor at EPFL and co-lead of the Apertus project. “It also means that we are enabling a broader community to contribute to the model’s further improvement.”&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Why work together&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Building an open and independent AI ecosystem is bigger than any one model or company. To compete in AI, Europe needs to pool its resources and build public-private partnerships that can do what no single organization can achieve alone. Europe&amp;#8217;s future in AI depends on researchers building in the open, infrastructure governed in Europe, companies turning that technology into products people can use, and people willing to help those technologies improve.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Through this partnership, we are taking steps to make that alternative more than an idea. Starting today, fully open source AI is now something people can use and — if and when they choose to — help shape for the future.&lt;/p&gt;



&lt;div class=&quot;flex flex-wrap justify-center gap-2&quot;&gt;
&lt;a class=&quot;btn inline-block rounded-full font-bold btn-small btn-solid-purple&quot; href=&quot;https://lumo.proton.me/&quot;&gt;Try Lumo now&lt;/a&gt;
</content:encoded><category>Lumo AI</category><category>Proton updates</category><author>Eamonn Maguire</author></item><item><title>87% of Canada&amp;#8217;s biggest companies depend on US tech</title><link>https://proton.me/business/blog/canada-us-tech</link><guid isPermaLink="true">https://proton.me/business/blog/canada-us-tech</guid><description>Our latest research found that 87% of Canada’s largest companies and 100% of government domains rely on US-owned email infrastructure.</description><pubDate>Thu, 17 Sep 2026 11:48:36 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;It’s clearer than ever that too much of the technology the world relies on is controlled by too few tech giants, most of them based in the United States and China.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/drive&quot;&gt;Cloud storage&lt;/a&gt;, web hosting, &lt;a href=&quot;https://proton.me/business/mail&quot;&gt;email&lt;/a&gt;, social media, &lt;a href=&quot;https://proton.me/business/meet&quot;&gt;video calling&lt;/a&gt;, communication platforms, and the basic productivity tools that companies and governments use every day have become essential infrastructure. The modern economy cannot function without them. And control over that infrastructure gives both providers — and the countries whose laws they operate under — outsized power over everyone who depends on it.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;We’ve been tracking this concentration for some time. Our previous research found that 74% of publicly listed &lt;a href=&quot;https://proton.me/business/europe-tech-watch&quot;&gt;European companies rely on US tech&lt;/a&gt;, fueling a wider debate in Europe about economic security, digital sovereignty, and geopolitical risk.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Now we&amp;#8217;ve found that Canada is even more exposed than Europe. We examined 220 publicly listed companies representing 70% of the Canadian stock market’s total capitalization and found that 87% rely on US-owned infrastructure for their email. The same was true for 84% of the 100 largest municipalities. We also found that 14 out of 14 federal, provincial, and territorial government domains rely on American email infrastructure.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;To be clear, the problem is not that these companies are American. The risk comes when too much of the infrastructure the world depends on sits under the control and jurisdiction of any single government. At a time of increasing geopolitical tensions and trade negotiations, we believe it&amp;#8217;s important to fully understand the different levers that one country can hold over another behind the scenes.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full&quot;&gt;&lt;img width=&quot;2400&quot; height=&quot;744&quot; data-public-id=&quot;wp-pme/us-tech-reliance-across-sectors-in-canada/us-tech-reliance-across-sectors-in-canada.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_2400,h_744,c_scale/f_auto,q_auto/v1789637989/wp-pme/us-tech-reliance-across-sectors-in-canada/us-tech-reliance-across-sectors-in-canada.png?_i=AA&quot; alt=&quot;A diagram showing the US tech reliance across different sectors in Canada&quot; class=&quot;wp-post-296473 wp-image-296474&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;195 KB&quot; data-optsize=&quot;46 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;76.5&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=296474&quot; data-version=&quot;1789637989&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1789637989/wp-pme/us-tech-reliance-across-sectors-in-canada/us-tech-reliance-across-sectors-in-canada.png?_i=AA 2400w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_93,c_scale/f_auto,q_auto/v1789637989/wp-pme/us-tech-reliance-across-sectors-in-canada/us-tech-reliance-across-sectors-in-canada.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_317,c_scale/f_auto,q_auto/v1789637989/wp-pme/us-tech-reliance-across-sectors-in-canada/us-tech-reliance-across-sectors-in-canada.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_238,c_scale/f_auto,q_auto/v1789637989/wp-pme/us-tech-reliance-across-sectors-in-canada/us-tech-reliance-across-sectors-in-canada.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_476,c_scale/f_auto,q_auto/v1789637989/wp-pme/us-tech-reliance-across-sectors-in-canada/us-tech-reliance-across-sectors-in-canada.png?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_2048,h_635,c_scale/f_auto,q_auto/v1789637989/wp-pme/us-tech-reliance-across-sectors-in-canada/us-tech-reliance-across-sectors-in-canada.png?_i=AA 2048w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_486,c_scale/f_auto,q_auto/v1789637989/wp-pme/us-tech-reliance-across-sectors-in-canada/us-tech-reliance-across-sectors-in-canada.png?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 2400px) 100vw, 2400px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;h2 class=&quot;wp-block-heading&quot;&gt;How we measured Canada&amp;#8217;s dependence on US tech&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;We collected the data using the same method as our earlier research in Europe. Using public DNS lookups, we identified the mail exchange (MX) records associated with each organization’s domain. These records show which companies handle an organization’s email, either directly or through an email security service.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For Canada, we looked at three parts of the economy and public sector:&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Federal, provincial, and territorial governments.&lt;/strong&gt; We examined all 14 federal, provincial and territorial domains. Of these, all 14 rely on &lt;a href=&quot;https://proton.me/business/microsoft-365-alternative&quot;&gt;Microsoft 365&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Companies.&lt;/strong&gt; We analyzed the 220 companies in the S&amp;amp;P/TSX Composite Index, which together account for around 70% of the Canadian stock market’s total capitalization. Of the companies reviewed, 161 used &lt;a href=&quot;https://proton.me/business/microsoft-365-alternative&quot;&gt;Microsoft 365&lt;/a&gt; and nine used &lt;a href=&quot;https://proton.me/business/google-workspace-alternative&quot;&gt;Google Workspace&lt;/a&gt; for their email infrastructure.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Municipalities.&lt;/strong&gt; Canada has more than 4,000 local governments, so we focused on the country’s 100 largest municipalities by population. Of those, 77 used Microsoft and one used Google.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Why this matters&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The problem with this arrangement is quite simple: One company, headquartered in one country, operating under one country&amp;#8217;s laws, carries the email of an entire G7 nation&amp;#8217;s governments.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;US law gives that country real power. Under the CLOUD Act, US authorities can compel American tech companies to hand over data they hold,&amp;nbsp;including data stored outside the US. When the US placed sanctions on the International Criminal Court, for example, &lt;a href=&quot;https://www.theregister.com/2026/02/18/microsoft_asks_uk_parliament_to_correct_record/&quot;&gt;Microsoft cut off the email account of the court&amp;#8217;s chief prosecutor&lt;/a&gt; — a move Microsoft initially told UK lawmakers was the ICC&amp;#8217;s own decision, before acknowledging that testimony was inaccurate. Access to infrastructure can be withdrawn on political terms and virtually overnight.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;AWS, Microsoft Azure, and Google Cloud serve an estimated&amp;nbsp;85% of the European cloud market&amp;nbsp;— and when one of them fails, the failures cascade.&amp;nbsp;A major &lt;a href=&quot;https://proton.me/business/blog/aws-outage&quot;&gt;AWS outage&lt;/a&gt; in late 2025&amp;nbsp;crashed apps across industries;&amp;nbsp;&lt;a href=&quot;https://www.reuters.com/technology/microsoft-azure-down-thousands-users-downdetector-shows-2025-10-29&quot;&gt;an Azure outage followed nine days later&lt;/a&gt;, knocking &lt;a href=&quot;https://proton.me/business/mail/outlook-alternative&quot;&gt;Outlook&lt;/a&gt;, &lt;a href=&quot;https://proton.me/business/meet/microsoft-teams-alternative&quot;&gt;Teams&lt;/a&gt;, and dozens of enterprise services offline for eight hours.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Much of the email infrastructure used by Canadian companies and governments depends on Microsoft, leaving them exposed to the same kind of service disruption.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;These risks, however, exist regardless of which country holds leverage. A world where one government can lawfully reach into the central communications of other nations is the problem, no matter who that government is, and wherever its companies are headquartered.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Canadians are already reacting&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The dependence we measured in Canada&amp;#8217;s public and private sectors comes amid a wider rupture in Canada-US relations, including retaliatory tariffs matched dollar for dollar and trade talks that broke down in a very public manner.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This backdrop is already shaping how Canadians see their tech dependence.&amp;nbsp;&lt;a href=&quot;https://www.politico.com/newsletters/digital-future-daily/2026/02/02/canadas-digital-sovereignty-dilemma-00760361&quot;&gt;Politico&amp;#8217;s reporting&lt;/a&gt; on Canada&amp;#8217;s digital sovereignty dilemma&amp;nbsp;describes a country forging its own path to reduce reliance on American tech, noting that its smaller economy and US-tied tech industry severely limit its bargaining power. This mirrors the shift we documented in Europe over the last year, where our research found&amp;nbsp;&lt;a href=&quot;https://proton.me/blog/european-alternative-us-tech-survey&quot;&gt;73% of Europeans believe their societies rely too heavily on US tech&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href=&quot;https://proton.me/business/blog/european-digital-independence-survey-2026&quot;&gt;56% now say local infrastructure matters more to them than a year ago&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Canada&amp;#8217;s position differs from Europe&amp;#8217;s in one important way: European institutions have moved from diagnosis to legislation, with the European Commission&amp;#8217;s&amp;nbsp;&lt;a href=&quot;https://proton.me/business/blog/eu-tech-sovereignty-package&quot;&gt;tech sovereignty package&lt;/a&gt;&amp;nbsp;committing major funding to local alternatives. Canadian institutions haven&amp;#8217;t announced migration plans, and we&amp;#8217;re not the ones to call for it. Proton is a Swiss company. What we can do is show what the data says and what it implies for anyone who depends on these systems, including what&amp;nbsp;&lt;a href=&quot;https://proton.me/business/blog/europe-us-tech-dependence-qwant&quot;&gt;Europe&amp;#8217;s slow, imperfect transition&lt;/a&gt;&amp;nbsp;reveals about how hard these moves are in practice.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What any organization can do about it&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For Canadian businesses and institutions assessing their own exposure, the starting steps are concrete:&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;List every third-party tool you use:&lt;/strong&gt; Flag which are headquartered outside Canada and which of those fall under a foreign government&amp;#8217;s legal jurisdiction.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Identify what would stop your operations:&lt;/strong&gt;&amp;nbsp;Which tools, cut off tomorrow, would halt work? This belongs in &lt;a href=&quot;https://proton.me/business/business-continuity&quot;&gt;business continuity&lt;/a&gt; planning.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Check where your data sits:&lt;/strong&gt;&amp;nbsp;Which country&amp;#8217;s laws govern it? Who can access it, and through what legal process?&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Test the alternatives:&lt;/strong&gt;&amp;nbsp;For most critical tools, Canadian and European alternatives are available, and some offer built-in tools that make switching easier, such as Proton&amp;#8217;s &lt;a href=&quot;https://proton.me/easyswitch&quot;&gt;Easy Switch&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Move the highest-risk services first:&lt;/strong&gt;&amp;nbsp;Full migration takes time. Start with the systems you can&amp;#8217;t operate without.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When your &lt;a href=&quot;https://proton.me/business/mail&quot;&gt;business email&lt;/a&gt; relies on US tech companies, you&amp;#8217;re exposing your organization to strategic risks that, at the end of the day, are out of your control.&lt;/p&gt;
</content:encoded><category>For business</category><author>Raphael Auphan</author></item><item><title>8 more privacy tools experts actually use</title><link>https://proton.me/blog/more-privacy-tools-experts-use</link><guid isPermaLink="true">https://proton.me/blog/more-privacy-tools-experts-use</guid><description>See the tech tools used by privacy experts, from a DIY smartwatch and travel router to Tails, Linux, Pi-hole, and offline Wikipedia.</description><pubDate>Tue, 15 Sep 2026 18:02:32 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Privacy technology does not have to mean replacing every device you own or learning how to build your own computer.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;There are plenty of smaller changes you can make to adjust the way you use technology. You can keep information offline, block trackers across your home network, choose software that gives you more control, or even carry an entire operating system on a USB drive.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The tools below take different approaches to privacy, but they share a common idea: you get to decide how your technology works instead of simply accepting its default settings.&lt;/p&gt;



&lt;figure class=&quot;wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio&quot;&gt;&lt;div class=&quot;wp-block-embed__wrapper&quot;&gt;
&lt;iframe loading=&quot;lazy&quot; title=&quot;Seven Gadgets A Security Expert Actually Trusts&quot; width=&quot;750&quot; height=&quot;422&quot; src=&quot;https://www.youtube-nocookie.com/embed/3VJ5Htyhm7k?feature=oembed&quot; frameborder=&quot;0&quot; allow=&quot;accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share&quot; referrerpolicy=&quot;strict-origin-when-cross-origin&quot; allowfullscreen&gt;&lt;/iframe&gt;
&lt;/div&gt;&lt;/figure&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Build a smartwatch that only does what you want&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Many smartwatches are designed to work alongside an app and an online account. Your activity data is collected by the watch, transferred to another device, and potentially sent onwards to a company&amp;#8217;s servers.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You can take a different approach with &lt;a href=&quot;https://watchy.sqfmi.com/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Watchy&lt;/a&gt;, a small programmable computer designed to be used as an open-source smartwatch. Because you can program the device yourself, you get to decide what it does and what information it collects. You could use it for something as simple as counting your steps without requiring an account or constantly syncing your activity to a remote service.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The data can either stay on the device or transfer it to your computer. You can also customize the watch with your own features, information, and displays. This makes Watchy an interesting alternative to more ubiquitous smartwatch brands if you want the functionality of a wearable without automatically handing control of the experience to a third party.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Use Flipper Zero to understand wireless technology&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A surprising amount of everyday technology communicates wirelessly. Your garage door opener, office access system, television remote, and other devices all rely on different kinds of wireless signals to communicate. Most of the time, you never see any of this happening.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://flipperzero.one/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Flipper Zero&lt;/a&gt; gives you a way to experiment with some of those signals. It can read, save, and replicate certain wireless communications, depending on the technology and security involved.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For example, you can use it with a compatible infrared remote. The device can capture the signal sent by the remote, store it, and transmit the same command itself. That does not mean it can unlock or control everything around you. What it can interact with depends on the particular technology being used.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The real value is educational. Instead of treating wireless communication as something invisible happening in the background, you can use a Flipper Zero device to understand how some of it actually works.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Keep Wikipedia in your pocket with Kiwix&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://kiwix.org/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Kiwix&lt;/a&gt; lets you download large collections of information so you can access them offline. One of the best-known examples is Wikipedia, which you can store locally and search without being connected to the internet.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That can be useful when you&amp;#8217;re travelling somewhere with unreliable connectivity, spending an extended amount of time in a remote location, or simply want access to information without constantly requesting it from an online service.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;There is one obvious limitation: your offline library is only as current as the version you downloaded. But once the content is stored on your device, you do not need a live connection to access it.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It is a useful reminder that you do not have to depend on the internet for every piece of information you need. Sometimes, you can simply keep the information yourself.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Turn an old iPod into a dedicated music player&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You probably already have a device that can play music. Your phone can stream millions of songs, recommend something based on your listening habits, and keep your entire library in the cloud. But if all you want is a device that plays your music, an old iPod Classic can still do the job.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;With alternative software such as &lt;a href=&quot;https://www.rockbox.org/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Rockbox&lt;/a&gt;, you can give an iPod Classic a new lease on life. Hardware modifications can also bring it up to date with features such as USB-C. The result can be deliberately simple. You load your own music onto the device, much like copying files to a USB drive, and listen without needing a streaming subscription or account.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That way, there are no recommendations for deciding what you should listen to next. Nor is there a need for a service to track your listening habits as your music library can simply remain on the device. You can even use the extra storage for things such as important phone numbers or other information you might want available when your phone is unavailable.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Sometimes privacy means choosing a device that does less.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Block trackers across your home network with Pi-hole&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Your phone is not the only device that can connect to advertising and tracking services. Your laptop, smart TV, tablet, and other connected devices can all make requests to servers around the internet.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://pi-hole.net/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Pi-hole&lt;/a&gt; lets you filter some of those requests at the network level. You can run Pi-hole on a small computer like a Raspberry Pi. It sits between the devices on your network and the wider internet, checking where they are trying to connect. Requests to destinations on your blocklist can then be stopped before they leave your network.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Because Pi-hole operates at the network level, you can use it to cover multiple devices at once. This can be particularly useful for devices such as smart TVs, where installing conventional ad-blocking software may not be possible. You can also see the requests being made by devices on your network, including the ones Pi-hole has blocked.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For even more local control, you can combine Pi-hole with &lt;a href=&quot;https://nlnetlabs.nl/projects/unbound/about/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Unbound&lt;/a&gt;. Instead of relying entirely on another company&amp;#8217;s DNS server to resolve website addresses, your own system can handle more of that work and store the answers locally. Your home network becomes something you can inspect and manage rather than a black box.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you want to try it yourself, check out our guide explaining &lt;a href=&quot;https://protonvpn.com/blog/pi-hole&quot;&gt;how to set up a Pi-hole&lt;/a&gt; and use it to filter DNS requests across your network.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Take your own network with you when you travel&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Hotel Wi-Fi can become awkward when you have several devices. You might have to connect your phone, laptop, tablet, and other hardware individually, and some hotels place limits on how many devices you can use. A travel router gives you another option.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Instead of connecting every device directly to the hotel&amp;#8217;s network, you connect the router to the hotel Wi-Fi. Your devices then connect to your router. That means you only have to deal with the hotel&amp;#8217;s network once. Your own devices can stay connected to the network you&amp;#8217;ve configured, even if you&amp;#8217;re travelling with several of them.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You can also run a VPN directly on the router. Traffic from the devices connected to it can then pass through the VPN connection before reaching the internet. A travel router is a small piece of hardware, but it gives you considerably more control over how your devices connect when you&amp;#8217;re away from home.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Our guide to &lt;a href=&quot;https://protonvpn.com/blog/setup-a-vpn-router&quot;&gt;setting up a VPN on your router&lt;/a&gt; explains how router-level VPN protection works and how it can cover devices across a network.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Choose a laptop you can repair and customize&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A laptop does not have to be a closed system that gets replaced when something goes wrong. &lt;a href=&quot;https://frame.work/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Framework&lt;/a&gt; laptops are designed so you can open them up, replace components, upgrade parts, and customize the hardware. Even the ports are modular, allowing you to swap one type for another when your needs change. That philosophy extends to the software if you run Linux.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Linux gives you more control over what is running on your computer and most Linux distributions are largely open source. That means the underlying code can be inspected by developers and researchers rather than requiring you to rely entirely on a company&amp;#8217;s description of what its software does.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Open-source software is not automatically private or secure. But having access to the underlying code gives you another level of control over the technology you use.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Together, repairable hardware and open-source software let you take greater ownership of both the physical computer and the software running on it.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Carry a privacy-focused operating system on a USB drive&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You can carry an entire privacy-focused computer environment without carrying another computer.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://tails.net/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Tails&lt;/a&gt; is an operating system designed around privacy that you can boot from a USB drive on a compatible computer. Instead of using the operating system already installed on the machine, you can start the computer using Tails.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Internet traffic is routed through the &lt;a href=&quot;https://www.torproject.org/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Tor&lt;/a&gt; network, which sends connections through multiple relays to make it harder to determine where they originally came from. Tails is also designed to be amnesic. When you shut it down, it aims to leave as little trace as possible on the computer you were using.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That makes a USB drive containing Tails something like a portable privacy setup. You can carry your preferred operating system with you and use it on a compatible computer without relying on the machine&amp;#8217;s usual operating system.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It is an extreme example of the same principle behind many of the other tools here: you can have more control over the technology you use, even when you are away from your own devices.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you want to understand how Tor and VPNs differ, Our guide to &lt;a href=&quot;https://protonvpn.com/blog/tor-vpn&quot;&gt;Tor over VPN&lt;/a&gt; explains how the two technologies provide different layers of privacy.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Start with one change&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You do not need a programmable smartwatch, a modified iPod, or a privacy-focused operating system on a USB drive to take more control over your technology.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Each of these tools represents a different way to change a default. You can keep your data locally instead of automatically syncing it. You can block trackers at the network level. You can store information offline, choose open-source software, or create your own network when travelling.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You can also start much smaller. Check which permissions your existing apps have. Think about whether an app actually needs access to your location, microphone, or other device features. Look at which services require accounts and which information is being stored remotely.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You also do not have to change everything at once. One deliberate choice can reduce the amount of information you hand over by default.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Privacy does not require completely changing how you use technology. It can start with deciding that one part of your technology should work differently.&lt;/p&gt;
</content:encoded><category>Videos</category><author>Proton Team</author></item><item><title>What does CC mean in emails? To, CC, and BCC explained</title><link>https://proton.me/business/blog/what-is-to-cc-bcc</link><guid isPermaLink="true">https://proton.me/business/blog/what-is-to-cc-bcc</guid><description>Learn the different ways to send an email to multiple email addresses with our explainer on To, CC, and BCC.</description><pubDate>Fri, 11 Sep 2026 18:57:00 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;CC (carbon copy) and BCC (blind carbon copy) are standard email features that control who receives a message and what information they can see.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Understanding the difference between To, CC, and BCC is crucial in a business context. CC the wrong person and your client sees an internal aside they shouldn&amp;#8217;t have. Forget to CC a decision-maker and they never see an email thread they really needed to.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Keep reading to find out which option to select to communicate clearly (to the right recipient/s), avoid unnecessary replies, protect recipients’ &lt;a href=&quot;https://proton.me/blog/what-is-email-address&quot;&gt;&lt;u&gt;email addresses&lt;/u&gt;&lt;/a&gt;, and safeguard sensitive information.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What does CC mean?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;CC stands for Carbon Copy, a throwback to a time when physical, handwritten memos or letters would be &lt;a href=&quot;https://en.wikipedia.org/wiki/Carbon_copy&quot;&gt;&lt;u&gt;replicated using a sheet of carbon paper&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;CC allows you to send a copy of an email to multiple recipients who are not the primary recipient in the To field. The primary recipient will see the email address(es) you have entered into the CC field, and any responses from them. Likewise, the person you have CCd will see any responses from the recipient (unless they&amp;#8217;re removed from the CC field, or the recipient clicks Reply instead of Reply all).&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;CC&amp;#8217;ing is especially useful when sending &lt;a href=&quot;https://proton.me/business/mail&quot;&gt;&lt;u&gt;business emails&lt;/u&gt;&lt;/a&gt;, because you can add as many recipients into an email as you like, all of whom will receive a copy of the same email and see each other&amp;#8217;s addresses and responses. This keeps everyone in the loop and creates a transparent record of the conversation without requiring a response.&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;a href=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1707569552/wp-pme/bcc-and-cc-1/bcc-and-cc-1.png?_i=AA&quot;&gt;&lt;img width=&quot;1024&quot; height=&quot;862&quot; data-public-id=&quot;wp-pme/bcc-and-cc-1/bcc-and-cc-1.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_862,c_scale/f_auto,q_auto/v1707569552/wp-pme/bcc-and-cc-1/bcc-and-cc-1.png?_i=AA&quot; alt=&quot;&quot; class=&quot;wp-post-10543 wp-image-12683&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;78 KB&quot; data-optsize=&quot;24 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;69.3&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=12683&quot; data-version=&quot;1707569552&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_862,c_scale/f_auto,q_auto/v1707569552/wp-pme/bcc-and-cc-1/bcc-and-cc-1.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_253,c_scale/f_auto,q_auto/v1707569552/wp-pme/bcc-and-cc-1/bcc-and-cc-1.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_647,c_scale/f_auto,q_auto/v1707569552/wp-pme/bcc-and-cc-1/bcc-and-cc-1.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1707569552/wp-pme/bcc-and-cc-1/bcc-and-cc-1.png?_i=AA 1268w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;/a&gt;&lt;/figure&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;When to use CC in email&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;CC is a useful function when you need someone (or multiple people) other than the recipient to know about and follow an &lt;a href=&quot;https://proton.me/blog/what-is-an-email-thread&quot;&gt;&lt;u&gt;email thread&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For example, when you want to loop in an entire project team on something that affects everyone&amp;#8217;s work, such as a scope or deadline change, you can simply CC them in.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;CC&amp;#8217;ing can also be helpful when you want particular individuals to have visibility of an email thread without requiring their input. When emailing a client proposal, for example, you might want to CC anyone directly involved in the project so they have visibility of their feedback and your subsequent discussion. If anything gets escalated or referenced in a review later, they&amp;#8217;re always informed on time.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;When not to use CC in email&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;CC&amp;#8217;ing should be avoided when your email (or the subsequent email thread) contains sensitive or confidential information. When you email one person sensitive information, there’s a risk they could forward or store it, but CCing increases that risk by adding more recipients, often including people who weren&amp;#8217;t the intended audience for the content in the first place.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You should also avoid using CC when you expect someone you&amp;#8217;re CC&amp;#8217;ing to take action. People included in CC often assume they don&amp;#8217;t need to respond, which can lead to missed tasks or delays. This risk grows when you CC large numbers of recipients unnecessarily, which also clutters inboxes with irrelevant noise.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;CC&amp;#8217;ing an entire distribution list on a routine status update creates noise without adding accountability. Emailing your entire team about a change that doesn&amp;#8217;t affect them can create confusion.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You should also be careful about CC&amp;#8217;ing someone into an existing conversation without the other party&amp;#8217;s knowledge or agreement — like, for example, adding a new stakeholder to a client thread without telling the client first. Even if you have a legitimate reason, it can look like you&amp;#8217;re widening access to a conversation that may be confidential.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What does BCC mean?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/blog/bcc-email&quot;&gt;&lt;u&gt;BCC&lt;/u&gt;&lt;/a&gt; stands for Blind Carbon Copy. It works like CC&amp;#8217;ing, without the visibility. The BCC function allows you to send copies of the same email to multiple people without revealing that they are part of a mass email, or revealing the other recipients’ email addresses or responses to your original email.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Another key difference: If you enter multiple contacts into the BCC field, when they respond it is only you who will receive their response email. It will not be received by any other BCC recipients.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;When to use BCC in email&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;BCC should be used whenever you need to send multiple people the same email, but you do not want them to know they are a part of a mass email or to be able to see the email addresses of the other recipients.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;BCC&amp;#8217;ing is useful for protecting the privacy of people who have given you their email address with the expectation that you will not share it without their permission. For example, when sending an update about your company to a mailing list, you should use the BCC function to ensure the individual recipients cannot see the addresses of everyone else who has signed up for that mailing list.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You can also BCC yourself when sending an email from a shared or generic team inbox, to keep a personal record of correspondence sent on your team&amp;#8217;s behalf.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;When not to use BCC in email&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;As with CC&amp;#8217;ing, be wary of BCC&amp;#8217;ing when your email contains sensitive information, or you suspect that the email thread resulting from your email will contain sensitive information.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Avoid using BCC in situations where transparency matters. Covertly adding someone to the conversation can damage trust if it surfaces and be considered a breach of &lt;a href=&quot;https://proton.me/business/blog/email-etiquette&quot;&gt;email etiquette&lt;/a&gt;. It&amp;#8217;s better to CC them openly or send a separate note.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;BCC should not be used for ongoing conversations, such as an active back-and-forth negotiation or client conversation — where you expect whoever you&amp;#8217;ve BCC&amp;#8217;d in to be able to follow the whole conversation. Since BCC recipients are excluded from replies, this means cutting them out of exactly the conversation you wanted them to follow.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What’s the difference between To, CC, and BCC?&lt;/h2&gt;



&lt;figure class=&quot;wp-block-table&quot;&gt;&lt;table class=&quot;has-fixed-layout&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Feature&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;To&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;CC&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;BCC&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Role&amp;nbsp;&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;The intended main contact of the email.&amp;nbsp;&lt;/td&gt;&lt;td&gt;For people who need to stay in the loop.&amp;nbsp;&lt;/td&gt;&lt;td&gt;To include people without others knowing.&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Visibility&amp;nbsp;&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Visible to everyone.&amp;nbsp;&lt;/td&gt;&lt;td&gt;Visible to everyone.&amp;nbsp;&lt;/td&gt;&lt;td&gt;Hidden from all other recipients.&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Recipient Awareness&amp;nbsp;&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Everyone knows they are the main contact.&amp;nbsp;&lt;/td&gt;&lt;td&gt;Everyone knows who else is being kept informed.&amp;nbsp;&lt;/td&gt;&lt;td&gt;Only you and the BCC’d person know they are there.&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Reply All Behavior&amp;nbsp;&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Receives all replies.&amp;nbsp;&lt;/td&gt;&lt;td&gt;Receives all replies.&amp;nbsp;&lt;/td&gt;&lt;td&gt;Excluded from future &amp;#8220;Reply All&amp;#8221; threads.&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Expectation&amp;nbsp;&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Response expected.&lt;/td&gt;&lt;td&gt;For your information (FYI) only.&amp;nbsp;&lt;/td&gt;&lt;td&gt;Should not participate in the thread.&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Best For&amp;nbsp;&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Direct requests, tasks, and 1:1s.&amp;nbsp;&lt;/td&gt;&lt;td&gt;Transparency and team collaboration.&amp;nbsp;&lt;/td&gt;&lt;td&gt;Mass emails, privacy, and discreet oversight.&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/figure&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What happens when you hit reply or reply all?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Reply behavior can be confusing, especially when multiple recipients are involved. What happens depends on whether you choose Reply or Reply all.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Hitting Reply all when you intended to hit Reply can lead to internal asides and information leaking to clients, or to an entire distribution list being emailed by mistake. One wrong click can stifle your team’s productivity and even threaten your company’s reputation.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;If you are in the To or CC field:&lt;/strong&gt;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Clicking Reply sends your response only to the sender.&lt;/li&gt;



&lt;li&gt;Clicking Reply all sends your response to everyone in the To and CC fields.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;If you are in the BCC field:&lt;/strong&gt;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Clicking Reply sends your response only to the sender.&lt;/li&gt;



&lt;li&gt;Clicking Reply all sends your response to everyone in the To and CC fields, not to other BCC recipients — but you will reveal to them that you were BCC&amp;#8217;d  &lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;A better way to send group emails&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Although using the CC and BCC functions is the main way to send an email to multiple people, our encrypted email service &lt;a href=&quot;https://proton.me/business/mail&quot;&gt;&lt;u&gt;Proton Mail&lt;/u&gt;&lt;/a&gt; also lets you do this by putting multiple recipients in a contact group.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/support/contact-groups&quot;&gt;&lt;u&gt;Contact groups&lt;/u&gt;&lt;/a&gt; are useful for emailing multiple people who all know each other, especially if you regularly email them as a group. For example, a team sending weekly updates to stakeholders can save time by using a contact group instead of adding recipients manually every time.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Once you&amp;#8217;ve created a &lt;a href=&quot;https://proton.me/support/contact-groups&quot;&gt;&lt;u&gt;contact group&lt;/u&gt;&lt;/a&gt; in your Proton Mail account, you can email everyone in that group at once by typing the name of the contact group into the To field and selecting the contact group you want to mass-email from the autofill menu. This will enter all of the email addresses of the contacts in that group to the To field.&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-full&quot;&gt;&lt;img loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;300&quot; height=&quot;108&quot; src=&quot;https://pme.protonblog.tech/wp-content/uploads/2022/02/image-12.png&quot; alt=&quot;&quot; class=&quot;wp-post-10543 wp-image-245173&quot;/&gt;&lt;/figure&gt;



&lt;figure class=&quot;wp-block-image size-full&quot;&gt;&lt;img loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;300&quot; height=&quot;109&quot; src=&quot;https://pme.protonblog.tech/wp-content/uploads/2022/02/image-13.png&quot; alt=&quot;&quot; class=&quot;wp-post-10543 wp-image-245197&quot;/&gt;&lt;/figure&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When you email people who are in a contact group with each other, they can all see each other’s email addresses, although they will not know that you have put them in a contact group, and the name of that group won’t appear in their inboxes. If you don’t want the contacts in your contact group to know the other members’ addresses, you can enter the contact group into the BCC field instead.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Key takeaways on using CC and BCC in a professional setting&lt;/h2&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;To: is for the people expected to take action.&lt;/li&gt;



&lt;li&gt;CC (Carbon Copy): is for keeping people informed (FYI).&lt;/li&gt;



&lt;li&gt;BCC (Blind Carbon Copy): is for privacy (recipients are hidden from everyone else).&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How Proton Mail protects To, CC and BCC email messages&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Contact groups make CC and BCC quicker to use, but they don&amp;#8217;t make them any safer from interception by a third party. That&amp;#8217;s a different problem, and it&amp;#8217;s one Proton Mail&amp;#8217;s encryption can help with.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton Mail encrypts messages sent between Proton accounts with &lt;a href=&quot;https://proton.me/learn/encryption/types-of-encryption/what-is-end-to-end&quot;&gt;end-to-end encryption&lt;/a&gt;, and protects everything stored in your mailbox with &lt;a href=&quot;https://proton.me/learn/encryption/types-of-encryption/zero-access&quot;&gt;zero-access encryption&lt;/a&gt;, meaning even Proton can&amp;#8217;t read it — or decrypt it, even under compulsion from law enforcement. You can also add password protection to emails sent to non-Proton addresses, so they&amp;#8217;re encrypted too.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;None of this stops an email reaching the wrong person through a misplaced CC or BCC, and it doesn&amp;#8217;t change who can see whose address in a CC or BCC field.&amp;nbsp;That&amp;#8217;s still down to you using the fields correctly. What &lt;a href=&quot;https://proton.me/learn/encryption&quot;&gt;encryption&lt;/a&gt; does protect is the content of a CC&amp;#8217;d or BCC&amp;#8217;d business email in transit, so a client proposal or an internal aside can&amp;#8217;t be intercepted by a third party.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If your business regularly sends CC&amp;#8217;d and BCC&amp;#8217;d correspondence containing sensitive content like client proposals and internal decisions, Proton&amp;#8217;s &lt;a href=&quot;https://proton.me/business/mail&quot;&gt;&lt;/a&gt;&lt;a href=&quot;https://proton.me/business/mail&quot;&gt;&lt;u&gt;business email service&lt;/u&gt;&lt;/a&gt; applies that protection automatically, without your team having to think about it.&lt;/p&gt;



&lt;hr class=&quot;wp-block-separator has-alpha-channel-opacity&quot;/&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;FAQ&lt;/h2&gt;



&lt;div class=&quot;wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex&quot;&gt;
&lt;div class=&quot;wp-block-column is-layout-flow wp-block-column-is-layout-flow&quot; style=&quot;flex-basis:100%&quot;&gt;
&lt;div class=&quot;schema-faq wp-block-yoast-faq-block&quot;&gt;&lt;div class=&quot;schema-faq-section&quot; id=&quot;faq-question-1643737620478&quot;&gt;&lt;strong class=&quot;schema-faq-question&quot;&gt;Is BCC safer than CC?&lt;/strong&gt; &lt;p class=&quot;schema-faq-answer&quot;&gt;When it comes to protecting your contacts&amp;#8217; email addresses from your other contacts, BCC is safer than CC. With BCC, there is no way for a recipient to know that they are not the only recipient of an email (as long as all other recipients are marked BCC), let alone find out the email addresses of other recipients. For this reason, you should use BCC when you do not have permission to share a contact’s email address with anyone else.&lt;br&gt;It&amp;#8217;s important to note that neither CC nor BCC is safer when it comes to protecting your messages against interception by a third party. That protection only comes with encryption, not through your choice of field.&lt;br&gt;&lt;/p&gt; &lt;/div&gt; &lt;div class=&quot;schema-faq-section&quot; id=&quot;faq-question-1789131685714&quot;&gt;&lt;strong class=&quot;schema-faq-question&quot;&gt;&lt;strong&gt;Is it safe to CC or BCC sensitive business information?&lt;/strong&gt;&lt;/strong&gt; &lt;p class=&quot;schema-faq-answer&quot;&gt;This depends on who you send it to: the mechanisms don&amp;#8217;t protect you. CC and BCC control who receives a copy of an email, not what happens to it afterward. Anyone included in a CC or BCC field for a message can forward, screenshot, or store it. If you&amp;#8217;re sending confidential information, keep your recipient list as small as possible, and consider encrypting the message itself so the content stays protected even if it ends up somewhere you didn&amp;#8217;t intend.&lt;/p&gt; &lt;/div&gt; &lt;div class=&quot;schema-faq-section&quot; id=&quot;faq-question-1643737839389&quot;&gt;&lt;strong class=&quot;schema-faq-question&quot;&gt;Is it better to CC or BCC?&lt;/strong&gt; &lt;p class=&quot;schema-faq-answer&quot;&gt;If you want to maintain a conversation with all the original recipients of your email, it is better to use the CC function, so that all contacts who were initially included in the email receive all the responses. However, if it is important that your contacts’ email addresses are not exposed to each other, and they are not expected to continue an inclusive email chain, then you should use BCC to conceal your recipients’ contact information.&lt;/p&gt; &lt;/div&gt; &lt;div class=&quot;schema-faq-section&quot; id=&quot;faq-question-1643737864828&quot;&gt;&lt;strong class=&quot;schema-faq-question&quot;&gt;Can a CC’d person see BCC’d recipients?&lt;/strong&gt; &lt;p class=&quot;schema-faq-answer&quot;&gt;No. CC recipients cannot see the names or addresses of anyone who was included as a BCC on any original message. The only time the BCC recipients’ contact information will be exposed is if they respond to the email using “reply all”.&lt;/p&gt; &lt;/div&gt; &lt;div class=&quot;schema-faq-section&quot; id=&quot;faq-question-1785510331074&quot;&gt;&lt;strong class=&quot;schema-faq-question&quot;&gt;How is CC different from To?&lt;/strong&gt; &lt;p class=&quot;schema-faq-answer&quot;&gt;The To field should be used for the main recipient(s) of your email, who you expect to respond or take some kind of action after receiving your email. The main recipients will usually be the ones the email is addressed to in the salutation of your email.&lt;/p&gt; &lt;/div&gt; &lt;div class=&quot;schema-faq-section&quot; id=&quot;faq-question-1785510378759&quot;&gt;&lt;strong class=&quot;schema-faq-question&quot;&gt;Can you use CC and BCC at the same time?&lt;/strong&gt; &lt;p class=&quot;schema-faq-answer&quot;&gt;Yes. People in the To and CC fields can see each other, while BCC recipients are hidden from everyone else. BCC recipients can still see who is in the To and CC fields, but they do not receive replies from those recipients.&lt;/p&gt; &lt;/div&gt; &lt;div class=&quot;schema-faq-section&quot; id=&quot;faq-question-1789131855002&quot;&gt;&lt;strong class=&quot;schema-faq-question&quot;&gt;What happens if someone I BCC’d replies to all?&lt;/strong&gt; &lt;p class=&quot;schema-faq-answer&quot;&gt;Their reply is sent to the sender and everyone in the To and CC fields. Their address is still not shown as a BCC recipient, but the reply can reveal that they were included in the original email.&lt;/p&gt; &lt;/div&gt; &lt;div class=&quot;schema-faq-section&quot; id=&quot;faq-question-1785510387282&quot;&gt;&lt;strong class=&quot;schema-faq-question&quot;&gt;Can you tell if you were BCC’d on an email?&lt;/strong&gt; &lt;p class=&quot;schema-faq-answer&quot;&gt;Usually no. BCC recipients are hidden from other recipients. If you receive an email but your address does not appear in the To or CC fields, you were likely BCC’d.&lt;/p&gt; &lt;/div&gt; &lt;div class=&quot;schema-faq-section&quot; id=&quot;faq-question-1785510400942&quot;&gt;&lt;strong class=&quot;schema-faq-question&quot;&gt;Does CC or BCC affect email delivery?&lt;/strong&gt; &lt;p class=&quot;schema-faq-answer&quot;&gt;Not directly. However, sending emails to large numbers of recipients using CC or BCC can trigger spam filters. For large groups, it’s better to use a mailing list or newsletter service.&lt;/p&gt; &lt;/div&gt; &lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;/p&gt;
</content:encoded><category>For business</category><author>Alanna Alexander</author></item></channel></rss>