<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>The Proton Blog</title><description>News from the front lines of privacy and security</description><link>https://proton.me/</link><language>en</language><feed_url>https://proton.me/feed</feed_url><item><title>A Gmail scam is exploiting Google Account recovery emails</title><link>https://proton.me/blog/google-account-recovery-gmail-scam</link><guid isPermaLink="true">https://proton.me/blog/google-account-recovery-gmail-scam</guid><description>See how the Google Account recovery Gmail scam uses real security emails and a fake Google call to trick victims, and learn the warning signs.</description><pubDate>Fri, 04 Sep 2026 11:59:42 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;One morning in August, a member of our team answered a call from a California number.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The caller, polished and speaking with a flawless American accent, claimed to be from Google. An attempt had been made, the caller said, to change the account recovery address on the employee&amp;#8217;s &lt;a href=&quot;https://proton.me/blog/is-gmail-secure&quot;&gt;Gmail&lt;/a&gt; account, and an email about it was sitting in his inbox at that very moment.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Upon further investigation, however, our team member soon learned things were not as they seemed.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This was a &lt;a href=&quot;https://proton.me/blog/what-is-phishing&quot;&gt;phishing&lt;/a&gt; scam, and a more sophisticated form of &lt;a href=&quot;https://proton.me/blog/what-is-social-engineering&quot;&gt;social engineering&lt;/a&gt;. It used a carefully scripted conversation designed to build just enough trust that you believe the caller really is Google, ultimately persuading you to hand over some form of access.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Our colleague ended the call before reaching that moment, so the exact ask went unheard. But the structure of the scam tells you exactly where it was headed.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;a href=&quot;#how&quot;&gt;How this Google account recovery scam works&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#tells&quot;&gt;The tells, annotated&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#why&quot;&gt;Why this Gmail scam is so convincing&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#protect&quot;&gt;How to protect yourself from account takeover attempts&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#safer-inbox&quot;&gt;A safer inbox starts with better email security&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 id=&quot;how&quot; class=&quot;wp-block-heading&quot;&gt;How this Google account recovery scam works&lt;/h2&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;The setup&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Before the phone rings, the scammer creates a fresh, anonymous Gmail address, which consists of random letters and digits. Using Google&amp;#8217;s legitimate &amp;#8220;add a recovery email&amp;#8221; flow, they try to add the victim&amp;#8217;s address as the&amp;nbsp;recovery email for the scammer&amp;#8217;s own throwaway account.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;The first real email&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Google&amp;#8217;s system needs the victim&amp;#8217;s confirmation, so an authentic message arrives asking them to verify the recovery email. The sender, branding, and code are real.&amp;nbsp;&lt;em&gt;(Figure 1&lt;/em&gt; &lt;em&gt;below&lt;/em&gt;&lt;em&gt;)&lt;/em&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;The call&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The scammer makes a call, poses as a member of Google&amp;#8217;s security team, and describes a suspicious account access attempt that was supposedly blocked, even claiming to have intercepted the victim&amp;#8217;s &lt;a href=&quot;https://proton.me/authenticator&quot;&gt;authenticator&lt;/a&gt; code. The word &amp;#8220;blocked&amp;#8221; casts the caller as the hero. In reality, the attack&amp;nbsp;&lt;em&gt;is&lt;/em&gt;&amp;nbsp;the phone call.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;The second real email&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Still on the line, the victim receives a genuine &amp;#8220;Security alert&amp;#8221; announcing that a recovery email was changed on a linked &lt;a href=&quot;https://proton.me/blog/delete-gmail-account#delete-google-account&quot;&gt;Google Account&lt;/a&gt;. Skimmed, it looks like a compromise. Read carefully, the fine print reveals it&amp;#8217;s a copy of an alert sent to the&amp;nbsp;&lt;em&gt;scammer&amp;#8217;s&lt;/em&gt;&amp;nbsp;address.&amp;nbsp;&lt;em&gt;(Figure 2 below)&lt;/em&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;The vanishing act&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The first email offers a legitimate escape: removing your address from the stranger&amp;#8217;s account. But the moment our colleague hung up, the scammer withdrew the recovery request, erasing the trail, and likely moved on to the next target.&lt;/p&gt;



&lt;h2 id=&quot;tells&quot; class=&quot;wp-block-heading&quot;&gt;The tells, annotated&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Figure 1 shows the first Google email, which contains a security code needed to confirm your address as the recovery email for the scammer’s account.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full is-resized&quot;&gt;&lt;img width=&quot;1338&quot; height=&quot;2229&quot; data-public-id=&quot;wp-pme/google-account-recovery-gmail-scam-1/google-account-recovery-gmail-scam-1.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1338,h_2229,c_scale/f_auto,q_auto/v1788514992/wp-pme/google-account-recovery-gmail-scam-1/google-account-recovery-gmail-scam-1.png?_i=AA&quot; alt=&quot;A Google Account recovery email scam on Gmail, explained&quot; class=&quot;wp-post-280021 wp-image-280022&quot; style=&quot;width:500px;height:auto&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;390 KB&quot; data-optsize=&quot;73 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;81.3&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=280022&quot; data-version=&quot;1788514992&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1788514992/wp-pme/google-account-recovery-gmail-scam-1/google-account-recovery-gmail-scam-1.png?_i=AA 1338w, https://res.cloudinary.com/dbulfrlrz/images/w_180,h_300,c_scale/f_auto,q_auto/v1788514992/wp-pme/google-account-recovery-gmail-scam-1/google-account-recovery-gmail-scam-1.png?_i=AA 180w, https://res.cloudinary.com/dbulfrlrz/images/w_615,h_1024,c_scale/f_auto,q_auto/v1788514992/wp-pme/google-account-recovery-gmail-scam-1/google-account-recovery-gmail-scam-1.png?_i=AA 615w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_1279,c_scale/f_auto,q_auto/v1788514992/wp-pme/google-account-recovery-gmail-scam-1/google-account-recovery-gmail-scam-1.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_922,h_1536,c_scale/f_auto,q_auto/v1788514992/wp-pme/google-account-recovery-gmail-scam-1/google-account-recovery-gmail-scam-1.png?_i=AA 922w, https://res.cloudinary.com/dbulfrlrz/images/w_1229,h_2048,c_scale/f_auto,q_auto/v1788514992/wp-pme/google-account-recovery-gmail-scam-1/google-account-recovery-gmail-scam-1.png?_i=AA 1229w&quot; sizes=&quot;auto, (max-width: 1338px) 100vw, 1338px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;The genuine Google sender&lt;/strong&gt;&amp;nbsp;— real, which is precisely what makes it dangerous.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;&amp;#8220;Wants to use your email address as their recovery email&amp;#8221;&lt;/strong&gt;&amp;nbsp;— the reversed logic, as this is about someone else&amp;#8217;s account.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;The anonymous throwaway address&lt;/strong&gt;&amp;nbsp;— no way to verify who&amp;#8217;s behind it.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;The expiring code&lt;/strong&gt;&amp;nbsp;— manufactured urgency, keeping you stressed and compliant.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;&amp;#8220;Remove email&amp;#8221;&lt;/strong&gt;&amp;nbsp;— the one action that stops it, and exactly what the scammer cancels when you hang up.&lt;/li&gt;
&lt;/ol&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Figure 2 shows how a genuine Google security alert can appear alarming at first.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full is-resized&quot;&gt;&lt;img width=&quot;1318&quot; height=&quot;2229&quot; data-public-id=&quot;wp-pme/google-account-recovery-gmail-scam-2/google-account-recovery-gmail-scam-2.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1318,h_2229,c_scale/f_auto,q_auto/v1788515000/wp-pme/google-account-recovery-gmail-scam-2/google-account-recovery-gmail-scam-2.png?_i=AA&quot; alt=&quot;A Google Account security alert scam on Gmail, explained&quot; class=&quot;wp-post-280021 wp-image-280046&quot; style=&quot;width:500px;height:auto&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;391 KB&quot; data-optsize=&quot;76 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;80.5&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=280046&quot; data-version=&quot;1788515000&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1788515000/wp-pme/google-account-recovery-gmail-scam-2/google-account-recovery-gmail-scam-2.png?_i=AA 1318w, https://res.cloudinary.com/dbulfrlrz/images/w_177,h_300,c_scale/f_auto,q_auto/v1788515000/wp-pme/google-account-recovery-gmail-scam-2/google-account-recovery-gmail-scam-2.png?_i=AA 177w, https://res.cloudinary.com/dbulfrlrz/images/w_605,h_1024,c_scale/f_auto,q_auto/v1788515000/wp-pme/google-account-recovery-gmail-scam-2/google-account-recovery-gmail-scam-2.png?_i=AA 605w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_1299,c_scale/f_auto,q_auto/v1788515000/wp-pme/google-account-recovery-gmail-scam-2/google-account-recovery-gmail-scam-2.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_908,h_1536,c_scale/f_auto,q_auto/v1788515000/wp-pme/google-account-recovery-gmail-scam-2/google-account-recovery-gmail-scam-2.png?_i=AA 908w, https://res.cloudinary.com/dbulfrlrz/images/w_1211,h_2048,c_scale/f_auto,q_auto/v1788515000/wp-pme/google-account-recovery-gmail-scam-2/google-account-recovery-gmail-scam-2.png?_i=AA 1211w&quot; sizes=&quot;auto, (max-width: 1318px) 100vw, 1318px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;The subject addresses the scammer&amp;#8217;s inbox, not yours&lt;/strong&gt;&amp;nbsp;— the first sign this alert isn&amp;#8217;t about you.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;&amp;#8220;A copy of a security alert sent to&amp;#8221; the throwaway address&lt;/strong&gt;&amp;nbsp;— the biggest tell, and the easiest to miss on a skim.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;The alarming headline&lt;/strong&gt;&amp;nbsp;— designed to scare before you read the fine print.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;&amp;#8220;If you didn&amp;#8217;t change it, check what happened&amp;#8221;&lt;/strong&gt;&amp;nbsp;— planted doubt that primes you to trust the caller.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;The &amp;#8220;Check activity&amp;#8221; button&lt;/strong&gt;&amp;nbsp;— a prompt to act fast instead of read carefully.&lt;/li&gt;
&lt;/ol&gt;



&lt;h2 id=&quot;why&quot; class=&quot;wp-block-heading&quot;&gt;Why this Gmail scam is so convincing&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Both &lt;a href=&quot;https://proton.me/business/mail/phishing-email&quot;&gt;phishing emails&lt;/a&gt; come from Google&amp;#8217;s real servers, so every conventional anti-phishing check passes.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Each element corroborates the others: real notifications, plus a caller who knows exactly what just landed in your inbox. At the same time, the conversation can discourage any attempt you may have to click &amp;#8220;Remove email&amp;#8221;, keeping you focused on the caller&amp;#8217;s instructions.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A &lt;a href=&quot;https://proton.me/blog/google-data-breach-gmail-warning&quot;&gt;Google data breach&lt;/a&gt; can make scams like this more convincing if exposed information gives attackers details they can use to personalize &lt;a href=&quot;https://proton.me/business/blog/vishing-attacks-business&quot;&gt;vishing&lt;/a&gt; or &lt;a href=&quot;https://proton.me/business/blog/phishing-attacks&quot;&gt;phishing attacks&lt;/a&gt;. Even when passwords aren’t leaked, names, contact details, or account-related information can help scammers sound more credible and build trust.&lt;/p&gt;



&lt;h2 id=&quot;protect&quot; class=&quot;wp-block-heading&quot;&gt;How to protect yourself from account takeover attempts&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You can protect yourself by slowing the interaction down and verifying what’s happening through Google directly:&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Hang up and verify independently.&lt;/strong&gt; If someone calls claiming to be from Google, end the call and check your account directly rather than following their instructions.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Read Google security emails carefully.&lt;/strong&gt; Pay attention to which account the alert actually refers to, especially any line saying the message is a copy of an alert sent to another address.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Do not share verification codes.&lt;/strong&gt; Google will not need you to read out an authenticator code, recovery code, or other sign-in credential over the phone.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Use “Remove email” if you do not recognize the account.&lt;/strong&gt; If Google says someone wants to use your address as their recovery email, remove it from that account.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Do not let the caller rush you.&lt;/strong&gt; Scammers rely on urgency to keep you reacting instead of checking what the notification actually says.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Review your Google Account security directly.&lt;/strong&gt; Open your account settings yourself and check recent activity, signed-in devices, recovery details, and security alerts.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Report suspicious calls and messages.&lt;/strong&gt; Reporting the attempt can help Google and your phone provider identify repeated abuse.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Review your&lt;/strong&gt; &lt;a href=&quot;https://proton.me/blog/google-privacy-settings&quot;&gt;&lt;strong&gt;Google privacy settings&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;.&lt;/strong&gt; While privacy settings won’t stop this particular scam, regularly checking what data you share and which apps and services have access to your Google Account can reduce your exposure.&lt;/p&gt;



&lt;h2 id=&quot;safer-inbox&quot; class=&quot;wp-block-heading&quot;&gt;A safer inbox starts with better email security&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Scams like this are a reminder that even legitimate security emails can be turned into tools for social engineering. Staying skeptical of unexpected calls, checking account activity independently, and reading alerts carefully can help you avoid falling for them.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Looking for a better &lt;a href=&quot;https://proton.me/mail/best-gmail-alternative&quot;&gt;alternative to Gmail&lt;/a&gt;? Proton Mail gives you a &lt;a href=&quot;https://proton.me/mail/&quot;&gt;secure email&lt;/a&gt; service built around protecting your data and communications with &lt;a href=&quot;https://proton.me/learn/encryption/types-of-encryption/what-is-end-to-end&quot;&gt;end-to-end&lt;/a&gt; and &lt;a href=&quot;https://proton.me/learn/encryption/types-of-encryption/zero-access&quot;&gt;zero-access encryption&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If someone tries a similar scam while pretending to be Proton, there’s a simple rule to remember: &lt;a href=&quot;https://proton.me/support/scam-call-alert&quot;&gt;Proton will never call you&lt;/a&gt; about an account security issue. You can protect your account from takeover by enabling &lt;a href=&quot;https://proton.me/support/two-factor-authentication-2fa&quot;&gt;two-factor authentication&lt;/a&gt;. On paid plans, &lt;a href=&quot;https://proton.me/support/proton-sentinel&quot;&gt;Proton Sentinel&lt;/a&gt; combines automated detection with human security analysis.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton Mail also includes protections against more conventional phishing attempts, such as &lt;a href=&quot;https://proton.me/blog/cloud-storage-email-scam&quot;&gt;cloud storage email scams&lt;/a&gt;. PhishGuard blocks and flags suspected phishing emails, while &lt;a href=&quot;https://proton.me/support/link-confirmation&quot;&gt;link confirmation&lt;/a&gt; prompts you to verify before opening external links from an email.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;No email service can provide perfect protection against &lt;a href=&quot;https://proton.me/business/blog/account-takeover-attacks&quot;&gt;account takeover&lt;/a&gt;. However, if someone does manage to break into your Proton account using email or SMS recovery, they won&amp;#8217;t automatically gain access to your emails and contacts, thanks to &lt;a href=&quot;https://proton.me/support/set-account-recovery-methods&quot;&gt;separate data recovery protections&lt;/a&gt;.&lt;/p&gt;
</content:encoded><category>News</category><author>Edward Komenda</author></item><item><title>Amazon is tracking you.  Here&amp;#8217;s how to stop it and what to use instead.</title><link>https://proton.me/blog/how-amazon-tracks-you</link><guid isPermaLink="true">https://proton.me/blog/how-amazon-tracks-you</guid><description>Reduce Amazon tracking by understanding what data it collects across shopping, Alexa, Ring, Kindle, Whole Foods, and AWS.</description><pubDate>Tue, 01 Sep 2026 18:58:04 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Amazon has the resources to know a lot about you: what you buy, what you watch, what you read, when you’re home, what you ask your voice assistant, what you eat, what websites and apps you use.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The sheer breadth of Amazon’s ecosystem sets it apart.&amp;nbsp;It has woven itself into everyday life through online shopping, a streaming service and devices, e-readers home security cameras, smart speakers, grocery services, and other businesses that span entertainment, retail and gaming.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Individually, each of these products and services collect data to deliver what you&amp;#8217;ve signed up for. Together, however, they create a remarkably detailed picture of your daily habits.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;And the more you use Amazon, the easier it becomes for it to collect even more information about you.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The good news is that reducing Amazon&amp;#8217;s knowledge about you doesn&amp;#8217;t require giving up online shopping. In many cases, altering a few privacy settings can limit the amount of data that&amp;#8217;s collected. In others, choosing different services or devices can give you greater control over where your information is stored and who has access to it.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In this guide, we’ll walk you through Amazon&amp;#8217;s ecosystem and explain what data each service collects, why it matters, and the practical steps you can take to keep more of your personal information to yourself.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;a href=&quot;#how-amazon-tracks-your-shopping-habits&quot; data-type=&quot;internal&quot; data-id=&quot;#how-amazon-tracks-your-shopping-habits&quot;&gt;How Amazon tracks your shopping habits&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#how-ring-cameras-collect-and-share-your-data&quot; data-type=&quot;internal&quot; data-id=&quot;#how-ring-cameras-collect-and-share-your-data&quot;&gt;How Ring cameras collect and share your data&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#how-fire-tv-kindle-track-what-you-watch-read&quot; data-type=&quot;internal&quot; data-id=&quot;#how-fire-tv-kindle-track-what-you-watch-read&quot;&gt;How Fire TV and Kindle track what you watch and read&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#how-alexa-collects-and-uses-your-voice-data&quot; data-type=&quot;internal&quot; data-id=&quot;#how-alexa-collects-and-uses-your-voice-data&quot;&gt;How Alexa collects and uses your voice data&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#amazon-companies-collecting-data&quot; data-type=&quot;internal&quot; data-id=&quot;#amazon-companies-collecting-data&quot;&gt;Amazon-owned companies you may not realize are collecting your data&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#what-is-amazon-web-services&quot; data-type=&quot;internal&quot; data-id=&quot;#what-is-amazon-web-services&quot;&gt;What is Amazon Web Services (AWS), and why does it matter?&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#how-to-reduce-amazon-tracking&quot; data-type=&quot;internal&quot; data-id=&quot;#how-to-reduce-amazon-tracking&quot;&gt;How to reduce Amazon&amp;#8217;s tracking without giving up convenience&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;



&lt;figure class=&quot;wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio&quot;&gt;&lt;div class=&quot;wp-block-embed__wrapper&quot;&gt;
&lt;iframe loading=&quot;lazy&quot; title=&quot;All the ways Amazon Tracks You and How to Stop It&quot; width=&quot;750&quot; height=&quot;422&quot; src=&quot;https://www.youtube-nocookie.com/embed/AzJDM_Gkf_g?feature=oembed&quot; frameborder=&quot;0&quot; allow=&quot;accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share&quot; referrerpolicy=&quot;strict-origin-when-cross-origin&quot; allowfullscreen&gt;&lt;/iframe&gt;
&lt;/div&gt;&lt;/figure&gt;



&lt;h2 id=&quot;how-amazon-tracks-your-shopping-habits&quot; class=&quot;wp-block-heading&quot;&gt;How Amazon tracks your shopping habits&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Over 150 million Americans shop on Amazon every year. The company accounts for roughly &lt;a href=&quot;https://capitaloneshopping.com/research/amazon-orders-per-day/&quot;&gt;&lt;u&gt;40% of all U.S. retail e-commerce sales&lt;/u&gt;&lt;/a&gt;, giving the company a detailed view of millions of shoppers&amp;#8217; everyday lives.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Orders for baby products may indicate a growing family. Fitness equipment and supplements can hint at health goals. Gardening tools, pet supplies, kitchen appliances, books, and electronics all contribute to a profile of your interests and lifestyle.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Amazon Prime goes a step further. Because Prime encourages customers to centralize their shopping, streaming, reading, and music subscriptions under a single account, Amazon gains additional context on how you spend your time. Watching movies on Prime Video, listening to Amazon Music, or reading books on a Kindle paint a picture of your customer profile and can also reveal how often you&amp;#8217;re home or how regularly you shop.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;To be fair, data collection is common across e-commerce retailers. Every online retailer collects some information about its customers. To process an order, a company may need your name, shipping address, payment details, and contact information. It may also record your IP address, browser type, device identifiers, and the products you&amp;#8217;ve viewed or purchased.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;But privacy advocates have raised concerns about how Amazon handles customer information. A report by &lt;a href=&quot;https://www.wired.com/story/amazon-failed-to-protect-your-data-investigation/&quot;&gt;&lt;u&gt;W&lt;/u&gt;&lt;/a&gt;IRED described how some Amazon employees improperly accessed customer order histories. It also said that it wasn&amp;#8217;t uncommon for employees to look up the purchase histories of acquaintances.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;How to protect yourself &lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You don&amp;#8217;t have to stop using Amazon to limit its data collection. Review your Amazon privacy settings. (Instructions are below.) Disable browsing history if you don&amp;#8217;t want products you have viewed to influence recommendations, and opt out of interest-based advertising where available.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Avoid using &amp;#8220;Login with Amazon&amp;#8221; to sign in to third-party websites, which allows Amazon to become part of your activity outside its own platform.&lt;/li&gt;
&lt;/ul&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full&quot;&gt;&lt;img width=&quot;321&quot; height=&quot;73&quot; data-public-id=&quot;wp-pme/amazon-button/amazon-button.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_321,h_73,c_scale/f_auto,q_auto/v1788267694/wp-pme/amazon-button/amazon-button.png?_i=AA&quot; alt=&quot;Login with Amazon button&quot; class=&quot;wp-post-277720 wp-image-278972&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;10 KB&quot; data-optsize=&quot;5 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;45.9&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=278972&quot; data-version=&quot;1788267694&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1788267694/wp-pme/amazon-button/amazon-button.png?_i=AA 321w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_68,c_scale/f_auto,q_auto/v1788267694/wp-pme/amazon-button/amazon-button.png?_i=AA 300w&quot; sizes=&quot;auto, (max-width: 321px) 100vw, 321px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Consider whether every purchase needs to go through Amazon. Buying directly from manufacturers, supporting independent retailers, or using specialized stores for books, electronics, and household goods helps spread your digital footprint instead of concentrating it in a single ecosystem. While no retailer is completely anonymous, reducing your reliance on any one platform makes it harder for a single company to build a profile of you.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;To &lt;strong&gt;remove access&lt;/strong&gt;, go to Your Account and click &lt;strong&gt;Remove&lt;/strong&gt; next to any third-party app or site you no longer want connected to your account.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full&quot;&gt;&lt;img width=&quot;964&quot; height=&quot;543&quot; data-public-id=&quot;wp-pme/amazon-remove-access-1/amazon-remove-access-1.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_964,h_543,c_scale/f_auto,q_auto/v1788267971/wp-pme/amazon-remove-access-1/amazon-remove-access-1.png?_i=AA&quot; alt=&quot;Amazon remove access 1&quot; class=&quot;wp-post-277720 wp-image-278996&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;202 KB&quot; data-optsize=&quot;33 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;83.5&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=278996&quot; data-version=&quot;1788267971&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1788267971/wp-pme/amazon-remove-access-1/amazon-remove-access-1.png?_i=AA 964w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_169,c_scale/f_auto,q_auto/v1788267971/wp-pme/amazon-remove-access-1/amazon-remove-access-1.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_433,c_scale/f_auto,q_auto/v1788267971/wp-pme/amazon-remove-access-1/amazon-remove-access-1.png?_i=AA 768w&quot; sizes=&quot;auto, (max-width: 964px) 100vw, 964px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;From your &lt;strong&gt;Browsing History&lt;/strong&gt; page, click the &lt;strong&gt;settings icon&lt;/strong&gt; in the top-right corner to open more options.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full&quot;&gt;&lt;img width=&quot;967&quot; height=&quot;535&quot; data-public-id=&quot;wp-pme/amazon-browsing-history-more-settings/amazon-browsing-history-more-settings.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_967,h_535,c_scale/f_auto,q_auto/v1788268391/wp-pme/amazon-browsing-history-more-settings/amazon-browsing-history-more-settings.png?_i=AA&quot; alt=&quot;amazon browsing history more settings&quot; class=&quot;wp-post-277720 wp-image-279022&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;399 KB&quot; data-optsize=&quot;61 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;84.8&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=279022&quot; data-version=&quot;1788268391&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1788268391/wp-pme/amazon-browsing-history-more-settings/amazon-browsing-history-more-settings.png?_i=AA 967w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_166,c_scale/f_auto,q_auto/v1788268391/wp-pme/amazon-browsing-history-more-settings/amazon-browsing-history-more-settings.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_425,c_scale/f_auto,q_auto/v1788268391/wp-pme/amazon-browsing-history-more-settings/amazon-browsing-history-more-settings.png?_i=AA 768w&quot; sizes=&quot;auto, (max-width: 967px) 100vw, 967px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;Selecting &lt;strong&gt;More settings&lt;/strong&gt; opens additional privacy controls.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full&quot;&gt;&lt;img width=&quot;968&quot; height=&quot;545&quot; data-public-id=&quot;wp-pme/amazon-more-settings/amazon-more-settings.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_968,h_545,c_scale/f_auto,q_auto/v1788268594/wp-pme/amazon-more-settings/amazon-more-settings.png?_i=AA&quot; alt=&quot;Amazon more settings&quot; class=&quot;wp-post-277720 wp-image-279046&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;347 KB&quot; data-optsize=&quot;52 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;85.2&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=279046&quot; data-version=&quot;1788268594&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1788268594/wp-pme/amazon-more-settings/amazon-more-settings.png?_i=AA 968w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_169,c_scale/f_auto,q_auto/v1788268594/wp-pme/amazon-more-settings/amazon-more-settings.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_432,c_scale/f_auto,q_auto/v1788268594/wp-pme/amazon-more-settings/amazon-more-settings.png?_i=AA 768w&quot; sizes=&quot;auto, (max-width: 968px) 100vw, 968px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;From there, click the &lt;strong&gt;Browsing History toggle&lt;/strong&gt; to turn it off.&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-full&quot;&gt;&lt;img width=&quot;967&quot; height=&quot;544&quot; data-public-id=&quot;wp-pme/amazon-browsing-history-toggle/amazon-browsing-history-toggle.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_967,h_544,c_scale/f_auto,q_auto/v1788268844/wp-pme/amazon-browsing-history-toggle/amazon-browsing-history-toggle.png?_i=AA&quot; alt=&quot;Amazon browsing history toggle&quot; class=&quot;wp-post-277720 wp-image-279070&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;363 KB&quot; data-optsize=&quot;51 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;85.9&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=279070&quot; data-version=&quot;1788268844&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1788268844/wp-pme/amazon-browsing-history-toggle/amazon-browsing-history-toggle.png?_i=AA 967w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_169,c_scale/f_auto,q_auto/v1788268844/wp-pme/amazon-browsing-history-toggle/amazon-browsing-history-toggle.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_432,c_scale/f_auto,q_auto/v1788268844/wp-pme/amazon-browsing-history-toggle/amazon-browsing-history-toggle.png?_i=AA 768w&quot; sizes=&quot;auto, (max-width: 967px) 100vw, 967px&quot; /&gt;&lt;/figure&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Next, in &lt;strong&gt;Advertising Privacy and Preferences&lt;/strong&gt;, select “&lt;strong&gt;Do not show me interest-based ads provided by Amazon&lt;/strong&gt;” and click &lt;strong&gt;Submit&lt;/strong&gt;.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full&quot;&gt;&lt;img width=&quot;965&quot; height=&quot;515&quot; data-public-id=&quot;wp-pme/screenshot-2026-09-01-at-6-39-25-am/screenshot-2026-09-01-at-6-39-25-am.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_965,h_515,c_scale/f_auto,q_auto/v1788270067/wp-pme/screenshot-2026-09-01-at-6-39-25-am/screenshot-2026-09-01-at-6-39-25-am.png?_i=AA&quot; alt=&quot;advertising and privacy preferences&quot; class=&quot;wp-post-277720 wp-image-279094&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;184 KB&quot; data-optsize=&quot;30 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;83.5&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=279094&quot; data-version=&quot;1788270067&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1788270067/wp-pme/screenshot-2026-09-01-at-6-39-25-am/screenshot-2026-09-01-at-6-39-25-am.png?_i=AA 965w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_160,c_scale/f_auto,q_auto/v1788270067/wp-pme/screenshot-2026-09-01-at-6-39-25-am/screenshot-2026-09-01-at-6-39-25-am.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_410,c_scale/f_auto,q_auto/v1788270067/wp-pme/screenshot-2026-09-01-at-6-39-25-am/screenshot-2026-09-01-at-6-39-25-am.png?_i=AA 768w&quot; sizes=&quot;auto, (max-width: 965px) 100vw, 965px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;Clicking &lt;strong&gt;Delete ad data&lt;/strong&gt; removes your personal information from Amazon’s advertising systems.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full&quot;&gt;&lt;img width=&quot;870&quot; height=&quot;487&quot; data-public-id=&quot;wp-pme/screenshot-2026-09-01-at-7-11-12-am/screenshot-2026-09-01-at-7-11-12-am.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_870,h_487,c_scale/f_auto,q_auto/v1788271898/wp-pme/screenshot-2026-09-01-at-7-11-12-am/screenshot-2026-09-01-at-7-11-12-am.png?_i=AA&quot; alt=&quot;delete data&quot; class=&quot;wp-post-277720 wp-image-279120&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;154 KB&quot; data-optsize=&quot;28 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;82.1&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=279120&quot; data-version=&quot;1788271898&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1788271898/wp-pme/screenshot-2026-09-01-at-7-11-12-am/screenshot-2026-09-01-at-7-11-12-am.png?_i=AA 870w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_168,c_scale/f_auto,q_auto/v1788271898/wp-pme/screenshot-2026-09-01-at-7-11-12-am/screenshot-2026-09-01-at-7-11-12-am.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_430,c_scale/f_auto,q_auto/v1788271898/wp-pme/screenshot-2026-09-01-at-7-11-12-am/screenshot-2026-09-01-at-7-11-12-am.png?_i=AA 768w&quot; sizes=&quot;auto, (max-width: 870px) 100vw, 870px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;h2 id=&quot;how-ring-cameras-collect-and-share-your-data&quot; class=&quot;wp-block-heading&quot;&gt;How Ring cameras collect and share your data&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Video doorbells have become one of the most popular smart home devices on the market, and Amazon’s Ring has played a major role in that growth. Being able to see who&amp;#8217;s at your door, receive motion alerts while you&amp;#8217;re away, and review recorded footage can be useful and convenient.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;But these features also rely on cameras that are constantly monitoring the area around your home and, in many cases, uploading footage to the cloud.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Ring has expanded its &lt;a href=&quot;https://techcrunch.com/2025/12/09/amazons-ring-rolls-out-controversial-ai-powered-facial-recognition-feature-to-video-doorbells/&quot;&gt;&lt;u&gt;AI-powered features&lt;/u&gt;&lt;/a&gt;. New tools such as facial recognition and features that can help &lt;a href=&quot;https://www.popsci.com/diy/how-to-turn-off-ring-search-party/&quot;&gt;&lt;u&gt;locate lost pets&lt;/u&gt;&lt;/a&gt; aim to make neighborhood security more collaborative. However, these systems work by analyzing and sharing more visual data than traditional security cameras. Some of these features are enabled by default, meaning users may participate without fully understanding what information is being collected or how it&amp;#8217;s used.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Ring has faced criticism over its own security. In 2019, attackers gained access to thousands of Ring accounts by using stolen credentials from unrelated data breaches and were able to view live camera feeds and &lt;a href=&quot;https://www.wfaa.com/article/news/hacker-says-pay-bitcoin-ransom-or-get-terminated-through-couples-ring-security-cameras/287-226c535c-c765-4b29-91b6-d849fb315e94&quot;&gt;&lt;u&gt;speak through the devices&lt;/u&gt;&lt;/a&gt;&amp;#8216; &lt;a href=&quot;https://www.wfaa.com/article/news/hacker-says-pay-bitcoin-ransom-or-get-terminated-through-couples-ring-security-cameras/287-226c535c-c765-4b29-91b6-d849fb315e94&quot;&gt;&lt;u&gt;built-in microphones&lt;/u&gt;&lt;/a&gt;. The incident highlighted the importance of using unique passwords and enabling two-factor authentication.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Ring has also been criticized for sharing footage with law enforcement without a warrant. The company says it complies with legal requests and emergencies, but reports have shown that video footage has been &lt;a href=&quot;https://theintercept.com/2022/07/13/amazon-ring-camera-footage-police-ed-markey/&quot;&gt;&lt;u&gt;provided to police&lt;/u&gt;&lt;/a&gt; without a warrant or the user&amp;#8217;s explicit permission. For privacy-conscious users, this raises important questions about who ultimately controls cloud-stored recordings.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;How to protect yourself &lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you own a Ring device, disable features such as Search Party, Community Requests, and any optional marketing or analytics sharing if you don&amp;#8217;t intend to use them. Enable end-to-end encryption where supported to better protect recordings in transit, and configure privacy zones so your camera avoids capturing public footpaths or neighboring properties whenever possible. (See instructions below.)&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you&amp;#8217;re shopping for a new security camera, consider devices that prioritize local storage over cloud storage. Cameras that support recording directly to an SD card or network video recorder (NVR) reduce your dependence on a manufacturer&amp;#8217;s servers. Brands like &lt;a href=&quot;https://reolink.com/&quot;&gt;&lt;strong&gt;Reolink&lt;/strong&gt;&lt;/a&gt; offer cameras built around this local-first approach.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Support for standards such as Real-Time Streaming Protocol (RTSP) and Open Network Video Interface Forum (ONVIF) also makes it easier to integrate cameras into your own home network without relying exclusively on proprietary cloud services.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Ultimately, no internet-connected camera can guarantee complete privacy. But by understanding where your footage is stored, who can access it, and which features you&amp;#8217;ve enabled, you can make more informed decisions about the trade-offs between convenience and control.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In the Ring app, open &lt;strong&gt;Control Centre&lt;/strong&gt; and tap &lt;strong&gt;Amazon Account Linking&lt;/strong&gt;.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full&quot;&gt;&lt;img width=&quot;266&quot; height=&quot;584&quot; data-public-id=&quot;wp-pme/ring-control-center/ring-control-center.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_266,h_584,c_scale/f_auto,q_auto/v1788272599/wp-pme/ring-control-center/ring-control-center.png?_i=AA&quot; alt=&quot;Ring control center&quot; class=&quot;wp-post-277720 wp-image-279146&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;63 KB&quot; data-optsize=&quot;16 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;74.3&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=279146&quot; data-version=&quot;1788272599&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1788272599/wp-pme/ring-control-center/ring-control-center.png?_i=AA 266w, https://res.cloudinary.com/dbulfrlrz/images/w_137,h_300,c_scale/f_auto,q_auto/v1788272599/wp-pme/ring-control-center/ring-control-center.png?_i=AA 137w&quot; sizes=&quot;auto, (max-width: 266px) 100vw, 266px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;Click &lt;strong&gt;Unlink&lt;/strong&gt; next to Other Amazon Services.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full&quot;&gt;&lt;img width=&quot;264&quot; height=&quot;479&quot; data-public-id=&quot;wp-pme/ring-unlink/ring-unlink.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_264,h_479,c_scale/f_auto,q_auto/v1788272658/wp-pme/ring-unlink/ring-unlink.png?_i=AA&quot; alt=&quot;ring unlink&quot; class=&quot;wp-post-277720 wp-image-279170&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;44 KB&quot; data-optsize=&quot;11 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;75.5&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=279170&quot; data-version=&quot;1788272658&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1788272658/wp-pme/ring-unlink/ring-unlink.png?_i=AA 264w, https://res.cloudinary.com/dbulfrlrz/images/w_165,h_300,c_scale/f_auto,q_auto/v1788272658/wp-pme/ring-unlink/ring-unlink.png?_i=AA 165w&quot; sizes=&quot;auto, (max-width: 264px) 100vw, 264px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;Enter your Ring account password and tap &lt;strong&gt;Unlink Accounts&lt;/strong&gt; to confirm.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full&quot;&gt;&lt;img width=&quot;267&quot; height=&quot;565&quot; data-public-id=&quot;wp-pme/ring-unlink-2/ring-unlink-2.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_267,h_565,c_scale/f_auto,q_auto/v1788272804/wp-pme/ring-unlink-2/ring-unlink-2.png?_i=AA&quot; alt=&quot;ring unlink 2&quot; class=&quot;wp-post-277720 wp-image-279218&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;75 KB&quot; data-optsize=&quot;16 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;79&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=279218&quot; data-version=&quot;1788272804&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1788272804/wp-pme/ring-unlink-2/ring-unlink-2.png?_i=AA 267w, https://res.cloudinary.com/dbulfrlrz/images/w_142,h_300,c_scale/f_auto,q_auto/v1788272804/wp-pme/ring-unlink-2/ring-unlink-2.png?_i=AA 142w&quot; sizes=&quot;auto, (max-width: 267px) 100vw, 267px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;To limit analytics sharing, go to &lt;strong&gt;Privacy Information&lt;/strong&gt; in the Ring app menu and tap &lt;strong&gt;Cookies and Third-party Service Providers&lt;/strong&gt;.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full&quot;&gt;&lt;img width=&quot;267&quot; height=&quot;490&quot; data-public-id=&quot;wp-pme/cookies-and-third-part-service-providers/cookies-and-third-part-service-providers.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_267,h_490,c_scale/f_auto,q_auto/v1788272876/wp-pme/cookies-and-third-part-service-providers/cookies-and-third-part-service-providers.png?_i=AA&quot; alt=&quot;cookies and third part service providers&quot; class=&quot;wp-post-277720 wp-image-279242&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;64 KB&quot; data-optsize=&quot;17 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;73.5&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=279242&quot; data-version=&quot;1788272876&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1788272876/wp-pme/cookies-and-third-part-service-providers/cookies-and-third-part-service-providers.png?_i=AA 267w, https://res.cloudinary.com/dbulfrlrz/images/w_163,h_300,c_scale/f_auto,q_auto/v1788272876/wp-pme/cookies-and-third-part-service-providers/cookies-and-third-part-service-providers.png?_i=AA 163w&quot; sizes=&quot;auto, (max-width: 267px) 100vw, 267px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Toggling off Third-party Web and App Analytics Cookies&lt;/strong&gt; opts you out of third-party analytics tracking.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full&quot;&gt;&lt;img width=&quot;268&quot; height=&quot;573&quot; data-public-id=&quot;wp-pme/third-party-web-cookies/third-party-web-cookies.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_268,h_573,c_scale/f_auto,q_auto/v1788272940/wp-pme/third-party-web-cookies/third-party-web-cookies.png?_i=AA&quot; alt=&quot;third party web cookies&quot; class=&quot;wp-post-277720 wp-image-279266&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;88 KB&quot; data-optsize=&quot;19 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;77.7&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=279266&quot; data-version=&quot;1788272940&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1788272940/wp-pme/third-party-web-cookies/third-party-web-cookies.png?_i=AA 268w, https://res.cloudinary.com/dbulfrlrz/images/w_140,h_300,c_scale/f_auto,q_auto/v1788272940/wp-pme/third-party-web-cookies/third-party-web-cookies.png?_i=AA 140w&quot; sizes=&quot;auto, (max-width: 268px) 100vw, 268px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;h2 id=&quot;how-fire-tv-kindle-track-what-you-watch-read&quot; class=&quot;wp-block-heading&quot;&gt;How Fire TV and Kindle track what you watch and read&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When you&amp;#8217;re reading on your Kindle or streaming through &lt;a href=&quot;https://protonvpn.com/support/firestick&quot;&gt;&lt;u&gt;Fire TV&lt;/u&gt;&lt;/a&gt;, Amazon is also collecting information about you.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Kindle devices, for example, record more than the books you purchase. Depending on your settings and how you use the device, Amazon may also collect your reading progress, the amount of time you spend reading, the passages you highlight, the notes you make, and the words you look up in the built-in dictionary.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Fire TV knows how you use the device, what apps you open, what content you watch, and what you search for. It also supports Automatic Content Recognition (ACR), a technology that identifies what&amp;#8217;s being displayed on your screen by taking hundreds of screenshots of your viewing behavior in an effort to support targeted advertising.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The challenge is that even if you replace your streaming device, your television itself may still collect similar information if it&amp;#8217;s connected to the internet.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;How to protect yourself&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If privacy is your priority, start by reviewing your Fire TV privacy settings and disabling any optional data collection or interest-based advertising. You can also reduce data collection by keeping your television offline and using a dedicated streaming device instead. If you&amp;#8217;d rather reduce tracking, &lt;a href=&quot;https://protonvpn.com/download-appletv&quot;&gt;&lt;u&gt;Apple TV&lt;/u&gt;&lt;/a&gt; collects less viewing data than many of its competitors . Likewise, Kobo e-readers paired with Calibre offer a way to build a digital library without relying entirely on Amazon&amp;#8217;s ecosystem.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;No connected entertainment device is completely private. However, understanding which device is collecting your data can significantly reduce how much information is shared while still letting you enjoy your favorite books, films, and TV shows.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-large&quot;&gt;&lt;img width=&quot;1024&quot; height=&quot;512&quot; data-public-id=&quot;wp-pme/amazon-feat-image-02/amazon-feat-image-02.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_512,c_scale/f_auto,q_auto/v1788275413/wp-pme/amazon-feat-image-02/amazon-feat-image-02.png?_i=AA&quot; alt=&quot;amazon tracking cover&quot; class=&quot;wp-post-277720 wp-image-279392&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;14 KB&quot; data-optsize=&quot;9 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;39.7&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=279392&quot; data-version=&quot;1788275413&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_512,c_scale/f_auto,q_auto/v1788275413/wp-pme/amazon-feat-image-02/amazon-feat-image-02.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_150,c_scale/f_auto,q_auto/v1788275413/wp-pme/amazon-feat-image-02/amazon-feat-image-02.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_384,c_scale/f_auto,q_auto/v1788275413/wp-pme/amazon-feat-image-02/amazon-feat-image-02.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_768,c_scale/f_auto,q_auto/v1788275413/wp-pme/amazon-feat-image-02/amazon-feat-image-02.png?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_2048,h_1024,c_scale/f_auto,q_auto/v1788275413/wp-pme/amazon-feat-image-02/amazon-feat-image-02.png?_i=AA 2048w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_784,c_scale/f_auto,q_auto/v1788275413/wp-pme/amazon-feat-image-02/amazon-feat-image-02.png?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;h2 id=&quot;how-alexa-collects-and-uses-your-voice-data&quot; class=&quot;wp-block-heading&quot;&gt;How Alexa collects and uses your voice data&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Smart speakers like Amazon Echo and their built-in virtual assistants like Amazon Alexa have become a convenient way to control lights, play music, set reminders, and answer questions without lifting a finger. But they work by doing something many other devices don&amp;#8217;t: They listen for your voice. While Echo devices are designed to activate only after hearing a wake word, they have become the subject of privacy concerns.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;One notable incident occurred in 2018, when an Echo &lt;a href=&quot;https://www.nbcnews.com/tech/tech-news/little-did-she-know-alexa-was-recording-every-word-she-n877286&quot;&gt;&lt;u&gt;mistakenly sent a private conversation&lt;/u&gt;&lt;/a&gt; between a couple to one of their contacts. Amazon said that an unlikely sequence of misinterpreted voice commands was to blame, but it served as a reminder that voice assistants aren&amp;#8217;t infallible.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Amazon has also faced scrutiny over how it handles voice recordings after reports revealed that employees reviewed a sample of Alexa interactions to help improve speech recognition systems. Separately, the US Federal Trade Commission fined Amazon over allegations that it retained children&amp;#8217;s Alexa voice recordings even after parents requested they be deleted. These incidents raised broader questions about how long voice recordings are stored, who can access them, and how they&amp;#8217;re used.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;As generative AI has become increasingly important to technology companies, voice data has taken on greater value. Amazon has announced new AI-powered Alexa features that rely on cloud processing, meaning voice requests are analyzed on Amazon&amp;#8217;s servers rather than entirely on the device itself. For users concerned about privacy, this represents another trade-off for convenience.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;How to protect yourself&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Amazon provides several controls that allow you to reduce the amount of information linked to your account. You can review and delete your voice history, choose how long recordings are retained, and opt out of using voice recordings to help develop new Amazon services where those options are available.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you&amp;#8217;d rather avoid sending voice commands to the cloud altogether, it may be worth considering smart home platforms that support local voice processing. Open-source solutions like &lt;strong&gt;&lt;a href=&quot;https://www.home-assistant.io/green/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Home Assistant Green&lt;/a&gt;&lt;/strong&gt; can process commands on local hardware. While these systems often require more technical setup than a plug-and-play smart speaker, they offer a level of transparency and control that many commercial devices don&amp;#8217;t.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Ultimately, the convenience of a voice assistant comes down to trust. If you&amp;#8217;re comfortable sending voice commands to a cloud service in exchange for smarter features, Alexa remains one of the most capable assistants available. But if you prefer to minimize the amount of personal data leaving your home, reviewing Alexa&amp;#8217;s privacy settings or choosing a locally processed alternative can help you regain more control over what your smart speaker hears.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In the Alexa app, go to &lt;strong&gt;More&lt;/strong&gt; and tap &lt;strong&gt;Alexa Privacy&lt;/strong&gt;.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full is-resized&quot;&gt;&lt;img width=&quot;266&quot; height=&quot;242&quot; data-public-id=&quot;wp-pme/alexa-privacy/alexa-privacy.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_266,h_242,c_scale/f_auto,q_auto/v1788273662/wp-pme/alexa-privacy/alexa-privacy.png?_i=AA&quot; alt=&quot;alexa privacy&quot; class=&quot;wp-post-277720 wp-image-279292&quot; style=&quot;width:366px;height:auto&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;24 KB&quot; data-optsize=&quot;7 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;69.6&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=279292&quot; data-version=&quot;1788273662&quot; data-seo=&quot;1&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Review Voice History&lt;/strong&gt; lets you delete your voice recordings, while &lt;strong&gt;Review Smart Home Device History&lt;/strong&gt; shows your connected device activity.&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-full&quot;&gt;&lt;img width=&quot;262&quot; height=&quot;454&quot; data-public-id=&quot;wp-pme/alexa-privacy-1/alexa-privacy-1.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_262,h_454,c_scale/f_auto,q_auto/v1788273771/wp-pme/alexa-privacy-1/alexa-privacy-1.png?_i=AA&quot; alt=&quot;Alexa privacy 1&quot; class=&quot;wp-post-277720 wp-image-279317&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;100 KB&quot; data-optsize=&quot;29 KB&quot; data-optformat=&quot;image/jpeg&quot; data-percent=&quot;70.9&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=279317&quot; data-version=&quot;1788273771&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1788273771/wp-pme/alexa-privacy-1/alexa-privacy-1.png?_i=AA 262w, https://res.cloudinary.com/dbulfrlrz/images/w_173,h_300,c_scale/f_auto,q_auto/v1788273771/wp-pme/alexa-privacy-1/alexa-privacy-1.png?_i=AA 173w&quot; sizes=&quot;auto, (max-width: 262px) 100vw, 262px&quot; /&gt;&lt;/figure&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;br&gt;Scrolling further, you&amp;#8217;ll find &lt;strong&gt;Review Activity History&lt;/strong&gt;, &lt;strong&gt;Manage skill permissions and ad preferences&lt;/strong&gt;, and &lt;strong&gt;Manage Your Alexa Data&lt;/strong&gt;. Here, you&amp;#8217;ll find additional ways to limit what Alexa collects and shares.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full is-resized&quot;&gt;&lt;img width=&quot;269&quot; height=&quot;464&quot; data-public-id=&quot;wp-pme/alexa-privacy-2/alexa-privacy-2.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_269,h_464,c_scale/f_auto,q_auto/v1788274758/wp-pme/alexa-privacy-2/alexa-privacy-2.png?_i=AA&quot; alt=&quot;Alexa privacy 2&quot; class=&quot;wp-post-277720 wp-image-279343&quot; style=&quot;width:269px;height:auto&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;96 KB&quot; data-optsize=&quot;31 KB&quot; data-optformat=&quot;image/jpeg&quot; data-percent=&quot;67.8&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=279343&quot; data-version=&quot;1788274758&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1788274758/wp-pme/alexa-privacy-2/alexa-privacy-2.png?_i=AA 269w, https://res.cloudinary.com/dbulfrlrz/images/w_174,h_300,c_scale/f_auto,q_auto/v1788274758/wp-pme/alexa-privacy-2/alexa-privacy-2.png?_i=AA 174w&quot; sizes=&quot;auto, (max-width: 269px) 100vw, 269px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;h2 id=&quot;amazon-companies-collecting-data&quot; class=&quot;wp-block-heading&quot;&gt;Amazon-owned companies you may not realize are collecting your data&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Even if you stop shopping on Amazon, you may still be using Amazon-owned services without realizing it. The company has acquired businesses that span entertainment, books, gaming, groceries, and retail. While each service has its own purpose, many also collect information that contributes to your overall Amazon profile.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Film fans may frequent IMDb, bookworms may track their reading lists on Goodreads, audiobook listeners might subscribe to Audible, gamers are likely familiar with Twitch, and shoppers may regularly visit Whole Foods or Zappos. On the surface, these brands operate independently, but behind the scenes, they&amp;#8217;re within Amazon&amp;#8217;s ecosystem.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Whole Foods is perhaps the clearest example of Amazon extending its reach into the physical world. In addition to integrating Amazon Prime discounts, the company has experimented with technologies designed to connect in-store purchases with customers&amp;#8217; online identities. One example was Amazon One, a &lt;a href=&quot;https://www.oregonlive.com/retail/2026/02/shunned-by-customers-this-payment-method-will-soon-disappear-at-whole-foods-stores.html&quot;&gt;&lt;u&gt;palm-scanning payment system&lt;/u&gt;&lt;/a&gt; that allowed shoppers to pay by scanning their hand instead of using a card or phone. Although Amazon has essentially phased out the technology at Whole Foods stores, it demonstrated the company&amp;#8217;s ambition to link physical shopping with digital customer profiles.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;How to reduce your data flowing into Amazon&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Replacing every service overnight isn&amp;#8217;t realistic or necessary. Instead, consider switching the services you use most often. &lt;strong&gt;&lt;a href=&quot;https://thestorygraph.com/&quot;&gt;StoryGraph&lt;/a&gt; &lt;/strong&gt;offers an alternative to Goodreads for tracking books, &lt;strong&gt;&lt;a href=&quot;https://www.themoviedb.org/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;TMDB&lt;/a&gt;&lt;/strong&gt; provides movie and television information without relying on Amazon, and audiobook listeners can explore services like &lt;strong&gt;&lt;a href=&quot;https://libro.fm/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Libro.fm&lt;/a&gt;&lt;/strong&gt; or borrow titles through Libby using a local library membership.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When it comes to groceries and everyday shopping, supporting local businesses can reduce your dependence on a single retailer. Recognizing just how broad Amazon&amp;#8217;s ecosystem has become can help you make small changes that can significantly reduce how much of your digital life is tied to a single account.&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img width=&quot;1024&quot; height=&quot;512&quot; data-public-id=&quot;wp-pme/amazon-feat-image-01/amazon-feat-image-01.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_512,c_scale/f_auto,q_auto/v1788275359/wp-pme/amazon-feat-image-01/amazon-feat-image-01.png?_i=AA&quot; alt=&quot;amazon tracking&quot; class=&quot;wp-post-277720 wp-image-279368&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;81 KB&quot; data-optsize=&quot;53 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;35.4&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=279368&quot; data-version=&quot;1788275359&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_512,c_scale/f_auto,q_auto/v1788275359/wp-pme/amazon-feat-image-01/amazon-feat-image-01.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_150,c_scale/f_auto,q_auto/v1788275359/wp-pme/amazon-feat-image-01/amazon-feat-image-01.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_384,c_scale/f_auto,q_auto/v1788275359/wp-pme/amazon-feat-image-01/amazon-feat-image-01.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_768,c_scale/f_auto,q_auto/v1788275359/wp-pme/amazon-feat-image-01/amazon-feat-image-01.png?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_2048,h_1024,c_scale/f_auto,q_auto/v1788275359/wp-pme/amazon-feat-image-01/amazon-feat-image-01.png?_i=AA 2048w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_784,c_scale/f_auto,q_auto/v1788275359/wp-pme/amazon-feat-image-01/amazon-feat-image-01.png?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;/figure&gt;



&lt;h2 id=&quot;what-is-amazon-web-services&quot; class=&quot;wp-block-heading&quot;&gt;What is Amazon Web Services (AWS), and why does it matter?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It may surprise you to find out that Amazon&amp;#8217;s most profitable business isn&amp;#8217;t its marketplace or Prime. It&amp;#8217;s Amazon Web Services (AWS), one of the world&amp;#8217;s largest cloud-computing platforms.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Many businesses use AWS to host websites, store data, run applications, process transactions, and deliver online services to millions of users around the world.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This became clear during &lt;a href=&quot;https://www.nbcnews.com/news/us-news/amazon-web-services-outage-websites-offline-rcna238594&quot;&gt;&lt;u&gt;major AWS outages&lt;/u&gt;&lt;/a&gt; in late 2025, which disrupted businesses, government agencies, healthcare providers, and popular online services. When a cloud provider of this scale experiences problems, the effects ripple across the internet, preventing users from accessing banking apps, streaming platforms, and other sites.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Interestingly, unlike Amazon&amp;#8217;s retail business, AWS isn&amp;#8217;t collecting data. Instead, its influence comes from its position as critical infrastructure. If a website or service is hosted on AWS, Amazon provides the computing power that keeps it online. A significant portion of the internet depends on this infrastructure.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This position also gives AWS considerable influence over the services it hosts. Over the years, AWS has suspended or removed customers from the platform after determining they had violated its terms of service. While supporters argue these decisions help protect users and maintain platform integrity, critics point out that when a small number of cloud providers host a large share of the internet, those decisions can have far-reaching consequences.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For individual users, however, there isn&amp;#8217;t a practical way to avoid AWS entirely. You can neither easily tell whether the websites, apps, or online services you use are hosted on Amazon&amp;#8217;s infrastructure, nor can you choose which cloud provider those companies rely on.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;What you can control is the infrastructure you use yourself. Privacy-conscious users may prefer to self-host services such as cloud storage or media libraries using their own hardware instead of relying entirely on large cloud providers. Platforms like Nextcloud make this increasingly accessible.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Self-hosting isn&amp;#8217;t for everyone. It requires time, maintenance, and a willingness to learn. But for those who value privacy and digital independence, it offers an alternative to large cloud providers. Even moving a handful of personal services off the cloud can reduce the amount of data entrusted to big technology companies.&lt;/p&gt;



&lt;h2 id=&quot;how-to-reduce-amazon-tracking&quot; class=&quot;wp-block-heading&quot;&gt;How to reduce Amazon&amp;#8217;s tracking without giving up convenience&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Amazon&amp;#8217;s products and services are designed to work together. A purchase on Amazon.com can lead to a recommendation on your Kindle. A Ring camera can integrate with Alexa. Prime connects shopping, entertainment, and groceries under a single account. Behind the scenes, AWS powers a significant portion of the internet itself. Individually, these services can be genuinely useful. Collectively, they give Amazon an unusually broad view of your digital life.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For many people, breaking out of Amazon’s box isn&amp;#8217;t that simple. But privacy isn&amp;#8217;t an all-or-nothing decision. Every step you take can help to reduce the amount of information Amazon has on you.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The most important thing is to make choices deliberately. Convenience often comes at the cost of sharing more personal data, but understanding those trade-offs puts you back in control.&lt;/p&gt;
</content:encoded><category>Videos</category><author>Proton Team</author></item><item><title>Team password management: How to organize password vaults by department</title><link>https://proton.me/business/blog/team-password-management-by-department</link><guid isPermaLink="true">https://proton.me/business/blog/team-password-management-by-department</guid><description>Learn how to organize shared password vaults by department, enforce least privilege, and keep credential management secure.</description><pubDate>Tue, 01 Sep 2026 16:34:31 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/pass&quot;&gt;Team password management&lt;/a&gt; is simple at three people. At 15 people, it starts to break down.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A small company might have a handful of tools, a few shared accounts, and usually one informal place where passwords live: a spreadsheet, a pinned message in chat, a shared document.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;As more people join a business, informal sharing makes it difficult to see the difference between useful access and risky access. Passwords for everyday tools end up mixed with credentials for finance, admin, client, or infrastructure systems. The list may still look organized from the outside, but it no longer reflects who actually needs access to what.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;As a business grows, shared credentials need structure and control: who can access each password, which department owns the credentials, and how access changes as people join, leave, and switch roles.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;We’ll explain how to organize password vaults by team or department, how group-based access supports least privilege, and how to make onboarding and offboarding more secure — before credential sprawl becomes a security and operations problem.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Why shared password access doesn’t scale&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Informal sharing is usually the first model growing companies rely on. Informal sharing is built for convenience: passwords may live in a spreadsheet, a chat thread, or someone&amp;#8217;s browser, and nobody has to ask for access every time they need a login.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That convenience is quickly outweighed by chaos and risk. Once more teams, contractors, clients, and tools enter the business, that shared list becomes too broad for the work people actually do. The finance team may need banking, payroll, and invoicing credentials, but not ad accounts or developer tools, for example. Marketing may need analytics, content, and social media access, but not legal portals or infrastructure credentials.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The cracks show in everyday work, but &lt;a href=&quot;https://proton.me/business/blog/employee-offboarding-security&quot;&gt;offboarding&lt;/a&gt; is where this model becomes dangerous. When someone leaves, the business has no reliable way to know which credentials they had access to, copied, or still remember. Rotating a password means distributing the new one all over again through the same unprotected channels, with no record of who received it. Faced with that effort, many businesses skip rotation.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt; with structured vaults and group-based access replaces imprecision with control: access can be granted, reviewed, and revoked deliberately.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The larger the vault becomes, the less useful it is as an access control. It may still store passwords securely, but it no longer reflects how the business actually works, who owns each credential, or who should be able to use it.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Team-based access supports least privilege&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The principle behind credential access by department is simple: people should only have access to the credentials they need for their work.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The principle of &lt;a href=&quot;https://proton.me/business/blog/principle-of-least-privilege&quot;&gt;least privilege&lt;/a&gt; is useful because it gives credential access a clear test: does this person need this credential to do their job, or do they have it because access was granted once and never questioned again? In team password management, that question should shape how vaults are created, who joins them, and when access is removed.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is especially important for shared credentials. A shared login is already harder to govern than an individual account because more than one person can use it.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When that credential is also accessible to people who don’t need access to it, the business carries exposure without any benefit: every extra person who can view it is another device where it can be autofilled, copied, or &lt;a href=&quot;https://proton.me/blog/what-is-phishing&quot;&gt;phished&lt;/a&gt;. The business may know that the password is stored somewhere safe, but not whether everyone with vault access still has a valid reason to use it.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/blog/pass-groups&quot;&gt;Groups&lt;/a&gt; in Proton Pass for Business solve this: admins can organize people into groups that mirror teams, departments, or projects, then assign those groups to specific vaults and items, so access follows the role rather than a list of individual grants.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Vault structure should match risk. Low-risk operational logins can be shared easily, while admin credentials, finance tools, HR systems, customer exports, and backup access need tighter controls.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What good vault structure looks like&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A useful vault structure should help people find what they need without giving them everything.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A practical baseline for most growing SMBs includes six password vaults by team::&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Finance:&lt;/strong&gt; Accounting, payroll, banking, invoicing, tax portals, payment platforms.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Marketing:&lt;/strong&gt; Social media, analytics, advertising, content management, design tools.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Sales and customer success:&lt;/strong&gt; CRM, proposal tools, customer portals, support platforms.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Operations:&lt;/strong&gt; Vendor portals, project management tools, logistics, procurement.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;IT and security:&lt;/strong&gt; Admin consoles, backup accounts, device management, DNS, hosting, infrastructure.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Leadership:&lt;/strong&gt; Board materials, investor portals, executive-level services, sensitive vendor accounts.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When vault structure and group access work together, admins can manage permissions at scale: assign a finance group to the finance vault, an IT group to infrastructure vaults, and a project group to temporary client work. Access then scales with the org chart instead of with an admin’s memory.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;After the base structure is in place, create restricted vaults where the risk justifies them. An IT team may keep a general IT vault and a separate privileged admin vault, both assigned to the appropriate groups.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This becomes essential during onboarding and offboarding. Adding someone to a group grants them all necessary vaults at once; removing them revokes everything at once.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The goal is not to make vaults complicated. The goal is to avoid mixing credentials with very different risk levels. A social media scheduler should not share access with payroll administration.&amp;nbsp;&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Password vault structures for different team sizes&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A very small business doesn’t need enterprise-level vault architecture. Too much structure too early can create confusion and slow adoption.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Even at one to two people, separating business credentials from personal ones in separate vaults sets a foundation for growth.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For a team of three to 10 people, a few broad vaults may be enough: company operations, finance, marketing, and IT. The main priority is to avoid one vault for everything and keep the most sensitive credentials separate.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For a team of 10 to 50 people, vault structure needs to follow how the business is actually organized. At this stage, credential access becomes part of everyday operations: people join teams, contractors come in for specific projects, managers become responsible for the tools their teams use, and admins need a way to review access without opening every credential one by one. Contractors and external collaborators can be assigned to project-specific vaults without scoped access, so they only see what their engagement requires —&amp;nbsp;and lose access automatically when the project ends.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For teams of 50 or more — larger SMBs and mid-market teams — vaults may need to follow both departments and roles. A department label is not always specific enough; someone may work in finance without needing banking access, or support IT operations without needing privileged admin credentials.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The structure should fit the business, not the other way around. The following sections explain how to operationalize that structure through onboarding, offboarding, and ongoing access reviews.&amp;nbsp;&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Building structure into onboarding&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Onboarding often exposes weak password management. A new employee joins and someone has to remember which credentials they need, where those passwords live, who can share them, and which access should wait until after training or approval.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A team-based model removes that reliance on memory. When a new finance hire joins, they don’t need a colleague to manually identify and share each credential. They can simply be added to the finance group for the access they need. No one should have to forward links, paste passwords into chat, or remember which tools the finance team usually uses.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The person should simply be added to the finance group and automatically inherit the vaults and items assigned to it — only the credentials tied to that role. This makes onboarding faster and keeps sensitive accounts from spreading beyond the team that needs them. People can start work without chasing passwords, while the business avoids giving broad access for convenience.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is also where a clear password policy helps. Proton’s guide to &lt;a href=&quot;https://proton.me/business/blog/creating-password-policy&quot;&gt;creating a password policy&lt;/a&gt; explains how businesses can define password creation, secure sharing, access management, and authentication rules. Those rules become easier to apply when credentials are already organized by team.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Making offboarding more secure&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;With one shared company vault, revocation is all-or-nothing: the departing employee may have touched dozens or hundreds of credentials, facing broad rotation or — worse — leaving ex-employees with lingering access.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&amp;nbsp;A precise offboarding looks like this:&amp;nbsp;&lt;/p&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Remove the person from team and project groups.&lt;/li&gt;



&lt;li&gt;Review any credentials they owned or managed.&lt;/li&gt;



&lt;li&gt;Rotate higher-risk passwords where needed.&lt;/li&gt;
&lt;/ol&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The business can focus rotation and review effort on the credentials that actually carry risk, instead of treating every password as a fire drill.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is where creating groups pay off. If access is managed only through shared vaults, an admin has to revoke the person from each vault one by one. With groups, removing them from the group revokes every vault and item assigned to that group at once — one action instead of an audit.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The same logic applies when someone changes roles. A person moving from sales to operations should not keep old CRM admin credentials by default. Role changes should trigger a vault access review just as much as offboarding does. With group-based access, this review is fast: move the person between groups, and their access updates automatically —&amp;nbsp;old CRM credentials gone, new operations vaults granted, in one simple step.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Better visibility for admins&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Good team password management gives admins a clear view of access. They should be able to answer basic questions quickly.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Key access questions admins should be able to answer&lt;/h3&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Who can access finance credentials?&lt;/li&gt;



&lt;li&gt;Which vaults include contractors?&lt;/li&gt;



&lt;li&gt;Which users have access to admin passwords?&lt;/li&gt;



&lt;li&gt;Which credentials are shared across departments?&lt;/li&gt;



&lt;li&gt;What changed after an employee left?&lt;/li&gt;



&lt;li&gt;Which vaults contain high-risk or privileged accounts?&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The &lt;a href=&quot;https://www.ncsc.gov.uk/collection/10-steps/identity-and-access-management&quot;&gt;NCSC’s identity and access management guidance&lt;/a&gt; emphasizes controlling who and what can access systems and data. It also points to the importance of limiting access to what is needed and reviewing access regularly.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is difficult when access is organized around convenience instead of responsibility. A clean vault structure gives admins a stronger starting point for security audits, access reviews, and customer questionnaires.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For &lt;a href=&quot;https://proton.me/business/pass/for-it-teams&quot;&gt;IT teams&lt;/a&gt;, Proton Pass for Business supports centralized management, policies, secure sharing, reporting and logs, SCIM provisioning, and SSO integrations. Teams gain centralized visibility that browser-saved passwords and shared spreadsheets don’t provide.&amp;nbsp;&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Common mistakes in shared vault management&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Shared vault problems usually begin as shortcuts. They make access easier in the moment, but they also make it harder to know who can use which credentials later.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Five mistakes account for most shared vault failures in growing businesses:&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Keeping one company vault for too long&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&amp;nbsp;A single vault may work at the beginning, but it eventually gives too many people access to credentials outside their role.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Depending on one admin’s knowledge&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If only one person knows where critical credentials live, the business is reliant on memory instead of process — and that knowledge walks out the door with them.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Treating vault access as permanent&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;People change roles, contractors finish projects, and vendors leave. Vault access should change with them.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Forgetting credential rotation&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Some passwords need to be changed after offboarding, role changes, or periods of overly broad sharing, especially for admin accounts, finance tools, customer systems, and vendor portals.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Mixing everyday logins with privileged access&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A team vault can make daily work easier, but high-risk credentials still need stricter review and narrower access.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Each of these mistakes has the same root cause —&amp;nbsp;access organized around convenience —&amp;nbsp;and the same cure: structure that reflects team, roles, and risk.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How Proton Pass for Business supports team password management&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton Pass for Business helps businesses move from informal password sharing to structured credential management. Teams can generate strong passwords, store credentials in encrypted vaults, share access securely, and manage business passwords from one place.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt; gives teams a safer place to store and share credentials, but the structure around those credentials still matters. For growing teams, the next step is making sure shared access reflects how people actually work: by department, role, project, and level of risk.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;With groups in Proton Pass, credential access is managed at the level teams actually work: admins assign vaults and items to groups mirroring their departments or projects, and membership changes update access automatically — adding a hire grants everything they need; removing them revokes it all.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Clearer structure makes &lt;a href=&quot;https://proton.me/pass/password-sharing&quot;&gt;secure sharing&lt;/a&gt; easier to manage in the flow of work. Credentials are organized around the teams and roles that actually use them, admins have a better view of access, and employees can find the passwords they need without moving secrets into chat, email, or personal notes.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Organize your team’s credential access with a &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt;.&lt;/p&gt;
</content:encoded><category>For business</category><author>Kate Menzies</author></item><item><title>Become a Proton Pass managed service provider (MSP) with our new program</title><link>https://proton.me/business/blog/password-manager-msp-pilot</link><guid isPermaLink="true">https://proton.me/business/blog/password-manager-msp-pilot</guid><description>We&apos;re introducing a pilot program for MSPs to offer Proton Pass to their clients. Find out how to apply and what to expect.</description><pubDate>Tue, 01 Sep 2026 11:56:18 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Small and medium-sized businesses are under threat from hackers in a way they&amp;#8217;ve never been before. They&amp;#8217;re the new favorite &lt;a href=&quot;https://proton.me/business/blog/ransomware-threats-smbs&quot;&gt;targets of ransomware attacks&lt;/a&gt;. AI-fueled phishing scams and malware-as-a-service make criminal work easier than ever. Our &lt;a href=&quot;https://proton.me/business/smb-cybersecurity-report&quot;&gt;SMB Cybersecurity Report&lt;/a&gt; found that hackers breached one in four SMBs last year, costing most of them between $10,000 and $100,000.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The best solution is also the simplest: Use a &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;To make strong cybersecurity even more accessible to SMBs, Proton Pass is launching a &lt;strong&gt;&lt;/strong&gt;&lt;strong&gt;pilot program&lt;/strong&gt; &lt;strong&gt;for managed service providers&lt;/strong&gt;. We&amp;#8217;re inviting MSPs in our community and beyond to take part. By joining the program now, &lt;strong&gt;you&amp;#8217;ll be able to offer and manage Proton Pass Professional subscriptions&lt;/strong&gt; from a dedicated portal in your own Proton Pass dashboard.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Many organizations use our Proton Pass password manager within their own infrastructure, and some IT firms and MSPs deploy it for other businesses. But until now, a more feature-rich managed services portal hasn&amp;#8217;t been available. This program gives you the opportunity to add Proton Pass to the product portfolio offered to your customers while helping to shape the development and features of the Proton Pass MSP product.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What is the Proton Pass MSP pilot?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The pilot program introduces a dedicated portal that allows MSPs to sell and manage Pass Professional subscriptions across multiple client organizations from one interface.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Before we roll out MSP services for broader availability, we&amp;#8217;re inviting MSP businesses to take part in this initial pilot program. We&amp;#8217;ll work closely with them to understand how they use the portal and what new features they would like to see.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This launch focuses on the core features you need as an MSP, including:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Allowing multi-organization user provisioning and management&lt;/li&gt;



&lt;li&gt;Having an overview of all sub-organizations that you manage, showing allotted vs. used licenses per client, with one-click access to each client&amp;#8217;s admin dashboard&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What to know about the pilot program&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you&amp;#8217;re interested in taking part, here&amp;#8217;s what to expect:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;After you &lt;a href=&quot;https://proton.me/business/contact?pd=pass&quot;&gt;&lt;/a&gt;&lt;a href=&quot;https://proton.me/business/contact?pd=pass&quot;&gt;get&lt;/a&gt; &lt;a href=&quot;https://proton.me/partners/msp-registration&quot;&gt;in touch with our sales team&lt;/a&gt; and set up an agreement, you&amp;#8217;ll be granted access to the new MSP portal.&lt;/li&gt;



&lt;li&gt;You&amp;#8217;ll be subscribed to your own Proton Pass plan that allows you to create and manage client sub-organizations from the dedicated MSP portal.&lt;/li&gt;



&lt;li&gt;Every seat allocation or disablement is recorded as a timestamped event.&lt;/li&gt;



&lt;li&gt;At the end of each month, you can export a detailed report that you can use to bill your own clients.&lt;/li&gt;



&lt;li&gt;You&amp;#8217;ll also be &lt;strong&gt;sent a&lt;/strong&gt;&lt;strong&gt;n&lt;/strong&gt; &lt;strong&gt;invoice by Proton&lt;/strong&gt; in line with the detailed report.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/pass/msp&quot;&gt;Find out more about the pilot program.&lt;/a&gt;&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Why partner with Proton Pass as an MSP?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When you provide third-party password management services for businesses, your clients trust you to protect their entire IT perimeter, which includes valuable and &lt;a href=&quot;https://proton.me/business/blog/sensitive-information&quot;&gt;sensitive business data&lt;/a&gt;. That means choosing reliable tools that meet high security standards, not just ones that offer the right price or make claims you can&amp;#8217;t verify.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Security your clients can rely on&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Everything we claim about &lt;a href=&quot;https://proton.me/pass/security&quot;&gt;Proton Pass&amp;#8217;s security&lt;/a&gt; is backed up by regular &lt;a href=&quot;https://proton.me/business/blog/proton-pass-audit-2026&quot;&gt;third-party security audits&lt;/a&gt; and our application code is all &lt;a href=&quot;https://proton.me/community/open-source&quot;&gt;open-source&lt;/a&gt; so anyone can verify it. Our &lt;a href=&quot;https://proton.me/learn/encryption/types-of-encryption/zero-access&quot;&gt;zero-knowledge architecture&lt;/a&gt; and &lt;a href=&quot;https://proton.me/learn/encryption/types-of-encryption/what-is-end-to-end&quot;&gt;end-to-end encryption&lt;/a&gt; form a secure foundation for any business.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/pass/customer/elemnta&quot;&gt;&lt;em&gt;Read why fintech Elemnta chose Proton Pass&lt;/em&gt;&lt;/a&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Effective password management for teams&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton Pass provides secure credential management with &lt;a href=&quot;https://proton.me/support/pass-business-policies&quot;&gt;customizable policies&lt;/a&gt; and granular reporting that make it an ideal choice for managed service providers. You can manage all of your clients&amp;#8217; organizations from one console, ensuring that &lt;a href=&quot;https://proton.me/business/pass/password-policy&quot;&gt;business password policies&lt;/a&gt; are followed and strict security standards are met.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Easy enough for anyone to use&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When you&amp;#8217;re introducing a new password manager, encouraging adoption can be a challenge. Proton Pass was designed to work for anyone, no matter their familiarity or confidence with tech. Companies that switch to Proton Pass say the intuitive interface led to more widespread adoption.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/pass/customer/morning&quot;&gt;&lt;em&gt;See how French coworking firm Morning rolled out Proton Pass&lt;/em&gt;&lt;/a&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;An EU-based alternative for digital sovereignty&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Many businesses are looking for &lt;a href=&quot;https://proton.me/blog/european-alternative-us-tech-survey&quot;&gt;European alternatives&lt;/a&gt; to the American tech they&amp;#8217;ve relied on because they&amp;#8217;ve realized they don&amp;#8217;t truly have control of their own data. When clients ask how you address this problem, Proton Pass can be the simple answer.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You can learn about &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;all the Proton Pass features&lt;/a&gt; and see &lt;a href=&quot;https://proton.me/alternatives#pass&quot;&gt;how Pass compares&lt;/a&gt; to other password managers. Our &lt;a href=&quot;https://proton.me/partners/msp-registration&quot;&gt;sales team&lt;/a&gt; is also available to help you if you have any questions about the MSP program or need answers for your clients.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Find out more about the &lt;a href=&quot;https://proton.me/business/pass/msp&quot;&gt;pilot program&lt;/a&gt; and how businesses can benefit from adopting a secure European business password manager.&lt;/p&gt;
</content:encoded><category>For business</category><author>Raphael Auphan</author></item><item><title>August 27 outage: Incident report</title><link>https://proton.me/blog/august-27-outage-incident-report</link><guid isPermaLink="true">https://proton.me/blog/august-27-outage-incident-report</guid><description>Here&apos;s a timeline of what happened, what choices we made during the incident and why, and how it was resolved.</description><pubDate>Fri, 28 Aug 2026 21:12:56 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;In the early hours of August 27, 2026, Proton experienced a widespread outage that impacted services for a number of users. The root cause was a total failure of the cooling system in our Frankfurt datacenter. While all systems at Proton are redundant and we have enough capacity to endure a complete data center failure, there are a small number of scenarios where the failover can take longer and lead to user-facing disruptions.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Here&amp;#8217;s a timeline of what happened, what choices we made during the incident and why, and how it was resolved.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Timeline&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Just after 11 p.m. (Central European time) on Wednesday, August 26, a cooling system failure occurred in the main room of our Frankfurt datacenter. At around 11:15 p.m., the temperature started rising from approximately 21.8°C (nominal temperature) to 51.9°C in less than half an hour, with some measurement probes reporting 60°C air temperature in the room. As the temperatures rose, server and networking equipment within the facility started to die one by one.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The user-facing incident began at around midnight on August 27, when the failures escalated to the point that critical redundancy was lost. This occurred when both the primary and backup network switch on a critical rack failed, and this rack unfortunately contained several primary database copies. While almost all Proton systems are redundant and will failover automatically/immediately, primary database failovers are not done automatically without human supervision.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;We retain this control out of a desire to avoid so-called &amp;#8220;split brain&amp;#8221; situations, where a temporary unavailability of a primary database means that the replica copies miss some updates and become de-synced in ways that can be difficult to reconcile later. Furthermore, when a primary database failover occurs, the standard operating procedure is to failover to a replica in the same datacenter for latency and performance reasons. However, the specific nature of the problem meant that this might be ill-advised, since we potentially could be failing over to something that would also go down.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;The decisions&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;At this point, Proton&amp;#8217;s on-call engineers needed to make a couple consequential decisions while operating under extreme pressure.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Do they prioritize bringing the service back online, or prioritize addressing the cooling problem and saving the hardware inside the datacenter?&lt;/li&gt;



&lt;li&gt;Should we failover to replicas within the same building Frankfurt (faster and less disruptive, but possibly a temporary fix if the heat could not be brought under control), or failover to Zurich?&lt;/li&gt;



&lt;li&gt;Do we failover everything or just what is down at the moment? We have contingencies for complete data center failure where things failover fully and mostly automatically rather quickly, but a situation where random servers are dying one by one is not handled well by our failover logic.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Ultimately the rate at which temperatures were rising forced us to prioritize saving the hardware versus bringing services back online. This is not a choice that typically needs to be made, because cooling systems are typically redundant, and the complete loss of cooling is quite rare, meaning that there is quite a bit of time before temperatures become critical. The problem is exacerbated by large increase in server power density in recent years with higher power CPUs and GPUs for AI. As a result, what used to take 3-4 hours to go critical went critical in 20 minutes.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The on-call team therefore focused their attention on communicating with the on-site datacenter operations team to restore cooling while powering off as many servers as possible to protect them. Due to a server equipment shortage tied to the ongoing AI boom, lots of this equipment — if lost — would not be possible to replace on short timelines. Saving it had to be a priority, even at the cost of potentially extending the downtime.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;By &lt;strong&gt;00:45 CEST&lt;/strong&gt;, we were able to restore cooling and temperatures at the facility began to drop, and the on-call team switched focus to service recovery. At this point, we made the decision to failover the primary databases to Frankfurt if a replica was still alive, and to Zurich in cases where there was no replica alive in Frankfurt, to avoid changing our traffic flows too much and possibly creating new instability. This option was selected because we assumed that, now that we had the cooling under control, it would be relatively easy to bring Frankfurt back online and faster than switching over to Zurich.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Unfortunately, this turned out not to be the case. During the incident, many network cards in the Frankfurt infrastructure reached a temperature of 105C (normal operating temperature is 45C), which triggers a special temperature protection mode and causes the network cards to be disabled until there is a cold system reset. Our security posture limits the ability to access the out-of-band controller for our systems, which required us to wake up additional staff to assist with the recovery.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;By &lt;strong&gt;01:30 CEST&lt;/strong&gt;, we were able to get most services back online for most users. However, some less critical systems, such as push notifications or payment processing, were not recovered until around 02:00 CEST.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;As we reported during the initial incident report, no emails were lost, but email delivery in both directions was delayed during the incident.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;While user-facing services were fully restored, that was not the end of the night for our engineers, in particular the database team. Our infrastructure was left in a highly abnormal state, with some primary databases in Zurich and others in Frankfurt, and several of them operating with reduced redundancy and/or reduced performance. Our team worked through the night to resolve the most pressing of these issues, and the work continued through the day on August 27 to restore full redundancy.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;While we were able to save almost all of the infrastructure, some servers unfortunately suffered heat death, and we don&amp;#8217;t know yet if the heating incident will impact the lifespan of the surviving equipment.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Root cause and next steps&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A subsequent investigation on August 27 traced the root cause of the cooling failure to an air filter replacement on both of the redundant air compressors powering the cooling system. Unfortunately, the datacenter operator performed this operation in the middle of the night, without prior notice, and also failed to communicate the cooling failure when it happened, which dramatically cut down the time we had to respond. We are working closely with the operator to prevent a repeat of this incident.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;However, it is also a known limitation of our current database infrastructure that an outage of this type could lead to a longer than normal recovery process. The series of events that led to this incident are highly improbable — yet they happened.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The database resilience work required to address this failure mode is already underway and remains planned for completion by the end of the year. Additional infrastructure capacity, including new datacenter space, is also currently being commissioned and is expected to become available within the next few weeks, which will further reduce our single site dependency.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Unfortunately, this incident occurred before those improvements were fully in place. We are now reviewing where we can safely accelerate the remaining work while maintaining the level of care required for changes to critical database infrastructure.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;We recognize that our users expect a very high level of reliability from Proton, and this incident reinforces the importance of completing this work and continuing to raise our resilience standards. We apologize again, unreservedly, to every user who was impacted.&lt;/p&gt;
</content:encoded><category>Company news</category><category>Proton updates</category><author>Bart Butler</author></item><item><title>How to choose remote work tools that don&amp;#8217;t create security debt</title><link>https://proton.me/business/blog/remote-work-tools</link><guid isPermaLink="true">https://proton.me/business/blog/remote-work-tools</guid><description>The remote work tools you pick on day one become the infrastructure you&apos;re stuck with. Here&apos;s how to build a stack you won&apos;t need to rebuild.</description><pubDate>Fri, 28 Aug 2026 12:32:43 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Remote work tools may not feel like a major infrastructure decision when you&amp;#8217;ve just started scaling your business. They can feel like a relatively minor task compared to making payroll, shipping your MVP, or keeping your runway alive&amp;#8230; But that’s where the danger lies.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The remote work tools you pick on day one become infrastructure you&amp;#8217;re stuck with, and the gaps between those tools quietly accumulate into serious problems you won&amp;#8217;t notice until it&amp;#8217;s too late. That&amp;#8217;s security debt — and it&amp;#8217;s more common than you&amp;#8217;d think.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/smb-cybersecurity-report&quot;&gt;&lt;u&gt;One in four SMBs&lt;/u&gt;&lt;/a&gt; experienced a breach last year, despite actively investing in security tools. The problem wasn’t the password managers or VPN they chose: it was the gaps between them.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Security debt doesn&amp;#8217;t hit you immediately, but it does&amp;nbsp;compound in the background until the worst possible moment: When an enterprise customer asks for your audit trail and you don&amp;#8217;t have one. Or an investor asks where your data is stored and you tell them it falls under US jurisdiction. Or a security questionnaire asks you to list everyone who has had access to your core systems in the last 24 months, and you realize you never tracked this.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Here&amp;#8217;s how to build a secure stack of remote work tools that closes those gaps and is built to last.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;11 of the best remote work tools for your team&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Every business has different needs, but there are certain categories of remote work tools that just about every business needs to fill. Here are the 11 tools we recommend for each.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;1. Slack (Best for team chat) &lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Launched in 2013, Slack has become the default choice for teams that want chat, voice, and video in one place. It replaced the endless email threads of old with channels organized by team, topic, or project, and its deep integration library (Google Calendar, Jira, and hundreds more) makes it a notification hub for your whole stack. One drawback to consider: on some plans, admins can access message history, a potential privacy concern for some businesses.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;To find out what else is out there, read our list of the best &lt;/strong&gt;&lt;a href=&quot;https://proton.me/business/blog/internal-communication-tools&quot;&gt;&lt;u&gt;&lt;strong&gt;internal communication tools.&lt;/strong&gt;&lt;/u&gt;&lt;/a&gt;&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;2. Proton Mail (Best for business mail) &lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Email providers with economic models built around ad targeting can’t guarantee that your emails won’t be read by anybody else, whatever their privacy policy claims. &lt;a href=&quot;https://proton.me/business/mail&quot;&gt;Proton Mail&lt;/a&gt; is end-to-end encrypted by default, and protected under stringent &lt;a href=&quot;https://proton.me/blog/switzerland&quot;&gt;Swiss privacy law&lt;/a&gt;, so only you and your recipient can read what&amp;#8217;s sent. (Please note: emails to non-Proton recipients aren’t end-to-end encrypted unless you password-protect them first.)&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;3. Loom (Best for async video)&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you’ve ever been in a meeting that could easily have been a two minute video, Loom could be the solution for you. It lets you create video notes, recording your screen, face, and voice together, to be shared as a link. Popular use cases include recording onboarding walkthroughs, bug reports, and async updates across time-zones. (Note that Loom recordings are stored on Loom&amp;#8217;s own servers rather than your team&amp;#8217;s infrastructure, worth knowing if you prefer to keep company data under your own control.)&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;4. Proton Meet (Best for video conferencing) &lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Unlike Zoom, &lt;a href=&quot;https://proton.me/business/meet&quot;&gt;Proton Meet&lt;/a&gt; is end-to-end encrypted by default, which means not even Proton can access what&amp;#8217;s said or shared on a call. Guests join with just a link, no account required, and the free plan covers one-hour calls with up to 50 participants. One caveat: Proton Meet works well for internal team calls, but if your workflow leans on integrating video directly into a CRM or support tool, you should check compatibility before switching. &lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;5. Jira (Best for project management) &lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Jira is built for software teams running agile workflows: think sprints, backlogs, and issue tracking that ties directly to your codebase through Bitbucket or GitHub integrations. As such, Jira is the default choice for many engineering teams already inside the Atlassian ecosystem. On the downside, it is more configuration-heavy than general-purpose tools like Asana, and outside of a dev team it can feel like overkill. &lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;6. Trello (Best for tracking tasks)&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Simplicity is Trello’s strength, stripping task management down to cards moving across boards labeled &lt;strong&gt;&lt;strong&gt;to do&lt;/strong&gt;&lt;/strong&gt;, &lt;strong&gt;&lt;strong&gt;doing&lt;/strong&gt;&lt;/strong&gt;, and &lt;strong&gt;&lt;strong&gt;done&lt;/strong&gt;&lt;/strong&gt;. There’s almost no learning curve, making Trello a natural starting point for a small team. Once your team grows, however, that simplicity can become a limitation: you won’t find it so easy to perform cross-project reporting on it.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;7. Miro (Best for visual collaboration)&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When gathering around a physical whiteboard is impossible, a Miro board gives teams a remote —  and much more flexible — option: an infinite digital canvas for planning, collaboration, and brainstorming. You can drag and drop files onto boards, set up repeat workshops with templates for retrospectives and planning sessions. While Miro is great for teams who can work in live, synchronous sessions, it&amp;#8217;s less useful for teams working async across time zones.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;8. Proton Drive (Best for cloud storage)&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/drive&quot;&gt;Proton Drive&lt;/a&gt; is the privacy-first alternative to Dropbox and Google Drive. Though it has fewer direct integrations than those apps, Proton Drive does a better job of protecting your data, encrypting files on your device before they ever reach Proton&amp;#8217;s servers so that Proton can never decrypt them, even under a court order. Version history, access logs, and granular permissions come built in, and shared links expire by default rather than staying open indefinitely. &lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;9. Proton Pass (Best for password/credential management)&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The risk of credentials leaking increases sharply outside of a controlled office environment. Unlike most password managers, &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;Proton Pass&lt;/a&gt; encrypts every field of every saved item by default: not just passwords, but usernames and notes too. It also includes email alias generation to keep your team’s real email addresses out of signup forms. (Note that advanced admin controls — SSO and SCIM directory sync — are reserved for the Pass Professional tier, not the base plan.)&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;10. Notion (Best for building a knowledge base)&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;With Notion, you can organize and centralize your business’s internal knowledge and documentation in pages, databases, and wikis, building a single source of truth for your teams and eliminating doubt over which document versions are current. But be warned: Notion’s flexibility can become a risk, enabling the building of an unstructured wiki that sprawls unless someone keeps an eye on it.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;11. Lumo&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Even small teams benefit from AI assistance that lets them draft, edit, summarize, and research faster without having to add to head count. &lt;a href=&quot;https://proton.me/business/lumo&quot;&gt;Lumo&lt;/a&gt; is Proton&amp;#8217;s AI assistant, built to offer all the power of AI without compromising your IP and sensitive data. Gemini and Copilot need access to your document data to function, but Lumo never trains on your inputs. (Lumo is available on Premium Proton plans only.)&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Why even the best remote work tools can put you in security debt without you knowing it&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Even genuinely good remote collaboration tools add up to a shaky stack when each one operates under its own security model. A stack with no unified access control, no audit trail, no &lt;a href=&quot;https://proton.me/business/blog/data-sovereignty&quot;&gt;data sovereignty&lt;/a&gt;, and security debt accumulating from day one.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Security debt comes in four types:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Access debt:&lt;/strong&gt; Your stack forces you to manually provide and revoke access across five or six different platforms. It’s on you to remember (and memory is far from 100% reliable). Result: the contractor who left you six months ago &lt;a href=&quot;https://proton.me/business/blog/spreadsheet-security-business-survey&quot;&gt;can still open your files&lt;/a&gt;.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Audit trail debt&lt;/strong&gt;: The access that you’re controlling isn’t recorded anywhere. You know someone accessed that folder, but you can’t prove it. And when a future investor, customer, or regulator asks you who had access to what, when, you haven’t got a good answer.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Jurisdiction debt:&lt;/strong&gt; Your files are sitting on servers that fall under &lt;a href=&quot;https://proton.me/blog/us-tech-rules-europe&quot;&gt;&lt;u&gt;the CLOUD Act&lt;/u&gt;&lt;/a&gt;. You didn’t mean for that to happen: you just chose Dropbox.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Human error debt:&lt;/strong&gt; Fragmentation means more manual steps, which means more human error, which means…? Let’s just say that &lt;a href=&quot;https://proton.me/business/smb-cybersecurity-report&quot;&gt;&lt;u&gt;39% of breaches&lt;/u&gt;&lt;/a&gt; last year were caused by human error.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;None of this is inevitable. Every risk we&amp;#8217;ve listed is easier to cleanly avoid if you choose a more unified stack of remote collaboration tools from Day One.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What a secure remote work stack actually looks like&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/smb-cybersecurity-report&quot;&gt;Most SMBs (66%)&lt;/a&gt; say demonstrating &lt;a href=&quot;https://proton.me/business/drive/cloud-data-security&quot;&gt;cloud data security&lt;/a&gt; (especially as far as client data is concerned) is very or critically important when winning new business. A unified platform gives you that — by closing the gaps where security debt accumulates:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Unified access control:&lt;/strong&gt; One admin layer. Instead of having to work through a six-platform checklist, you need to be able to perform one action to add and remove a team member from your infrastructure.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Encryption by default:&lt;/strong&gt; Your data is encrypted in transit &lt;em&gt;and&lt;/em&gt; at rest. End-to-end encryption means your provider can&amp;#8217;t read your files and can&amp;#8217;t be compelled to hand them over.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Data sovereignty:&lt;/strong&gt; Your data is governed by laws you understand, in a jurisdiction you trust. (Not one that falls under the CLOUD Act.)&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Automatic audit trails:&lt;/strong&gt; So you never need to tell an investor (much less a regulator) that you don’t have one.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Built to scale securely: &lt;/strong&gt;Your permissions, access tiers, and admin controls work whether your company is ten people or 100. No need to rebuild, no need to slow down.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/blog/cybersecurity-for-startups&quot;&gt;Cybersecurity for startups&lt;/a&gt; starts earlier than you think — the earlier you build it in, the less you&amp;#8217;ll have to bolt on (or clean up) later.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Your remote work toolkit, built on Proton Workspace&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;We&amp;#8217;ve already introduced you to Proton Mail, Meet, Drive, Pass, and Lumo in this article. But selecting the best tool for each job doesn&amp;#8217;t automatically close the gaps between those tools. To do that, you need a unified stack like &lt;a href=&quot;https://proton.me/business&quot;&gt;Proton Workspace&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;With Workspace, the security-critical layer of your stack is in safe hands: yours. Your data is under your control, encrypted from end to end (not even Proton can see it) and protected under one of the world’s &lt;a href=&quot;https://proton.me/blog/switzerland&quot;&gt;&lt;u&gt;strongest privacy jurisdictions&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Compliance isn’t a concern: Proton is&lt;strong&gt; &lt;/strong&gt;&lt;a href=&quot;https://proton.me/business/trust&quot;&gt;&lt;u&gt;ISO 27001 certified, GDPR and HIPAA compliant&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You’ll need to add tools on top for management and team messaging. But you&amp;#8217;ll do so on a foundation that&amp;#8217;s already secure.&lt;/p&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Access debt&lt;/strong&gt;:&lt;strong&gt; resolved.&lt;/strong&gt; One admin dashboard. One action to provision a new team member across every Proton service, one to remove them when they leave&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Audit trail debt: resolved.&lt;/strong&gt; Version history, access logs, and granular permissions are built into &lt;a href=&quot;https://proton.me/drive&quot;&gt;&lt;u&gt;Proton Drive&lt;/u&gt;&lt;/a&gt; and &lt;a href=&quot;https://proton.me/drive/docs&quot;&gt;&lt;u&gt;Proton Docs&lt;/u&gt;&lt;/a&gt; by default&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Jurisdiction debt: resolved. &lt;/strong&gt;Headquartered in Switzerland, outside US and EU jurisdiction&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Human error debt: resolved. &lt;/strong&gt;Expiration dates are set on links by default. Files are automatically encrypted in storage. Security is enforced automatically, not manually&lt;/li&gt;
&lt;/ol&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The tools you pick on day one create the security debt you&amp;#8217;ll pay off later. Build on the right foundation, and you can stop worrying about security debt — and start using your security posture as a selling point.&lt;/p&gt;



&lt;div class=&quot;flex flex-wrap justify-center gap-2&quot;&gt;
  &lt;a class=&quot;btn inline-block rounded-full font-bold btn-small btn-solid-purple&quot; href=&quot;https://proton.me/business/&quot;&gt;Try Proton Workspace&lt;/a&gt;
&lt;/div&gt;

</content:encoded><category>For business</category><author>Alanna Alexander</author></item><item><title>Team collaboration software: 7 tools that won’t waste your money</title><link>https://proton.me/business/blog/team-collaboration-software</link><guid isPermaLink="true">https://proton.me/business/blog/team-collaboration-software</guid><description>Your team collaboration software stack isn&apos;t free — it&apos;s just expensive in ways you haven&apos;t counted yet. Here&apos;s how to fix that.</description><pubDate>Thu, 27 Aug 2026 18:35:04 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Most businesses build their team collaboration software stack the same way: one tool at a time, filling needs as they come up. When you’re just starting out, this seems like a reasonable approach.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;But there’s a catch. Approaching the challenge of enabling team collaboration this way is how you end up with a Frankenstein’s monster of a stack, made entirely of parts that are stitched together inorganically.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Even if the parts are good, the disconnection between them causes problems. You’re paying more subscription fees than you can track. You’re not sure who has access to what. And you’re drowning in admin work.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is a guide to taking the alternative route: building a team collaboration stack that has the essential tools in one place and is as consolidated as possible to save you money and time.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;7 team collaboration tools your stack needs&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Every team collaboration stack needs to cover the same ground: chat, email, video, documents, storage, and project management. It’s also worth adding visual collaboration and a knowledge base to that list.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Here are the seven tools you need to cover everything — with privacy built in wherever a genuinely private option exists.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;1. For team chat: Element&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Slack might be the most popular choice for team chat, but it’s not the most private. Element covers the same ground, with video calls, file sharing, and bridges to other chat networks — but it also encrypts private chats and direct messages by default. Element is built on Matrix, an open-source, decentralized protocol, so you can self-host for full control, or use a managed service. In either case, nobody outside the conversation ever holds your decryption keys. (With one exception: Element&amp;#8217;s Enterprise Cloud offers an optional compliance tool that lets admins read conversations, including encrypted ones, but you can keep that switched off if privacy is your priority.)&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;2. For business email and calendar: Proton Mail&amp;nbsp;&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton Mail gives you all the same essential &lt;a href=&quot;https://proton.me/business/mail&quot;&gt;business email&lt;/a&gt; functionality as &lt;a href=&quot;https://proton.me/mail/best-gmail-alternative&quot;&gt;Gmail&lt;/a&gt; or &lt;a href=&quot;https://proton.me/business/mail/outlook-alternative&quot;&gt;Outlook&lt;/a&gt;, with the added bonus of &lt;a href=&quot;https://proton.me/security/end-to-end-encryption&quot;&gt;end-to-end encryption&lt;/a&gt;. Google and Microsoft process messaging content to power search and AI features; Proton Mail’s encrypted architecture ensures your business communications are for your eyes only. &lt;a href=&quot;https://proton.me/business/calendar&quot;&gt;Proton Calendar&lt;/a&gt; is bundled in, so your event details — including meeting titles and guest lists — also stay private, and scheduling doesn&amp;#8217;t require a separate app or another login.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;3. For project and task management: Stackfield&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Stackfield beats out market-favorite Trello on data privacy, applying genuine end-to-end encryption across tasks, chat, files, and project notes, protecting them from exposure to both cybercriminals and court orders. Stackfield also offers jurisdictional safeguards: as a German company hosting exclusively on EU servers, they can’t be reached directly by the US CLOUD Act. But Stackfield isn’t simply a more secure version of Trello: it goes beyond Trello’s boards and cards with list, Kanban, and Gantt views, plus bundled team chat, calendar, and workflow automation.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;4. For video conferencing: Proton Meet&amp;nbsp;&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Zoom might be the go-to for &lt;a href=&quot;https://proton.me/business/meet&quot;&gt;video conferencing&lt;/a&gt; for many businesses, but it&amp;#8217;s far from the most private option. Its AI Companion feature processes call content — including anything commercially sensitive — to generate summaries and transcripts. Proton Meet&amp;#8217;s default end-to-end encryption ensures that what&amp;#8217;s said on a call stays between the people on that call. Guests join with a link and no account, and the free tier covers one-hour calls with up to 50 participants.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;5. For visual collaboration: Miro&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Miro is essentially a digital whiteboard, but its infinite canvas gives distributed teams a shared space for planning, brainstorming, and workshops that no whiteboard — or even chat thread or document — can replicate. Miro packs in enough features that mastering all of it takes time, but getting started takes just minutes: templates for retrospectives and roadmapping sessions mean new teams aren’t starting from a blank canvas.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;6. For cloud storage and document collaboration: Proton Drive&amp;nbsp;&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton Drive offers &lt;a href=&quot;https://proton.me/business/drive&quot;&gt;business cloud storage&lt;/a&gt; that matches &lt;a href=&quot;https://proton.me/drive/google-drive-alternative&quot;&gt;Google Drive&lt;/a&gt; and &lt;a href=&quot;https://proton.me/drive/dropbox-alternative&quot;&gt;Dropbox&lt;/a&gt; on granular per-file permissions and version history. Where it pulls ahead is what happens if a breach occurs. Google and Dropbox need access to your file content to index it for search and power AI features; that means they hold the keys to your contracts, financial records, and product roadmaps, and a breach on their end could expose that content directly. Proton Drive is end-to-end encrypted by default with zero-access architecture: Proton can&amp;#8217;t decrypt your files, so neither can anyone who breaches its servers.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton Drive also covers document collaboration, since &lt;a href=&quot;https://proton.me/business/drive/docs&quot;&gt;&lt;u&gt;Proton Docs&lt;/u&gt;&lt;/a&gt; and&lt;a href=&quot;https://proton.me/business/drive/sheets&quot;&gt; &lt;u&gt;Proton Sheets&lt;/u&gt;&lt;/a&gt; are included with every Proton Drive plan. Docs and Sheets cover the same core functionality as Google and Microsoft’s document tools (real-time co-editing, comments, and version history), while adding end-to-end encryption, ensuring your contracts, drafts, and financial models get the same protection as everything else in your stack.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;7. For a knowledge base: Notion&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Many businesses — particularly those scaling fast — struggle with the chaos that comes with disorganized &lt;a href=&quot;https://proton.me/business/blog/internal-documentation&quot;&gt;internal documentation&lt;/a&gt;. Notion centralizes internal documentation, wikis, and reference material in one searchable space, cutting down on the scattered, outdated copies competing for attention.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Unfortunately, Notion content isn&amp;#8217;t protected by end-to-end encryption, and there isn&amp;#8217;t any end-to-end encrypted alternative with the same wiki structure. If your team stores confidential client files, strategy documents, product plans, or company IP in the cloud, we recommend using a more secure &lt;a href=&quot;https://proton.me/drive/notion-alternative&quot;&gt;Notion alternative&lt;/a&gt;: Proton Drive. &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It doesn&amp;#8217;t replicate Notion&amp;#8217;s wiki structure, but real-time co-editing and zero-access encryption beat an unencrypted wiki for anything sensitive.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;The hidden cost of a disconnected collaboration stack&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Let’s say you’re starting from scratch and decide to go with the seven tools we recommend. Here’s how your collaboration stack will look (notice that there are’s only seven rows, as Drive includes both Docs and Sheets) — and it looks pretty solid.&lt;/p&gt;



&lt;figure class=&quot;wp-block-table&quot;&gt;&lt;table class=&quot;has-fixed-layout&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Best for&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Pricing&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Key feature&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Element&lt;/td&gt;&lt;td&gt;Team chat&lt;/td&gt;&lt;td&gt;Free (self-hosted Community edition); Enterprise/Sovereign = custom quote (no public per-seat price)&lt;/td&gt;&lt;td&gt;End-to-end encrypted by default, self-hostable, built on open-source &amp;amp; audited Matrix protocol&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Proton Mail&lt;/td&gt;&lt;td&gt;Business email&lt;/td&gt;&lt;td&gt;Mail Essentials (includes &lt;a href=&quot;https://proton.me/business/calendar&quot;&gt;&lt;u&gt;Proton Calendar&lt;/u&gt;&lt;/a&gt;) $6.99/user/month(annual)&amp;nbsp;&lt;/td&gt;&lt;td&gt;Shared domain, encrypted calendar and contacts built in&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Proton Meet&lt;/td&gt;&lt;td&gt;Video conferencing&lt;/td&gt;&lt;td&gt;Meet Professional&lt;br&gt;$7.99/user/month(annual)&lt;/td&gt;&lt;td&gt;Link-based guest access, no download required&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Proton Drive&amp;nbsp;&lt;/td&gt;&lt;td&gt;Cloud storage &amp;amp; document collaboration&lt;/td&gt;&lt;td&gt;Drive Professional (also includes &lt;a href=&quot;https://proton.me/business/drive/sheets&quot;&gt;&lt;u&gt;Proton Sheets&lt;/u&gt;&lt;/a&gt;)&lt;br&gt;$7.99/user per month&lt;br&gt;(annual)&lt;/td&gt;&lt;td&gt;Granular per-file permissions, realtime co-editing, version history&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Stackfield&lt;/td&gt;&lt;td&gt;Project &amp;amp; task management&lt;/td&gt;&lt;td&gt;Business €14/user/mo (~$16.20 USD, converted to USD at ~1.157)&lt;/td&gt;&lt;td&gt;End-to-end encrypted chat, tasks, files &amp;amp; docs; EU-only hosting (Germany)&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Miro&lt;/td&gt;&lt;td&gt;Visual collaboration&lt;/td&gt;&lt;td&gt;Free; Starter from $8/user/mo (annual)&lt;/td&gt;&lt;td&gt;Infinite canvas, templates for recurring sessions&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Notion&lt;/td&gt;&lt;td&gt;Knowledge base&lt;/td&gt;&lt;td&gt;Free; Plus from $10/user/mo (annual)&lt;/td&gt;&lt;td&gt;Pages, databases, wikis (note: no end-to-end encryption)&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/figure&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;However, if these tools are all running individually, not consolidated under one platform, you’re opening yourself up to three big problems.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;1. The hidden subscription bill&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Individually, the tools in our seven-tool stack don’t seem to cost that much. However, add the six subscriptions with public pricing up (Element doesn&amp;#8217;t publish a per-seat price), and — at the time of writing — a team of 25 is running up a bill of approximately $17,151 a year. And your team probably isn’t even using every seat.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It’s easy to lose track of what you’re spending on a set of disconnected team collaboration tools. You know they’re automatically renewing, but you’re reluctant to cancel the one you suspect nobody’s using because that means finding the login details. Or you’re worried that someone on your team must need it. (Why else would you have it?)&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;2. The cost of insecurity&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Disconnected tools multiply your attack surface, with each surface a potential misconfiguration waiting to happen. In the long run, that could cost you dearly. Proton research shows that 25% of SMBs experienced a data breach last year, and 57% of &lt;a href=&quot;https://proton.me/business/smb-cybersecurity-report&quot;&gt;breached SMBs&lt;/a&gt; lost between $10,000–$100,000.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;3. The burden of admin&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Time is money, and multiple tools demand that you spend a lot of both. Think of all that time spent adding and revoking permissions across seven tools (assuming you remember to), or reconciling seven separate invoices, or trying to figure out if anybody’s actually using that Miro seat you’ve been paying for since March. All these costs might not show up on one invoice. But they’re there.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What a consolidated collaboration stack gives you&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The answer to reducing the cost and waste of a disconnected stack isn’t better tools, and it certainly isn’t &lt;em&gt;more&lt;/em&gt; tools. The answer is a team collaboration platform that covers as many of the functions your disconnected tools are currently fulfilling as possible, while also giving you a secure and easily administered foundation for whatever other tools you need.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Pick your platform wisely, and replacing multiple tools with one platform will simplify and secure your team collaboration in a single stroke. When you have one platform handling team communication, file storage, document collaboration, and admin, you’re only dealing with:&lt;/p&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;One bill,&lt;/strong&gt; &lt;strong&gt;one renewal date, with one owner. &lt;/strong&gt;Zero autopilot charges for unused tools&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;One admin dashboard &lt;/strong&gt;to control &lt;a href=&quot;https://proton.me/business/drive/templates/onboarding-checklist&quot;&gt;onboarding&lt;/a&gt;, &lt;a href=&quot;https://proton.me/business/drive/templates/offboarding-checklist&quot;&gt;offboarding&lt;/a&gt;, and access permissions. (No contractors hanging around in your Dropbox months after project completion)&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;One security model, &lt;/strong&gt;with one permissions system to administer, no gaps between tools, and no seven-tool misconfiguration risk&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;One audit trail &lt;/strong&gt;so you can see who accessed what, when, all in one place (and provide proof when investors or regulators come calling)&lt;/li&gt;
&lt;/ol&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A consolidated, encrypted stack won’t just save you in subscriptions and security incidents. It sends a signal to your customers that you’re serious about handling their data seriously. It lets investors know that your operations are under control.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;The platform to consolidate your stack: Proton Workspace&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;With our digital &lt;a href=&quot;https://proton.me/business&quot;&gt;workspace platform&lt;/a&gt; for businesses Proton Workspace, you get all the Proton products and features we’ve mentioned on one platform: Mail (including Calendar), Meet, and Drive (including Docs and Sheets).&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Instead of running those products as separate subscriptions, each with its own admin panel and its own bill, you get all of them under one account and one security model.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;The subscription saving: &lt;/strong&gt;purchasing Mail, Meet, and Drive as separate subscriptions costs more than getting them together, since each one carries its own base fee on top of your per-seat pricing. Proton Workspace consolidates all of them into a single line item instead. Proton Workspace doesn&amp;#8217;t replace Element, Stackfield, Miro, or Notion (you&amp;#8217;ll still need separate tools for chat, project management, visual collaboration, and wiki-style knowledge sharing) but on the tools it does replace, the saving is meaningful.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;The admin relief: &lt;/strong&gt;Instead of three dashboards, you have one. Instead of three invoices on three different renewal dates, one. You can see exactly who&amp;#8217;s using what, so no more paying for seats nobody&amp;#8217;s touched since March. And when someone joins or leaves, &lt;a href=&quot;https://proton.me/business/drive/templates/onboarding-checklist&quot;&gt;onboarding&lt;/a&gt; and &lt;a href=&quot;https://proton.me/business/drive/templates/offboarding-checklist&quot;&gt;offboarding&lt;/a&gt; means one action for each user, not three. (And no more contractors retaining access to folders that are no longer their business.)&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;The security foundation: &lt;/strong&gt;You’ve established a secure foundation for collaboration. Proton Workspace is ISO 27001 certified, and GDPR and HIPAA compliant. All its services keep your data protected with &lt;a href=&quot;https://proton.me/security/end-to-end-encryption&quot;&gt;&lt;u&gt;end-to-end encryption&lt;/u&gt;&lt;/a&gt; and &lt;a href=&quot;https://proton.me/blog/switzerland&quot;&gt;&lt;u&gt;Swiss jurisdiction&lt;/u&gt;&lt;/a&gt;. Not even Proton can access your files.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;On top of this, you get extra products bundled in: Workspace Standard subscribers get a &lt;a href=&quot;https://proton.me/business/vpn&quot;&gt;&lt;u&gt;business VPN&lt;/u&gt;&lt;/a&gt; and &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;&lt;u&gt;team password manager&lt;/u&gt;&lt;/a&gt; bundled in; Premium subscribers get these, plus Lumo, our &lt;a href=&quot;https://proton.me/business/lumo&quot;&gt;business AI assistant&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Migrating your email and calendar to Proton is straightforward: Proton&amp;#8217;s &lt;a href=&quot;https://proton.me/easyswitch&quot;&gt;&lt;u&gt;Easy Switch&lt;/u&gt;&lt;/a&gt; tool imports your existing emails, contacts, and calendars automatically (including from &lt;a href=&quot;https://proton.me/mail/best-gmail-alternative&quot;&gt;Gmail&lt;/a&gt;).&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Few SMBs get their collaboration stack right the first time around. The right &lt;a href=&quot;https://proton.me/business&quot;&gt;team collaboration platform&lt;/a&gt; is the one your team uses, your admin controls, and your finance team can see on one invoice.&lt;/p&gt;



&lt;div class=&quot;flex flex-wrap justify-center gap-2&quot;&gt;
  &lt;a class=&quot;btn inline-block rounded-full font-bold btn-small btn-solid-purple&quot; href=&quot;https://proton.me/business/&quot;&gt;Try Proton Workspace&lt;/a&gt;
&lt;/div&gt;
</content:encoded><category>For business</category><author>Alanna Alexander</author></item><item><title>AI is making phishing attacks more sophisticated: What can businesses do about it?</title><link>https://proton.me/business/blog/ai-phishing-attacks</link><guid isPermaLink="true">https://proton.me/business/blog/ai-phishing-attacks</guid><description>Learn how AI phishing attacks are changing business risk, from AI-generated emails to deepfake phishing, and how to protect your team.</description><pubDate>Thu, 27 Aug 2026 17:46:23 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;AI &lt;a href=&quot;https://proton.me/business/blog/phishing-attacks&quot;&gt;phishing attacks&lt;/a&gt; are changing one of the oldest rules in security awareness: bad grammar is no longer a reliable red flag.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For years, employees were taught to look for awkward wording, strange formatting, spelling errors, and generic greetings. These clues are still important, but they can’t detect AI-powered phishing attacks.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Generative AI can help attackers write personalized messages in seconds. It can imitate a company’s tone, summarize public information about an employee, turn a short prompt into a convincing invoice request, or localize a scam to sound native in any target language.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;However, this isn’t a completely new threat. It’s leveled up &lt;a href=&quot;https://proton.me/blog/what-is-phishing&quot;&gt;phishing&lt;/a&gt; with better writing, faster preparation, and more convincing impersonation. Phishing still aims to make someone click, share credentials, approve a payment, open a file, or move a conversation to a channel the attacker controls. AI simply makes that manipulation more convincing and easier to scale.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Within businesses, teams need to build new habits. We’ll explain what to look for and how to build better phishing and &lt;a href=&quot;https://proton.me/business/pass/data-breach-protection&quot;&gt;data breach protections&lt;/a&gt; within your business network.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#how-are&quot;&gt;How are AI phishing attacks different?&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#look-like-real&quot;&gt;AI-generated phishing emails look like real work&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#new-forms&quot;&gt;New forms of AI social engineering&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#why-SMBS&quot;&gt;Why SMBs are increasingly exposed&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#how-to-adapt&quot;&gt;How to adapt your phishing training to AI-enabled attacks&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#what-businesses&quot;&gt;What businesses need to do differently&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#how-proton-pass&quot;&gt;How Proton Pass for Business helps reduce credential risk&lt;/a&gt;&lt;/p&gt;



&lt;h2 id=&quot;how-are&quot; class=&quot;wp-block-heading&quot;&gt;How are AI phishing attacks different?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Before generative AI, phishing required more manual effort. Attackers had to research a target, write believable copy, adjust the tone, and sometimes translate messages for different markets. Generative AI lowers these barriers to entry significantly.&amp;nbsp;&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The UK National Cyber Security Centre’s report on the &lt;a href=&quot;https://www.ncsc.gov.uk/report/impact-ai-cyber-threat-now-2027&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;impact of AI on cyber threats&lt;/a&gt; from now to 2027 notes that AI will almost certainly make parts of cyber intrusion more effective and efficient, increasing the frequency and intensity of cyber threats. It also notes that threat actors are already using AI to improve existing tactics, including &lt;a href=&quot;https://proton.me/blog/what-is-social-engineering&quot;&gt;social engineering&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Attackers can now produce phishing attack messages that look more natural and more specific. A scam email can refer to a real supplier, a recent LinkedIn post, a job title, a regional event, or an internal project name. Even when the attacker has limited information, AI can fill the gaps with language that sounds plausible.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The warning signs of a phishing attack remain the same. Suspicious links, urgent requests, unexpected attachments, and strange sender domains still matter. But the content itself is no longer enough to give the attack away.&lt;/p&gt;



&lt;figure class=&quot;wp-block-table&quot;&gt;&lt;table class=&quot;has-fixed-layout&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Traditional phishing attacks&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;AI-powered phishing attacks&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Often have typos, awkward grammar, or generic greetings&lt;/td&gt;&lt;td&gt;Can use polished, natural writing with the right tone&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Usually rely on broad, generic messages&lt;/td&gt;&lt;td&gt;Can include personal details, company context, or vendor references&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Mostly appear as suspicious emails&lt;/td&gt;&lt;td&gt;Can combine email, voice cloning, fake invoices, and deepfake video&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/figure&gt;



&lt;h2 id=&quot;look-like-real&quot; class=&quot;wp-block-heading&quot;&gt;AI-generated phishing emails look like real work&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Phishing attacks have always ranged from crude to highly sophisticated, but generative AI lowers the skill and time needed to produce messages that are fluent, well-structured, and written in professional-sounding language.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The NCSC’s&lt;a href=&quot;https://www.ncsc.gov.uk/guidance/phishing&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt; phishing guidance&lt;/a&gt; notes that phishing campaigns may try to steal sensitive information like passwords, or trick people into transferring money. It also explains that more targeted campaigns use information about employees or the company to make messages feel more realistic. AI makes that easier to do at scale.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Defense against modern phishing attacks requires layered controls rather than a single filter: &lt;a href=&quot;https://proton.me/business/blog/multi-factor-authentication-business&quot;&gt;multi-factor authentication&lt;/a&gt; (MFA) to make stolen credentials less of a threat, verified communication processes for critical requests, and employee training to recognize social engineering before credentials are surrendered.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Secure &lt;a href=&quot;https://proton.me/business/pass/credential-management&quot;&gt;credential management&lt;/a&gt; is also a key aspect of your defenses. A &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt; like Proton Pass for Business makes it easy to generate a strong, unique password for every account. You can also monitor for exposure within your business network, so even if a team member is convinced by a single message, their credentials can’t unlock more than one account.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For employees, phishing awareness needs to evolve in order to detect these new AI-powered threats. It requires asking yourself three questions:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Does this email look fake?&lt;/li&gt;



&lt;li&gt;Does this request make sense?&lt;/li&gt;



&lt;li&gt;Have I verified it or can I verify it through a trusted channel?&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Going beyond the spelling and formatting of the email and looking at the wider context in which it was sent can go a long way. A polished email can still be a phishing attempt if it asks for credentials, changes payment details, creates unusual urgency, or pushes someone outside the normal process.&lt;/p&gt;



&lt;h2 id=&quot;new-forms&quot; class=&quot;wp-block-heading&quot;&gt;New forms of AI social engineering&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;AI phishing isn’t limited to email. Attackers can now use AI to combine text, voice, images, and video into a single convincing story.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;AI-generated spear phishing&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/blog/whaling-spear-phishing&quot;&gt;Spear phishing&lt;/a&gt; works because the message is targeted to the person receiving it. AI makes targeting even easier: An attacker no longer needs to spend as much time writing from scratch or adapting the tone for each target. They can use public information, &lt;a href=&quot;https://proton.me/blog/journalist-data-leaks&quot;&gt;leaked data&lt;/a&gt;, or a compromised inbox to create a message that appears legitimate.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That could be a contract update that arrives at the right moment, a candidate file sent to HR, a vendor request that uses familiar language, or a payment instruction that matches the rhythm of normal finance work. The danger is not perfection, but plausibility. A spear phishing message only needs to feel relevant enough for someone to open the file, approve the request, or enter their credentials before they stop to verify.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Voice cloning and vishing&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/blog/vishing-attacks-business&quot;&gt;Vishing&lt;/a&gt;, or voice phishing, is becoming more convincing as AI-generated audio improves. The &lt;a href=&quot;https://www.ic3.gov/PSA/2025/PSA250515&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;FBI’s Internet Crime Complaint Center warned in 2025&lt;/a&gt; about malicious actors using text messages and AI-generated voice messages to impersonate senior US officials. The alert explains that vishing may incorporate AI-generated voices and recommends verifying callers through independently identified contact details.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton’s&lt;a href=&quot;https://proton.me/business/blog/data-breach-observatory-2026&quot;&gt; Data Breach Observatory 2026&lt;/a&gt; also highlights the rise of vishing campaigns, including coordinated attacks that led to large-scale breaches and exposed tens of millions of records. The same report found that passwords appeared in 47% of tracked incidents, showing why &lt;a href=&quot;https://proton.me/blog/what-is-social-engineering&quot;&gt;social engineering&lt;/a&gt; and credential protection are closely connected.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Deepfake phishing in video calls&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Deepfake phishing can also happen through video. In 2024, a finance worker in Hong Kong was&lt;a href=&quot;https://www.cnn.com/2024/02/04/asia/deepfake-cfo-scam-hong-kong-intl-hnk&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt; reportedly tricked into transferring about $25 million&lt;/a&gt; after fraudsters used deepfake video to impersonate senior colleagues during a video meeting.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Seeing a familiar face on a call is no longer enough to approve a sensitive request. Large payments, &lt;a href=&quot;https://proton.me/pass/password-sharing&quot;&gt;credential sharing&lt;/a&gt;, access changes, and unusual requests still need a separate verification step through a trusted channel.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;AI-generated fake invoices&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Invoice fraud is much easier with AI. A fake invoice can use polished language, realistic payment terms, a familiar supplier name, and a plausible explanation for a bank detail change. If the attacker has access to a breached inbox or leaked vendor information, the request may look even more believable.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A polished invoice should not be enough to move money. If the bank details have been changed, the timing feels unusual, or the message asks someone to skip the normal approval flow, the request needs to be checked through a trusted channel before anyone pays it.&lt;/p&gt;



&lt;h2 id=&quot;why-SMBS&quot; class=&quot;wp-block-heading&quot;&gt;Why SMBs are increasingly exposed&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;AI has changed the economics of phishing by lowering the cost of targeting. In the past, highly personalized attacks were more likely to focus on large companies because they took more time to prepare. AI makes it easier to create targeted messages for smaller businesses. Attackers can generate more variants, test more angles, and adapt messages quickly without spending the same amount of time or effort.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Smaller businesses are attractive because money, access, and decision-making are often concentrated between fewer people. One person may approve invoices, manage vendor relationships, and hold access to several business tools. When processes are informal, one convincing AI-generated request can reach payment workflows, shared accounts, customer data, or admin systems before anyone has a chance to challenge it.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The risk is visible in breach data too. The same Proton &lt;a href=&quot;https://proton.me/business/pass/breach-observatory&quot;&gt;Data Breach Observatory&lt;/a&gt; report found that SMBs accounted for 63% of breaches tracked since January 2025 and were disproportionately affected by critical incidents involving sensitive data such as authentication data, personal identifiers, or financial details.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;AI helps attackers exploit weaknesses small businesses already have: reused passwords, informal credential sharing, weak approval processes, and training that still assumes scams will look obvious.&lt;/p&gt;



&lt;h2 id=&quot;how-to-adapt&quot; class=&quot;wp-block-heading&quot;&gt;How to adapt your phishing training to AI-enabled attacks&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;To properly combat AI phishing attacks, your &lt;a href=&quot;https://proton.me/business/blog/security-awareness-training&quot;&gt;security awareness&lt;/a&gt; requires more consideration than checking for typos. Employees need to learn how to verify the request, not just judge the message.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The baseline your training needs is simple: If a request is unusual, sensitive, or urgent, verify it before acting:&lt;/p&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Stop before replying, don’t respond on the same email thread.&lt;/li&gt;



&lt;li&gt;Ignore the contact details in the message, never use the phone number, link, or reply address it provides.&lt;/li&gt;



&lt;li&gt;Don’t treat a voice or video call as proof, because a familiar voice on a call or a familiar face on screen can both be generated.&lt;/li&gt;



&lt;li&gt;Reach the person through a channel you already trust, an internal directory, a saved vendor record, or a previously verified contact method.&lt;/li&gt;



&lt;li&gt;Confirm the request itself, not just the sender, ask whether the payment, access change, or file request is real.&lt;/li&gt;
&lt;/ol&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Training should also focus on helping team members spot the moments where AI phishing is most likely to succeed:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Payment detail changes&lt;/li&gt;



&lt;li&gt;Requests for passwords, recovery codes, or MFA approvals&lt;/li&gt;



&lt;li&gt;Urgent file-sharing requests&lt;/li&gt;



&lt;li&gt;Unusual login prompts&lt;/li&gt;



&lt;li&gt;Vendor portal changes&lt;/li&gt;



&lt;li&gt;Executive requests that bypass normal processes&lt;/li&gt;



&lt;li&gt;Invitations to move a conversation to a personal messaging app&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton’s guide to building a &lt;a href=&quot;https://proton.me/blog/small-business-cyber-security-culture-workplace&quot;&gt;small business cybersecurity culture&lt;/a&gt; in the workplace is a useful and timely resource for making security behavior part of daily work.&lt;/p&gt;



&lt;h2 id=&quot;what-businesses&quot; class=&quot;wp-block-heading&quot;&gt;What businesses need to do differently&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;AI-powered phishing changes the standard for verification. If the message looks real, the process has to catch what’s no longer immediately obvious.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Use out-of-band verification&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When a request involves money, credentials, sensitive files, or privileged access, the reply should not stay inside the same thread that created the risk. The team needs a second path to confirm whether the request is real.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That might mean calling a supplier using a number already saved in the vendor record, checking an executive request through an internal channel, or confirming access changes with the project owner. The key is to use contact details the business already trusts, not the phone number, link, or reply path provided in the suspicious message.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Require multi-person approval&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;High-risk actions should not depend on one person’s judgment. Payment changes, large transfers, new vendor bank details, privileged access grants, and bulk data exports should require a second approval to reduce &lt;a href=&quot;https://proton.me/business/blog/vulnerability&quot;&gt;vulnerability&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;One urgent-looking message doesn’t need to derail normal work. A second approval gives the team a pause point before money is transferred, access is granted, or sensitive data leaves the business.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Protect credentials before they are targeted&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;AI phishing often ends at the same place as traditional phishing: credentials. The attacker wants a password, a session token, an MFA approval, or access to an account that opens the door to other systems.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;IBM’s&lt;a href=&quot;https://www.ibm.com/reports/data-breach&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt; Cost of a Data Breach Report 2025&lt;/a&gt; recommends strengthening identity security and adopting phishing-resistant authentication methods to reduce the risk of credential abuse. It also reports a global average breach cost of $4.4 million, showing why identity and access controls have financial consequences, not just technical ones.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Containment is key for SMBs. AI may make the first message harder to detect, but the business can still control what happens after a mistake. Strong, unique passwords, MFA, &lt;a href=&quot;https://proton.me/pass/password-sharing&quot;&gt;secure sharing&lt;/a&gt;, limited admin access, and consistent &lt;a href=&quot;https://proton.me/business/drive/templates/offboarding-checklist&quot;&gt;offboarding&lt;/a&gt; reduce the chance that one compromised account turns into access across email, finance tools, &lt;a href=&quot;https://proton.me/business/drive&quot;&gt;enterprise cloud storage&lt;/a&gt;, or other business systems.&lt;/p&gt;



&lt;h2 id=&quot;how-proton-pass&quot; class=&quot;wp-block-heading&quot;&gt;How Proton Pass for Business helps reduce credential risk&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Your organization&amp;#8217;s &lt;a href=&quot;http://proton.me/business/pass/password-policy&quot;&gt;password policy&lt;/a&gt; should bring credential habits under control before an employee is targeted. Limit password reuse across business accounts, use encrypted &lt;a href=&quot;https://proton.me/business/pass/password-vault&quot;&gt;password vaults&lt;/a&gt;, keep sensitive access out of browsers, spreadsheets, and chat threads, and provide secure sharing options. Those measures give teams a controlled way to grant or remove access without searching through old messages or documents.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt; like Proton Pass for Business limits how much damage a phishing attack can do. When credentials are unique, encrypted, and centrally managed, a single successful message compromises one account instead of opening a path across email, finance tools, and cloud storage. It works alongside awareness training, email filtering, and payment controls rather than replacing them.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton Pass for Business also helps teams &lt;a href=&quot;https://proton.me/pass/password-generator&quot;&gt;generate strong passwords&lt;/a&gt;, use autofill, and manage credentials through centralized admin controls. Unique passwords, strong authentication, secure credential sharing, and controlled access make it harder for one successful phishing attempt to spread across the business.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Protect your team from AI-powered phishing with a &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt;.&lt;/p&gt;
</content:encoded><category>For business</category><author>Ben Wolford</author></item><item><title>Data exfiltration: how attackers steal business data and how to stop them</title><link>https://proton.me/business/blog/data-exfiltration-prevention</link><guid isPermaLink="true">https://proton.me/business/blog/data-exfiltration-prevention</guid><description>Getting in is only half the attack. Learn how data exfiltration works, why it goes undetected for months, and how to catch it early.</description><pubDate>Thu, 27 Aug 2026 16:36:47 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Most breach prevention advice, including our own guide to &lt;a href=&quot;https://proton.me/blog/data-breach-prevention-for-businesses&quot;&gt;preventing data breaches&lt;/a&gt;, is focused on keeping attackers out of your business network. Using stronger credentials, &lt;a href=&quot;https://proton.me/blog/what-is-phishing&quot;&gt;phishing&lt;/a&gt; resistance, patched systems, vetted suppliers are all key components of this practice. They’re all essential practices, but they can’t be your only &lt;a href=&quot;https://proton.me/business/pass/data-breach-protection&quot;&gt;data breach protection&lt;/a&gt; tactics: they won’t support you if an attacker manages to breach your network.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Gaining access and data theft are different. An attacker who compromises one inbox, one laptop, or one supplier connection has not yet stolen anything. They&amp;#8217;ve gained a foothold, and what happens between that foothold and the moment data leaves the building is a phase most SMB security guidance skips entirely, because it isn&amp;#8217;t just about securing your network; it&amp;#8217;s also about noticing that data is being moved outside of it.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This phase is called exfiltration, and it typically lasts for days or even stretches across months undetected. It’s possible because of tools and channels that look completely ordinary to anyone not specifically watching for them. Breach notifications frequently arrive late not because organizations were careless about the initial compromise, but because the attacker wasn’t detected inside the business network.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#access-theft&quot;&gt;The exfiltration phase: what happens between access and theft&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#what-exfiltration-looks&quot;&gt;What data exfiltration looks like&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#difficult&quot;&gt;Why is exfiltration difficult to spot?&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#monitor&quot;&gt;What businesses should monitor for&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#early-detection&quot;&gt;How early detection can change your legal position&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#exfiltrated-data&quot;&gt;What happens to exfiltrated business data?&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#contain&quot;&gt;Contain what an attacker can reach&lt;/a&gt;&lt;/p&gt;



&lt;h2 id=&quot;access-theft&quot; class=&quot;wp-block-heading&quot;&gt;The exfiltration phase: what happens between access and theft&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Once an attacker gains initial access, whether through a phishing email, a stolen credential, or a compromised supplier connection, they rarely move straight to stealing data. Acting immediately risks triggering an alert before they&amp;#8217;ve found anything worth taking, so the more common pattern is patience.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The attacker spends time mapping the environment, including:&amp;nbsp;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Where financial records are stored&lt;/li&gt;



&lt;li&gt;Assessing which SaaS tools contain customer data&lt;/li&gt;



&lt;li&gt;Locating accounts with the broadest access&lt;/li&gt;



&lt;li&gt;Detecting whether activity monitoring, if any, is in place.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This reconnaissance stage can be slow. Some attackers move within hours, particularly in opportunistic &lt;a href=&quot;https://proton.me/blog/ransomware-attack&quot;&gt;ransomware cases&lt;/a&gt; where speed matters more than stealth. Others, especially in cases built around long-term data theft or espionage, stay embedded for weeks or months, learning normal patterns of activity well enough to blend into them.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Either way, by the time the attacker starts moving data out, they usually already know exactly what they want and which account or system will let them take it without tripping an alarm.&lt;/p&gt;



&lt;h2 id=&quot;what-exfiltration-looks&quot; class=&quot;wp-block-heading&quot;&gt;What data exfiltration looks like&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Malicious exfiltration is difficult to spot because it looks like everyday activity. IT admins aren’t looking for slightly larger file transfers than usual or folders synced somewhere they shouldn&amp;#8217;t be.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Large or unusual data transfers&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is the most direct form of exfiltration. For example, an account may suddenly pull gigabytes from a file server or database it normally touches only occasionally, or bulk export from a CRM or HR platform.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In SaaS-heavy environments, exfiltration often happens through the platform&amp;#8217;s own export features: bulk CSV downloads, PDF exports of customer records, or a sequence of screenshots taken of a dashboard that doesn&amp;#8217;t have an export button at all.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A typical case might look like this: a compromised HR account is used, over several weeks, to run small, staggered exports of employee records rather than one obvious bulk download. Each individual export looks unremarkable on its own, well within what an HR platform expects someone in that role to do.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It&amp;#8217;s only the pattern across weeks, the same account exporting similar data at odd intervals, that would reveal what&amp;#8217;s happening, and that pattern only becomes visible to a business that&amp;#8217;s looking for it.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Inbox compromise&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;An attacker who compromises a &lt;a href=&quot;https://proton.me/business/mail&quot;&gt;business email&lt;/a&gt; mailbox can set up a rule that silently copies every message, or every message matching certain keywords, to an external address, giving them an ongoing feed of sensitive correspondence long after the original phishing email is forgotten.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Cloud storage compromise&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Personal cloud storage is another common route. An employee&amp;#8217;s compromised laptop, or a compromised account with access to company files, can be used to copy documents into a personal &lt;a href=&quot;https://proton.me/drive/dropbox-alternative&quot;&gt;Dropbox&lt;/a&gt;, &lt;a href=&quot;https://proton.me/drive/google-drive-alternative&quot;&gt;Google Drive&lt;/a&gt;, or similar service, a transfer that often looks identical to a legitimate file backup unless someone is checking where the data ended up.&amp;nbsp;&lt;/p&gt;



&lt;h2 id=&quot;difficult&quot; class=&quot;wp-block-heading&quot;&gt;Why is exfiltration difficult to spot?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The uncomfortable truth about exfiltration is that it usually doesn&amp;#8217;t require any &lt;a href=&quot;https://protonvpn.com/blog/what-is-malware&quot;&gt;malware&lt;/a&gt; at all. An attacker using a compromised account to export a report, forward some emails, or upload files to a cloud drive is using the same tools and permissions a legitimate employee uses every day.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;There&amp;#8217;s no suspicious executable for antivirus software to flag, or any unusual processes for endpoint detection to catch, because nothing about the activity is technically abnormal. It only looks wrong in context, and context is exactly what most SMB security tooling isn&amp;#8217;t built to evaluate.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is why perimeter-focused defenses, however well implemented, aren’t enough on their own. A business can do everything right at the point of entry, enforce strong credentials, train employees against phishing, patch every system, and still have no way of knowing that a compromised account is steadily moving files to an external destination, because that activity was never designed to look suspicious in the first place.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Security researchers sometimes call this “living off the land”: using the target&amp;#8217;s own legitimate software, cloud integrations, and administrative tools rather than using any tools that an antivirus product would recognize as illegitimate.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A file sync client, a built-in export feature, or a standard email rule aren’t malicious tools in themselves. This is why an attacker who relies on them can operate for so long without setting off anything designed to catch malware.&lt;/p&gt;



&lt;h2 id=&quot;monitor&quot; class=&quot;wp-block-heading&quot;&gt;What businesses should monitor for&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Catching exfiltration early comes down to watching for a small number of specific signals, rather than scanning broadly for suspicious activity.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Traffic and exports&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Unusual data transfer volumes or destinations deserve the closest attention. Your organization should be watching for a spike in outbound traffic, a bulk export from a system that doesn&amp;#8217;t normally see them, or any transfer heading to a destination you don’t recognize.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The &lt;a href=&quot;https://www.ncsc.gov.uk/collection/10-steps/data-security&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;NCSC&amp;#8217;s guidance on data security&lt;/a&gt; specifically recommends logging access to sensitive data and monitoring for unusual queries or attempted bulk exports, precisely because that pattern is a sign that something has moved beyond normal use.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Email forwarding rules&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/blog/how-to-forward-emails&quot;&gt;Email forwarding rules&lt;/a&gt; are worth auditing directly, especially for any account that has been involved in a suspected phishing incident. A rule quietly forwarding messages to an unfamiliar address can sit unnoticed for months, and it&amp;#8217;s one of the simplest things to check once you know to look.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Unusual logins&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Login activity from unexpected locations or times is a signal worth taking seriously. A login at 3 AM from a country the business has no presence in isn&amp;#8217;t proof of anything on its own, but when cross-referenced with a data transfer around the same time, it&amp;#8217;s a detail that can confirm an incident.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Admin account activity outside business hours deserves particular scrutiny, since admin accounts typically have the broadest reach into a system and are a preferred target precisely because of that reach.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Activity on these accounts late at night, on weekends, or during a period when the actual administrator is known to be out of office is one of the more reliable indicators that an account, not just a device, has been compromised.&lt;/p&gt;



&lt;h2 id=&quot;early-detection&quot; class=&quot;wp-block-heading&quot;&gt;How early detection can change your legal position&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Under both EU GDPR and UK GDPR, &lt;a href=&quot;https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32016R0679#d1e3300-1-1&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Article 33&lt;/a&gt; gives organizations 72 hours to notify the relevant supervisory authority once they become aware that a breach affecting personal data has occurred; &lt;a href=&quot;https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach/personal-data-breaches-a-guide/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;the ICO in the UK&lt;/a&gt; or the national data protection authority in each EU member state. &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The requirement is materially the same for all jurisdictions: the clock starts for your organization at the moment of awareness, not from the moment the breach actually happened. This is why thorough exfiltration monitoring matters so much for compliance, not just security.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A business that detects exfiltration early, through forwarding-rule audits, transfer monitoring, or unusual login alerts, can notify proactively, on its own timeline, with a reasonably clear picture of what was taken.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A business that only discovers a breach weeks or months later, often because a customer complained or stolen data surfaced on a criminal forum, is notifying reactively, under pressure, often with an incomplete picture of scope and a regulator asking why it took so long to notice.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The difference goes beyond how your reputation is affected. It shapes how the entire incident is assessed, and how much latitude a regulator is inclined to extend.&lt;/p&gt;



&lt;h2 id=&quot;exfiltrated-data&quot; class=&quot;wp-block-heading&quot;&gt;What happens to exfiltrated business data?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton&amp;#8217;s &lt;a href=&quot;https://proton.me/business/pass/breach-observatory&quot;&gt;Data Breach Observatory&lt;/a&gt; tracks what surfaces on the dark web once a breach has occurred, and the pattern is a useful reality check on what exfiltration is really after.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;According to the &lt;a href=&quot;https://proton.me/blog/data-breach-observatory-2026&quot;&gt;2026 Data Breach Observatory update&lt;/a&gt;, names and email addresses appear in nearly nine out of ten tracked breaches, contact details such as phone numbers and physical addresses show up in roughly three-quarters of them, and passwords are exposed in close to half.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;More sensitive categories, government-issued IDs, health records, and other &lt;a href=&quot;https://proton.me/business/blog/pii&quot;&gt;personally identifiable information&lt;/a&gt;, appear in just over a third of breaches, while direct financial information shows up in a smaller share, around one in twenty.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;SMBs make up the majority of breaches the Observatory tracks, and they are disproportionately represented among the incidents involving the most sensitive data categories.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This combination, frequent targeting and a high rate of sensitive-data exposure, is consistent with the type of exfiltration this article describes: attacks that occur over a long period of time within a smaller organization&amp;#8217;s systems tend to pay more dividends, because nobody knew that data was being leaked and attackers could take everything.&lt;/p&gt;



&lt;h2 id=&quot;contain&quot; class=&quot;wp-block-heading&quot;&gt;Contain what an attacker can reach&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Exfiltration monitoring catches data on its way out, but the size of the problem is decided earlier, by what a compromised account can reach in the first place. An attacker who gains access to an account with broad, unrestricted permissions can pull from far more systems than one who compromises an account scoped tightly to what that specific role needs.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Unique credentials on every account, combined with access limited to what a role genuinely requires, directly shrinks the exfiltration surface. If a compromised marketing account can only reach marketing systems, the worst-case scenario is bounded by design, rather than depending on an attacker&amp;#8217;s restraint or a monitoring system catching them in time.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is the same containment logic that limits blast radius in a credential-based breach generally: the account that gets compromised should only ever be able to leak what it was legitimately allowed to touch.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt; like Proton Pass for Business makes this scoping realistic to maintain, since it removes the temptation to reuse a convenient set of broad credentials across tools simply because managing unique ones by hand doesn&amp;#8217;t scale.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When every account has its own credential and access is reviewed against what a role actually needs, a single compromised account stops being a route to the entire organization&amp;#8217;s data and becomes, at worst, a contained incident.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton Pass for Business can support your business with:&amp;nbsp;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Customizable team policies that help you enforce your &lt;a href=&quot;https://proton.me/business/blog/password-policy-template&quot;&gt;password policy&lt;/a&gt; with password requirements, mandatory &lt;a href=&quot;https://proton.me/blog/what-is-two-factor-authentication-2fa&quot;&gt;two-factor authentication&lt;/a&gt; (2FA) and revoked data sharing rules&lt;/li&gt;



&lt;li&gt;Usage logs that allow you to see activity within your network, with additional support from our advanced high security program &lt;a href=&quot;https://proton.me/blog/sentinel-high-security-program&quot;&gt;Proton Sentinel&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;Groups organized by role, project or access level, simplifying access management and ensuring that every team member only has access to what they need. &lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Stop credential-based data exfiltration with&lt;strong&gt; &lt;/strong&gt;a &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt;.&lt;/p&gt;
</content:encoded><category>For business</category><author>Kate Menzies</author></item><item><title>Does Chrome track you? Of course, but these steps can help</title><link>https://proton.me/blog/chrome-tracking-privacy</link><guid isPermaLink="true">https://proton.me/blog/chrome-tracking-privacy</guid><description>Learn how Chrome tracks your activity, what information it sends to Google, and which privacy settings can reduce tracking while you browse.</description><pubDate>Wed, 26 Aug 2026 20:06:58 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Chrome is the most used browser on the planet, which gives Google access to a considerable amount of information about how people use the internet. Some of that collection happens even when you&amp;#8217;re not signed in.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Google says some of Chrome’s data collection helps improve features, security, and search suggestions. But it can also send information back to Google that contributes to a broader picture of your browsing habits. &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you&amp;#8217;re not OK with that, your best course is to ditch Chrome once and for all. Here are the &lt;a href=&quot;https://proton.me/blog/best-browser-for-privacy&quot;&gt;best browsers for privacy&lt;/a&gt;, and if you&amp;#8217;d like to steer clear of American tech entirely, these are the &lt;a href=&quot;https://proton.me/learn/european-alternatives/european-web-browsers&quot;&gt;best private European web browsers&lt;/a&gt;. &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Unfortunately, there&amp;#8217;s no way to eliminate Google&amp;#8217;s data collection if you&amp;#8217;re determined to keep using Chrome. But you can limit the damage.&lt;/p&gt;



&lt;figure class=&quot;wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio&quot;&gt;&lt;div class=&quot;wp-block-embed__wrapper&quot;&gt;
&lt;iframe loading=&quot;lazy&quot; title=&quot;How Chrome Tracks Everything You Do and How to Stop It&quot; width=&quot;750&quot; height=&quot;422&quot; src=&quot;https://www.youtube-nocookie.com/embed/LE-TMEM1FS4?feature=oembed&quot; frameborder=&quot;0&quot; allow=&quot;accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share&quot; referrerpolicy=&quot;strict-origin-when-cross-origin&quot; allowfullscreen&gt;&lt;/iframe&gt;
&lt;/div&gt;&lt;/figure&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Why Chrome tracks your activity&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A web browser is a little like your front door to the internet. Everything you do &lt;a href=&quot;https://protonvpn.com/blog/digital-footprint&quot;&gt;&lt;u&gt;online&lt;/u&gt;&lt;/a&gt; passes through it. If that door also has cameras and sensors recording who comes and goes, it becomes much easier to understand your habits.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Chrome can &lt;a href=&quot;https://www.wired.com/story/google-chrome-browser-data&quot;&gt;&lt;u&gt;collect information&lt;/u&gt;&lt;/a&gt; even when you aren&amp;#8217;t signed in. It can also use identifiers associated with your browser and device, while other settings allow it to share information with Google to improve features and services.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Some of these settings are easy to overlook because they are presented as ways to make Chrome better. Enhanced &lt;strong&gt;Safe Browsing&lt;/strong&gt;, for example, can send information about websites you visit to Google as part of its &lt;a href=&quot;https://protonvpn.com/blog/google-ip-protection&quot;&gt;&lt;u&gt;security features&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That doesn&amp;#8217;t mean every privacy-related feature is inherently bad. It does mean you should know what you&amp;#8217;re agreeing to before leaving everything enabled.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Chrome sends what you type to Google&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;One of the more direct forms of data sharing happens while you type into Chrome’s address bar. With &lt;a href=&quot;https://protonvpn.com/blog/delete-search-history&quot;&gt;&lt;u&gt;search suggestions&lt;/u&gt;&lt;/a&gt; enabled, Chrome can send what you type to Google before you actually submit a search.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That can be useful if you want faster suggestions, but it also means Google may receive queries you never intended to search.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You can limit this by going to: &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Settings&lt;/strong&gt; &amp;gt; &lt;strong&gt;You and Google&lt;/strong&gt; &amp;gt; &lt;strong&gt;Sync and Google services&lt;/strong&gt;&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-large&quot;&gt;&lt;img width=&quot;1024&quot; height=&quot;711&quot; data-public-id=&quot;wp-pme/google-chrome-settings-1/google-chrome-settings-1.jpeg&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_711,c_scale/f_auto,q_auto/v1787682600/wp-pme/google-chrome-settings-1/google-chrome-settings-1.jpeg?_i=AA&quot; alt=&quot;Google Chrome privacy settings 1&quot; class=&quot;wp-post-276448 wp-image-276449&quot; data-format=&quot;jpeg&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;114 KB&quot; data-optsize=&quot;45 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;60.5&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=276449&quot; data-version=&quot;1787682600&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_711,c_scale/f_auto,q_auto/v1787682600/wp-pme/google-chrome-settings-1/google-chrome-settings-1.jpeg?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_208,c_scale/f_auto,q_auto/v1787682600/wp-pme/google-chrome-settings-1/google-chrome-settings-1.jpeg?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_533,c_scale/f_auto,q_auto/v1787682600/wp-pme/google-chrome-settings-1/google-chrome-settings-1.jpeg?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_1066,c_scale/f_auto,q_auto/v1787682600/wp-pme/google-chrome-settings-1/google-chrome-settings-1.jpeg?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1787682600/wp-pme/google-chrome-settings-1/google-chrome-settings-1.jpeg?_i=AA 1556w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;Next turn off &lt;strong&gt;Improve search suggestions&lt;/strong&gt;.&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img width=&quot;1024&quot; height=&quot;711&quot; data-public-id=&quot;wp-pme/google-chrome-privacy-settings-2/google-chrome-privacy-settings-2.jpeg&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_711,c_scale/f_auto,q_auto/v1787682689/wp-pme/google-chrome-privacy-settings-2/google-chrome-privacy-settings-2.jpeg?_i=AA&quot; alt=&quot;Google Chrome privacy settings 2&quot; class=&quot;wp-post-276448 wp-image-276473&quot; data-format=&quot;jpeg&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;187 KB&quot; data-optsize=&quot;91 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;51.3&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=276473&quot; data-version=&quot;1787682689&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_711,c_scale/f_auto,q_auto/v1787682689/wp-pme/google-chrome-privacy-settings-2/google-chrome-privacy-settings-2.jpeg?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_208,c_scale/f_auto,q_auto/v1787682689/wp-pme/google-chrome-privacy-settings-2/google-chrome-privacy-settings-2.jpeg?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_533,c_scale/f_auto,q_auto/v1787682689/wp-pme/google-chrome-privacy-settings-2/google-chrome-privacy-settings-2.jpeg?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_1066,c_scale/f_auto,q_auto/v1787682689/wp-pme/google-chrome-privacy-settings-2/google-chrome-privacy-settings-2.jpeg?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1787682689/wp-pme/google-chrome-privacy-settings-2/google-chrome-privacy-settings-2.jpeg?_i=AA 1556w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;/figure&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This prevents Chrome from sending your typing to Google simply to generate predictions and suggestions.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It’s a small setting, but it addresses a particularly revealing type of data: things you started typing but never actually searched for.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Chrome builds a profile of your browsing habits&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Chrome can also send information about how you use the browser back to Google. Combined with other data, this can help build a picture of your interests, the devices you use, and even your physical location.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;To reduce this collection:&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Open &lt;strong&gt;You and Google&lt;/strong&gt; &amp;gt; &lt;strong&gt;Sync and Google services&lt;/strong&gt; &amp;gt; toggle off &lt;strong&gt;Help improve Chrome’s features and performance&lt;/strong&gt; and &lt;strong&gt;Make searches and browsing better&lt;/strong&gt;.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-large&quot;&gt;&lt;img width=&quot;1024&quot; height=&quot;711&quot; data-public-id=&quot;wp-pme/google-chrome-privacy-settings-3/google-chrome-privacy-settings-3.jpeg&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_711,c_scale/f_auto,q_auto/v1787684352/wp-pme/google-chrome-privacy-settings-3/google-chrome-privacy-settings-3.jpeg?_i=AA&quot; alt=&quot;Google chrome privacy settings 3&quot; class=&quot;wp-post-276448 wp-image-276497&quot; data-format=&quot;jpeg&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;188 KB&quot; data-optsize=&quot;92 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;51.3&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=276497&quot; data-version=&quot;1787684352&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_711,c_scale/f_auto,q_auto/v1787684352/wp-pme/google-chrome-privacy-settings-3/google-chrome-privacy-settings-3.jpeg?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_208,c_scale/f_auto,q_auto/v1787684352/wp-pme/google-chrome-privacy-settings-3/google-chrome-privacy-settings-3.jpeg?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_533,c_scale/f_auto,q_auto/v1787684352/wp-pme/google-chrome-privacy-settings-3/google-chrome-privacy-settings-3.jpeg?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_1066,c_scale/f_auto,q_auto/v1787684352/wp-pme/google-chrome-privacy-settings-3/google-chrome-privacy-settings-3.jpeg?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1787684352/wp-pme/google-chrome-privacy-settings-3/google-chrome-privacy-settings-3.jpeg?_i=AA 1556w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;You can also disable &lt;strong&gt;Background Sync&lt;/strong&gt; under &lt;strong&gt;Privacy and Security&lt;/strong&gt;, then &lt;strong&gt;Site settings and Additional permissions&lt;/strong&gt;.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-large&quot;&gt;&lt;img width=&quot;1024&quot; height=&quot;711&quot; data-public-id=&quot;wp-pme/google-chrome-privacy-settings-4/google-chrome-privacy-settings-4.jpeg&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_711,c_scale/f_auto,q_auto/v1787833731/wp-pme/google-chrome-privacy-settings-4/google-chrome-privacy-settings-4.jpeg?_i=AA&quot; alt=&quot;&quot; class=&quot;wp-post-276448 wp-image-276521&quot; data-format=&quot;jpeg&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;174 KB&quot; data-optsize=&quot;79 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;54.7&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=276521&quot; data-version=&quot;1787833731&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_711,c_scale/f_auto,q_auto/v1787833731/wp-pme/google-chrome-privacy-settings-4/google-chrome-privacy-settings-4.jpeg?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_208,c_scale/f_auto,q_auto/v1787833731/wp-pme/google-chrome-privacy-settings-4/google-chrome-privacy-settings-4.jpeg?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_533,c_scale/f_auto,q_auto/v1787833731/wp-pme/google-chrome-privacy-settings-4/google-chrome-privacy-settings-4.jpeg?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_1066,c_scale/f_auto,q_auto/v1787833731/wp-pme/google-chrome-privacy-settings-4/google-chrome-privacy-settings-4.jpeg?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1787833731/wp-pme/google-chrome-privacy-settings-4/google-chrome-privacy-settings-4.jpeg?_i=AA 1556w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;This prevents websites from continuing to exchange data after you have closed a tab.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;While you&amp;#8217;re reviewing those settings, check your site permissions too. Remove access to your location, camera, or microphone from websites that don&amp;#8217;t genuinely need it.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How to reduce Chrome’s ad tracking&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Chrome also includes advertising features that use browsing activity to group you into advertising interests. These settings are separate from the basic functions you need to browse the web.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://protonvpn.com/blog/what-are-cookies&quot;&gt;&lt;u&gt;Third-party cookies&lt;/u&gt;&lt;/a&gt; are one such source of persistent tracking. These cookies can be placed by companies that aren&amp;#8217;t related to the website you&amp;#8217;re visiting, such as advertising networks and social media companies. Because the same companies can appear across many different websites, their cookies can help connect activity from one site to another.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You can &lt;a href=&quot;https://protonvpn.com/blog/how-to-block-third-party-cookies-on-all-browsers&quot;&gt;&lt;u&gt;block third-party cookies&lt;/u&gt;&lt;/a&gt; by: &lt;strong&gt;Privacy and Security&lt;/strong&gt; &amp;gt; &lt;strong&gt;Third-Party Cookies&lt;/strong&gt;. &lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-large&quot;&gt;&lt;img width=&quot;1024&quot; height=&quot;711&quot; data-public-id=&quot;wp-pme/google-chrome-privacy-settings-5/google-chrome-privacy-settings-5.jpeg&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_711,c_scale/f_auto,q_auto/v1787684785/wp-pme/google-chrome-privacy-settings-5/google-chrome-privacy-settings-5.jpeg?_i=AA&quot; alt=&quot;Google Chrome Privacy settings 5&quot; class=&quot;wp-post-276448 wp-image-276545&quot; data-format=&quot;jpeg&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;141 KB&quot; data-optsize=&quot;63 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;55.2&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=276545&quot; data-version=&quot;1787684785&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_711,c_scale/f_auto,q_auto/v1787684785/wp-pme/google-chrome-privacy-settings-5/google-chrome-privacy-settings-5.jpeg?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_208,c_scale/f_auto,q_auto/v1787684785/wp-pme/google-chrome-privacy-settings-5/google-chrome-privacy-settings-5.jpeg?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_533,c_scale/f_auto,q_auto/v1787684785/wp-pme/google-chrome-privacy-settings-5/google-chrome-privacy-settings-5.jpeg?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_1066,c_scale/f_auto,q_auto/v1787684785/wp-pme/google-chrome-privacy-settings-5/google-chrome-privacy-settings-5.jpeg?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1787684785/wp-pme/google-chrome-privacy-settings-5/google-chrome-privacy-settings-5.jpeg?_i=AA 1556w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;Chrome also offers a &lt;strong&gt;Do Not Track&lt;/strong&gt; request, although websites don&amp;#8217;t always honor it.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-large&quot;&gt;&lt;img width=&quot;1024&quot; height=&quot;711&quot; data-public-id=&quot;wp-pme/google-chrome-privacy-settings-6/google-chrome-privacy-settings-6.jpeg&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_711,c_scale/f_auto,q_auto/v1787684856/wp-pme/google-chrome-privacy-settings-6/google-chrome-privacy-settings-6.jpeg?_i=AA&quot; alt=&quot;Google chrome privacy settings&quot; class=&quot;wp-post-276448 wp-image-276569&quot; data-format=&quot;jpeg&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;204 KB&quot; data-optsize=&quot;103 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;49.4&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=276569&quot; data-version=&quot;1787684856&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_711,c_scale/f_auto,q_auto/v1787684856/wp-pme/google-chrome-privacy-settings-6/google-chrome-privacy-settings-6.jpeg?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_208,c_scale/f_auto,q_auto/v1787684856/wp-pme/google-chrome-privacy-settings-6/google-chrome-privacy-settings-6.jpeg?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_533,c_scale/f_auto,q_auto/v1787684856/wp-pme/google-chrome-privacy-settings-6/google-chrome-privacy-settings-6.jpeg?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_1066,c_scale/f_auto,q_auto/v1787684856/wp-pme/google-chrome-privacy-settings-6/google-chrome-privacy-settings-6.jpeg?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1787684856/wp-pme/google-chrome-privacy-settings-6/google-chrome-privacy-settings-6.jpeg?_i=AA 1556w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;For an additional layer of privacy, you can set Chrome to clear cookies whenever you close the browser. The trade-off is that you&amp;#8217;ll have to sign in to some websites more often.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Chrome gives you several ways to reduce how much information it collects, and changing a few settings can make a meaningful difference. But if you want to stop Google from collecting data through the browser entirely, Chrome may not be the right tool for you.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A different browser can give you more control over how your browsing data is handled. For Chrome users who want to stay put, though, reviewing these settings is a practical place to start.&lt;/p&gt;
</content:encoded><category>Videos</category><author>Proton Team</author></item></channel></rss>