The UK Small Business Cybersecurity Network | Helping Keep Small Business CYBERSafe! » REPORTAGE: Proton’s Privacy Problem: Disturbing DNS Findings Raise Serious Red Flags

REPORTAGE: Proton’s Privacy Problem: Disturbing DNS Findings Raise Serious Red Flags

Yandex_main_office
Image Credit: WikiFido via Wikimedia
nordvpn

Helping Keep Small Business CYBERSafe
Málaga: Saturday, 22nd March 2025 at 12:00 CEST

REPORTAGE: Proton’s Privacy Problem: Disturbing DNS Findings Raise Serious Red Flags – Critical Threat Intelligence Ignored
By Iain Fraser/Reportage & Andy Jenkinson CIP
via  CYBERInsightsThe UK Small Business Cybersecurity Network
#CyberInsights #CyberSecurity #CyberAwareness #CyberSafe #SME #SmallBusiness 

Weeks ago, CyberInsights uncovered serious security vulnerabilities in Proton’s infrastructure. Rather than addressing the issues, Proton responded with hostility and suppression—an unusual reaction for a company built on privacy and transparency.

This raises a crucial question: Why would a security-first company react this way? The answer may be more alarming than expected.

Proton’s Encryption Claims vs. Reality
Proton prides itself on end-to-end encryption and zero-access security, assuring users that not even Proton can access their emails. However, our investigation revealed multiple security lapses, including:

– Insecure DNS records
– Unprotected servers

A troubling connection to Yandex—Russia’s largest search engine
Why Is Yandex Inside Proton’s Infrastructure? Our findings show Yandex is embedded within Proton’s DNS records. This is deeply concerning, given Yandex’s well-documented ties to data-harvesting and intelligence operations.

Negligence or Intent?
Proton’s Response Is Telling Rather than fixing these security risks, Proton chose silence and suppression. For a company that markets itself as a leader in privacy, this response raises a pressing question for users:

🔹 Can you really trust Proton with your data?

The evidence suggests otherwise.

Stay Secure
What Small Businesses Should Do Next. If your business relies on Proton for secure communication, we strongly recommend:

✅ Conducting a security audit of your email provider
✅ Exploring alternative encrypted email solutions
✅ Following CyberInsights for the latest security intelligence

🛡 Your privacy matters. Don’t let questionable security practices put your business at risk.

CYBERInsights | Practical Small Business Cybersecurity
Image Credit: IfOnlyCommunications
nordvpn

UK Small Business Owner? Join CYBERInsights Free Now! & Access the SME Cyber Forum – Read, Learn, Engage, Share …

The Latest SME Cybersecurity News, Threat Intelligence & Analysis, Timely Scam Alerts, Best-practice Compliance, Mitigation & Resources specifically curated for UK Based SMEs in a Single Weekly Email direct to your Inbox or Smart Device together with Unrestricted Free Access to our entire SME Cyber Knowledge & Tutorial Library.

Cybersec Innovation Partners

About Andy Jenkinson

Group CEO CIP. Fellow Cyber Theory Institute. Director Fintech & Cyber Security Alliance (FITCA) working with Governments. Recognised Expert in Internet Asset & DNS Vulnerabilities.

Andy Jenkinson is a senior and seasoned innovative Executive with over 30 years’ experience as a hands-on lateral thinking CEO, coach, and leader.