Protonmail hacked; servers intentionally misconfigured -- Or not?



Have you read this?


As many of you may be aware, earlier today, criminals attempted to extort ProtonMail by alleging a data breach, with zero evidence. An internal investigation turned up two messages from the criminals involved, which again repeated the allegations with zero evidence, and demanded payment. We have no indications of any breach from our internal infrastructure monitoring.

Like any good conspiracy theory, it is impossible to disprove a breach. On the other hand, a breach can be easily proven by providing evidence. The lack of evidence strongly suggests there is no breach, and this is a simple case of online extortion.

Thus, we believe that this is a hoax and failed extortion attempt, and there is zero evidence to suggest otherwise. None of the claim made are true, and many of the claims are also unsound from a technical standpoint.

For instance, the criminals claim that ProtonMail is vulnerable because we do not use SRI (Subresource Integrity), but this claim is nonsense because ProtonMail doesn’t use any third party CDNs (content delivery networks) to serve our web app. We only use web servers that we operate and control ourselves, specifically to eliminate this potential attack vector.

We are aware of a small number of ProtonMail accounts which have been compromised as a result of those individual users falling for phishing attacks (this is why we encourage using 2FA). However, we currently have zero evidence of a breach of our infrastructure.

Our present policy is to always resist extortion attempts, and we never make payments in response to third party claims and allegations, unless they fall under the scope and criteria of our bug bounty program, where we always welcome the submission of vulnerabilities.

Upon further investigation, we were able to trace the source of the rumors back to 4chan where they were originally posted by the criminals in question. The claims there include increasingly ridiculous assertions such as:

  • CNN employees use ProtonMail and refer to the American people as prostitutes

  • Michael Avenatti uses ProtonMail and has a BDSM fetish

  • Private military contractors used ProtonMail to discuss circumventing the Geneva convention, underwater drone activities in the Pacific Ocean, and possible international treaty violations in Antarctica

  • Rampant pedophilia among high ranking government officials who use ProtonMail

In other words, the allegations appear designed to fuel certain right wing conspiracy theories in order to gain more attention. We don’t like to use the term, but this is starting to look very similar to “fake news.”

Due to our refusal to give in to the extortion attempt, the criminals involved are now attempting to spread the allegations publicly to harm ProtonMail. The best way to ensure that they do not succeed is to ignore them. Thank you again for your support.


Historically it seems Protonmail makes unkind statements toward upstanding organizations like my own.

Yeah… your “organisation” who allegedly hacked protonmail and then tried to extort them for money, and when that failed, publicly tried to damage them and attempt again to extort them for money.

Pretty sure there’s some law breaking there.

