ProtonMail — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
March 31, 2026
Last Seen
July 24, 2026

ProtonMail is a technology platform tracked across 4 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed March 31, 2026; most recent activity July 24, 2026.

Related Threat Clusters

  • Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign

    Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…

    53 articles · Updated July 23, 2026
  • FBI Warns of Kali365 Phishing Kit Targeting Microsoft 365 Users

    The FBI has issued a warning regarding the Kali365 phishing kit, which is actively stealing Microsoft OAuth tokens and bypassing multi-factor authentication (MFA) protocols. First identified in April 2026, Kali365 is…

    127 articles · Updated May 22, 2026
  • UNC6783 Exploits BPOs for Data Extortion via Phishing Campaigns

    The Google Threat Intelligence Group (GTIG) reported that a financially motivated cybercriminal group, UNC6783, is targeting business process outsourcing (BPO) companies to infiltrate high-value organizations across…

    8 articles · Updated April 8, 2026
  • Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages

    A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…

    697 articles · Updated April 29, 2026

Recent Intelligence Reports

  • ASD, National Cyber Security Coordinator warn of ongoing Russian phishing campaign — Defenceconnect.Au · July 24, 2026
  • Bluekit phishing kit adopts browser-in-the — Bleepingcomputer · June 25, 2026
  • UNC6783 Turns BPO Providers into Cyberattack Gateways — Thecyberexpress · April 9, 2026
  • Supply chain blast: Top npm package backdoored to drop dirty RAT on dev machines — Theregister · March 31, 2026

CVSS v3.1 Breakdown