Proton's Multi-Service Outage Points to Shared Login Infrastructure

Proton reported a service incident at 15:35 CEST on July 10, 2026, affecting login across its entire product suite. The status page initially read "Investigating," with the company stating: "We are aware of an incident, the team is working on investigating it." Proton Status
The outage is not limited to a single product. Proton Mail went down across its Web Application, Bridge (the desktop sync tool), Mobile Apps, and Desktop Apps. Proton Calendar's Mobile and Web applications were affected. Proton Drive, Proton Docs, Proton Pass—the company's password manager—and Proton VPN all reported service disruptions across multiple platforms. SimpleLogin, an email-alias service Proton acquired in 2022, also went down, along with Proton Wallet and Lumo, Proton's AI assistant. Proton Status
That breadth matters. Proton's lineup spans email, calendaring, cloud storage, password management, a consumer VPN, an email-masking service, a crypto wallet, and a generative AI product. A login failure that cuts across all of them strongly suggests a problem in Proton's centralized account and SSO (single sign-on) infrastructure—the shared system that authenticates users across the entire ecosystem—rather than a bug in any individual app.
Proton posted follow-up updates at 15:38, 15:39, 15:40, and 15:42 CEST. As of the last update, engineering teams were still investigating, with no resolution in sight. Proton Status Notably, the status page itself runs on Atlassian Statuspage, a third-party platform independent of Proton's own infrastructure, which ensures that status updates can be published even when Proton's main systems are down. Proton Status
At seven minutes past the initial alert, the public updates tell us that something broke, but not what. Proton has not yet identified whether the fault lies in an authentication microservice, a database or cache storing user session tokens, a certificate or key-rotation process, a dependency on a third-party identity provider, or a recent code deployment. Companies running centralized login for privacy-focused services face a particular constraint: because Proton's zero-access architecture means Proton itself cannot read user data, login failures are purely availability problems rather than data-breach risks. But that same architecture also eliminates workarounds—users locked out cannot use an alternate access method without breaking the encryption model that defines Proton's value.
For a company whose entire reputation rests on being a privacy-first, self-contained ecosystem, a login outage across email, VPN, password manager, and crypto wallet in one incident is a higher-stakes failure than the same outage would be for a loose collection of independent products. Users who depend on Proton Pass to manage passwords and Proton Mail as their primary email lose both at once if a shared login layer is the weak point. That operational reality puts pressure on Proton's team to find and communicate the root cause quickly, even while the technical repair is still underway.
The more interesting question, if this outage clears within the hour as most authentication-layer incidents do, will emerge in Proton's postmortem: which specific dependency in the login chain was the single point of failure, and whether a system designed to resist government data access has any architectural gaps when it comes to redundancy for its own account services. Proton has a track record of publishing transparent postmortems, and this incident will likely draw scrutiny precisely because of how many services were affected.
As of this writing, Proton has not published an estimated resolution time, and the incident remains open. Brief will update this story as Proton posts further status changes.


