One Overheated Rack Took Down Proton's Core Services
A cooling system failure at Proton's Frankfurt data center on the night of August 26, 2026 sent the room's temperature from a normal 21.8 degrees Celsius to 51.9 degrees Celsius within thirty minutes. Some sensors read as high as 60 degrees. Network cards hit 105 degrees against a normal operating temperature of 45 degrees and shut themselves down to avoid damage. Both the primary and backup network switch sat on the same rack, and that rack carried several of Proton's primary database copies, so the redundancy built to survive exactly this kind of failure did not activate automatically. Proton has said publicly that it can withstand a complete data center failure, but its own postmortem states that a primary database failover is never automated without human supervision, specifically to prevent the kind of split-brain data corruption that automatic failover can cause.
The Same Fault Line Reopened Five Days Later
A second outage on September 1, 2026 showed the August 26 failure had not actually finished.
| Incident | Date | Cause | Services affected |
|---|---|---|---|
| First outage | August 26 to 27, 2026 | Cooling failure, dual switch failure | Mail, Drive, Calendar, authentication |
| Second outage | September 1, 2026, 14:37 to 20:49 CEST | Residual hardware failure from database maintenance tied to the first incident | Mail, Pass, Drive, Calendar |
Sovereignty Describes Where Data Sits, Not Whether It Stays Up
Proton markets itself on jurisdiction and privacy, and this outage shows those guarantees are separate from resilience architecture. Many businesses that moved off US hyperscalers specifically to reduce concentration risk chose Proton, or a vendor like it, on the strength of its EU location and its refusal to hand data to US courts. Neither of those properties has anything to do with whether the service stays online when one rack overheats. Proton has a failover site in Zurich and, by its own account, is only now building the second-site capacity and automation that should have existed before this incident, with completion targeted for the end of 2026. A business that chose a sovereign alternative for data-residency reasons should ask that vendor directly how failover actually works, and whether it is automatic or waits on a person to approve it, rather than assume sovereignty implies resilience.
Read next: Europe's New AI Supercomputer Runs on American Chips | The Open Alternative to OpenAI Now Belongs to Nvidia



