Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

NordVPN Denies Breach After Hacker Leaks Data

The VPN company has conducted an investigation after a threat actor claimed to have hacked its systems. 

NordVPN hack

VPN company NordVPN has denied suffering a breach after a threat actor leaked data allegedly stolen from its systems.

The hacker claimed on January 4 on the BreachForums cybercrime forum that they had obtained source code from a “NordVPN development server”.

“This information was acquired by bruteforcing a misconfigured server of NordVPN, which has Salesforce and Jira information stored,” the hacker said.

The attacker publicly released some sample data and made all the information available for download to the cybercrime forum’s premium users. 

NordVPN responded to the claims on January 5, saying that while its probe is ongoing, an initial forensic analysis has not found any evidence of its servers or internal production infrastructure being compromised.

In addition, NordVPN clarified that the leaked data does not originate from its Salesforce environment or any other internal system. Instead, it appears to come from a third-party automated testing platform that the company evaluated six months ago. 

The VPN firm said it ended up choosing the services of a different vendor, but during the trial period it did create a temporary environment to test the platform’s functionality. 

Advertisement. Scroll to continue reading.

However, the test environment was never connected to its production systems, and no real customer data, source code, or credentials were ever uploaded.

“The claims that our internal Salesforce development servers were breached are false. The leaked elements, such as the specific API tables and database schemas can only be artifacts of an isolated third-party test environment, containing only dummy data used for functionality checks,” NordVPN said. 

“While no data in the dump points to NordVPN, we have contacted the vendor for additional information,” the company added.

Related: TorGuard, NordVPN Respond to Breach Reports

Related: Verizon DBIR Flags Major Patch Delays on VPNs, Edge Appliances

Related: New VPN Attack Demonstrated Against Palo Alto Networks, SonicWall Products

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

People on the Move

Anurag Jain has been appointed Senior Vice President of Engineering at CodeHunter

CTERA has appointed Tal Sarfaty as Senior Vice President of Cybersecurity.

Quantum Secure Encryption has named Michael Massing as Chief Technology Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.