NordVPN Denies Data Breach Following Threat Actor Claim on Dark Web
On Tue, Jan 4, 2022, NordVPN addressed allegations concerning a data breach purportedly affecting its Salesforce development server. In response to claims made on a dark web forum, the company conducted a forensic analysis to verify the authenticity of…
On Tue, Jan 4, 2022, NordVPN addressed allegations concerning a data breach purportedly affecting its Salesforce development server. In response to claims made on a dark web forum, the company conducted a forensic analysis to verify the authenticity of these assertions.
NordVPN's security team reported that the supposed data dump does not indicate any compromise to its core infrastructure. The investigation revealed no evidence linking the alleged breach to NordVPN's internal systems.
The data in question was traced back to a third-party testing platform used during a proof-of-concept evaluation six months prior. This temporary environment utilized only dummy data, with no connection to production systems or live credentials. Consequently, no customer data, production code, or live credentials were involved.
On Tue, Jan 4, 2022, NordVPN addressed allegations concerning a data breach purportedly affecting its Salesforce development server.
NordVPN emphasized that the leaked files originated from a third-party platform trial and not from its Salesforce environment. The company has stated that its systems remain secure and there is no need for customer action.
For further information, NordVPN has contacted the third-party vendor involved in the temporary setup, reinforcing the security of its systems.
Based on reporting by Cyber Security News.
