NordVPN denies breach claims, says attackers have "dummy data"
by Shadowraser - Monday January 5, 2026 at 04:33 PM
#1
 
By Sergiu Gatlan
 
NordVPN denied allegations that its internal Salesforce development servers were breached, saying that cybercriminals obtained "dummy data" from a trial account on a third-party automated testing platform.
 
The company's statement comes after a threat actor (@1011) claimed on a hacking forum over the weekend that they stole more than 10 databases containing sensitive information like Salesforce API keys and Jira tokens, following a brute-force attack against a NordVPN development server.
 
"Today i am leaking +10 DB's source codes from a nordvpn development server. This information was acquired by bruteforcing a misconfigured server of Nordypn, which has salesforce and jira information stored. Compromissed information: SalesForce api keys, jira tokens and more," the threat actor said.
 
However, as NordVPN revealed today, this is actually test data stolen from a temporary test environment deployed months earlier during trial testing a potential vendor for automated testing.
 
The Lithuanian VPN service added that the test environment had no connection with its own infrastructure and that the stolen data doesn't include sensitive customer or business information.
  
  
"The leaked elements, such as the specific API tables and database schemas can only be artifacts of an isolated third-party test environment, containing only dummy data used for functionality checks. While no data in the dump points to NordVPN, we have contacted the vendor for additional information," NordVPN explained.
 
"Because this was a preliminary test and no contract was ever signed, no real customer data, production source code, or active sensitive credentials were ever uploaded to this environment.
 
"We ultimately chose a different vendor and did not proceed with the one we tested. The environment in question was never connected to our production systems."
 
While this was only a false alarm, in 2019, hackers breached the servers of NordVPN and TorGuard, gaining full root access and stealing private keys used to secure their web servers and VPN configurations.
 
In response to the 2019 incident, NordVPN introduced a bug bounty program and hired outside cybersecurity experts for a "full-scale" third-party security audit.
 
The company also announced plans to switch to dedicated servers that they own exclusively and to upgrade their entire 5,100-server infrastructure to RAM servers.
Reply
#2
Fuck Nord


Get Mullvad
"Universal appeal is poison masquerading as medicine. Horror is not meant to be universal. It's meant to be personal, private, animal"
Reply
#3
(Jan 06, 2026, 11:02 AM)DredgenSun Wrote: Fuck Nord


Get Mullvad

Why is Mullvad so glazed? Sincere questionvtw, never used it before, been thinking about giving it a try just to see how it goes

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Contact Administration.
Reply
#4
I’m sure the "dummy data" coincidentally matches the real user database perfectly, purely for the sake of realism.
Reply
#5
(Feb 07, 2026, 09:09 AM)etyhtrtgfrt Wrote:
(Jan 06, 2026, 11:02 AM)DredgenSun Wrote: Fuck Nord


Get Mullvad

Why is Mullvad so glazed? Sincere questionvtw, never used it before, been thinking about giving it a try just to see how it goes

Because you can pay literal cash in the post for a sub, and its not tied to any account, you just make a payment and use a code for 'time'
"Universal appeal is poison masquerading as medicine. Horror is not meant to be universal. It's meant to be personal, private, animal"
Reply
#6
mullvad is goated. its a great vpn fr
Reply
#7
(Jan 05, 2026, 04:33 PM)Shadowraser Wrote:
 
By Sergiu Gatlan
 
NordVPN denied allegations that its internal Salesforce development servers were breached, saying that cybercriminals obtained "dummy data" from a trial account on a third-party automated testing platform.
 
The company's statement comes after a threat actor (@1011) claimed on a hacking forum over the weekend that they stole more than 10 databases containing sensitive information like Salesforce API keys and Jira tokens, following a brute-force attack against a NordVPN development server.
 
"Today i am leaking +10 DB's source codes from a nordvpn development server. This information was acquired by bruteforcing a misconfigured server of Nordypn, which has salesforce and jira information stored. Compromissed information: SalesForce api keys, jira tokens and more," the threat actor said.
 
However, as NordVPN revealed today, this is actually test data stolen from a temporary test environment deployed months earlier during trial testing a potential vendor for automated testing.
 
The Lithuanian VPN service added that the test environment had no connection with its own infrastructure and that the stolen data doesn't include sensitive customer or business information.
  
  
"The leaked elements, such as the specific API tables and database schemas can only be artifacts of an isolated third-party test environment, containing only dummy data used for functionality checks. While no data in the dump points to NordVPN, we have contacted the vendor for additional information," NordVPN explained.
 
"Because this was a preliminary test and no contract was ever signed, no real customer data, production source code, or active sensitive credentials were ever uploaded to this environment.
 
"We ultimately chose a different vendor and did not proceed with the one we tested. The environment in question was never connected to our production systems."
 
While this was only a false alarm, in 2019, hackers breached the servers of NordVPN and TorGuard, gaining full root access and stealing private keys used to secure their web servers and VPN configurations.
 
In response to the 2019 incident, NordVPN introduced a bug bounty program and hired outside cybersecurity experts for a "full-scale" third-party security audit.
 
The company also announced plans to switch to dedicated servers that they own exclusively and to upgrade their entire 5,100-server infrastructure to RAM servers.

WE BEEN KNOWING NORDVPN IS ASS NIGGA

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Contact Administration.
Reply
#8
thats really crazy ... nordvpn its like express vpn
Reply
#9
(Jan 06, 2026, 11:02 AM)DredgenSun Wrote: Fuck Nord


Get Mullvad

Mate, where the heck were you? long time. And yea, Mullvad is the boss. Nord and all are just crap!
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Corruptiion of PLN [Indonesia] - 2025 Investigation Viral LordZeroDay 25 1,451 Apr 25, 2026, 09:23 PM
Last Post: dipiwef113
  The Ratification of the TNI Bill, Has an Impact on Indonesia? LordZeroDay 12 736 Apr 25, 2026, 02:50 PM
Last Post: dipiwef113
  Another vulnerability popping up — early alert from Vuln Tracker Crizz_Mattel99 1 145 Apr 25, 2026, 02:32 PM
Last Post: dfawdawfawfaw
  Vulnerability in Windows Snipping Tool Could Expose Sensitive Information xXTH3_R3DXx 0 98 Apr 21, 2026, 02:36 AM
Last Post: xXTH3_R3DXx
  Who's next ? DC7414 3 154 Apr 20, 2026, 10:18 PM
Last Post: Crockett

Forum Jump:


 Users browsing this forum: 1 Guest(s)