К сожалению, содержание этой страницы недоступно на выбранном вами языке.

Ваш IP:Нет данных

·

Статус: Нет данных

Перейти к основному содержимому

NordVPN remains secure: Addressing the alleged Salesforce breach

Yesterday, on the 4th of January, we have identified a data dump on one of the breach forum websites, containing allegations made by a threat actor claiming to have accessed a "NordVPN Salesforce development server." We immediately started to verify these claims and now want to address them directly to clarify what happened.


Our security team has completed an initial forensic analysis of the alleged data dump. While we are continuing our investigation to ensure absolute certainty, we can confirm that, at this stage, there are no signs that NordVPN servers or internal production infrastructure have been compromised.

5 янв. 2026 г.

2 мин. для прочтения

The data in question does not originate from NordVPN’s internal Salesforce environment or any other services mentioned in the claim. Instead, our investigation identified that the leaked configuration files were related to a third-party platform, with which we briefly had a trial account.

What actually happened: 6 months ago, NordVPN evaluated a potential vendor for automated testing. As part of a standard Proof of Concept (PoC) phase, a temporary test environment was created to assess their functionality.

  • No sensitive data: Because this was a preliminary test and no contract was ever signed, no real customer data, production source code, or active sensitive credentials were ever uploaded to this environment.
  • Vendor not selected: We ultimately chose a different vendor and did not proceed with the one we tested. The environment in question was never connected to our production systems.

The claims that our internal Salesforce development servers were breached are false. The leaked elements, such as the specific API tables and database schemas can only be artifacts of an isolated third-party test environment, containing only dummy data used for functionality checks. While no data in the dump points to NordVPN, we have contacted the vendor for additional information.  

NordVPN systems remain fully secure. Your data is safe, and no action is required on your part.

Также доступно в: English,Français.

NordVPN experts

NordVPN experts

Our NordVPN experts know the ins and outs of cybersecurity solutions and strive to make the internet safer for everyone. With a finger on the pulse of online threats, they share their expertise and practical tips on how to avoid them. Whether you're a tech newbie or a seasoned user, you'll find valuable insights in their blog posts. Cybersecurity should be accessible to everyone — and we're making that happen, one blog post at a time.