Arab Press

بالشعب و للشعب
Thursday, Mar 19, 2026

NordVPN hit with major data breach

NordVPN hit with major data breach

NordVPN and TorGuard have both published statements on their respective sites providing more details on the incident.

One of the world's most popular VPN providers has revealed it was hacked by an unidentified party following a major data breach.

Details are still scant but the virtual private network provider has confirmed one of its datacenters was penetrated in March 2018.

"A few months ago, we became aware of an incident in March 2018 when a server at a datacenter in Finland we had been renting servers from was accessed without authorization," the company wrote in a blog post. "This was done through an insecure remote management system account that the datacenter had added without our knowledge. The datacenter deleted the user accounts that the intruder had exploited rather than notify us."

While NordVPN has a “zero log” policy that was recently independently audited, one may question the motives of the hacker or hackers.

“The server itself did not contain any user activity logs; none of our applications send user-created credentials for authentication, so usernames and passwords couldn’t have been intercepted either,” the blog added.

“On the same note, the only possible way to abuse the website traffic was by performing a personalized and complicated man-in-the-middle attack to intercept a single connection that tried to access NordVPN.”

"This was an isolated case, and no other servers or datacenter providers we use have been affected."


Two separate VPN issues

The hackers were able to identify an insecure remote management system that was operated by the datacenter provider and had full root access to a container server thanks to an expired TLS certificate.

In the own words of fellow hacker @hexdefined, this allowed “full control of everything in it (presumably including the ability to view and tamper with all network traffic going through it)”.

To make things even more interesting, two other VPN providers, access logs of VikingVPN and Torguard were also published alongside NordVPN on 8Chan, a possible indication that all three providers used the same data center.

Newsletter

Related Articles

Arab Press
0:00
0:00
Close
U.S. Lawmakers Press Rubio to Enforce Strong Safeguards in Saudi Nuclear Deal
Iran Issues Evacuation Warning to Gulf States After Strike on Major Gas Field
Saudi Arabia to Convene Arab and Islamic Ministers for Urgent Talks on Regional Conflict
Saudi Arabia Confirms Eid al-Fitr as Moon Sighting Determines End of Ramadan
Saudi Arabia Boosts Crude Exports to Highest Levels Since 2023, Data Shows
Iran Issues Warning to Gulf Energy Infrastructure Following Strike on Major Gas Field
Saudi Arabia Restarts Ras Tanura Refinery Following Drone Strike, Reinforcing Energy Resilience
Saudi Arabia Restarts Ras Tanura Refinery Following Drone Strike, Reinforcing Energy Resilience
Saudi Arabia Intercepts Ballistic Missiles Targeting Riyadh Amid Escalating Regional Tensions
Saudi Arabia Restores Significant Oil Flows Using Hormuz Bypass Amid Regional Tensions
Saudi Arabia Signals Potential Activation of Defence Pact with Pakistan Amid Escalating Iran Conflict
Saudi Supreme Court Urges Muslims to Observe Crescent Moon for Eid Determination
Saudi Supreme Court Urges Muslims to Observe Crescent Moon for Eid Determination
Saudi Arabia Reassesses Iran Strategy as Regional Conflict Tests MBS’s Diplomatic Bet
Iran Steps Up Drone Strikes on Saudi Oil Sites, Heightening Risks to Global Supply
Regional Fallout Grows as Iran Conflict Sends Shockwaves Across Jordan, Saudi Arabia, and Egypt
Saudi Arabia Intercepts Seven Drones in Intensifying Regional Security Threat
Saudi Arabia Intercepts Seven Drones in Intensifying Regional Security Threat
Saudi Arabia Weighs Regional Risks as Iran Conflict Deepens and Security Calculations Shift
Gulf States Confront Limits of U.S. Protection as Regional War Intensifies
Gulf Producers Rush to Reroute Oil Exports as Iran Tightens Control of Hormuz Strait
Saudi Gaming Investment Arm Acquires Strategic Stake in Capcom to Expand Global Influence
Iran Intensifies Strikes on Saudi Oil Infrastructure as Regional War Escalates
Saudi Arabia Targets South African Professionals in New Recruitment Drive Amid Regional Uncertainty
Formula One Faces Major Financial Hit as Bahrain and Saudi Arabian Grands Prix Cancelled Amid Middle East Conflict
U.S. and Saudi Firms Launch Local Production of Attritable Drone Systems in Saudi Arabia
Saudi Arabia and UAE Warn Rising Gulf Tensions Could Endanger Regional Security
Saudi Arabia Rejects Claims It Encouraged Prolonged War With Iran
Saudi Arabia to Host World’s Largest Single-Cell Protein Plant as Food Security Push Accelerates
Saudi Crown Prince Urges Trump to Continue Military Pressure on Iran
Iran Intensifies Drone Campaign Against Saudi Arabia as Gulf Conflict Escalates
When Is Eid al-Fitr 2026? Saudi Arabia Awaits Moon Sighting to Confirm End of Ramadan
When Is Eid al-Fitr 2026? Saudi Arabia Awaits Moon Sighting to Confirm End of Ramadan
Iranian Missile Strike Damages Five U.S. Refueling Aircraft at Saudi Air Base
Iranian Missile Strike Damages Five U.S. Refueling Aircraft at Saudi Air Base
Washington State Pilot Among Six U.S. Airmen Killed in Military Aircraft Crash Over Iraq
Severe Storm Threat Looms Over Washington as Tornado Risk and Damaging Winds Target Mid-Atlantic
Trump Supports FCC Warning to Broadcasters Over Iran War Reporting
Trump Supports FCC Warning to Broadcasters Over Iran War Reporting
Saudi Stocks Edge Lower as Tadawul All Share Index Slips Slightly at Market Close
Iranian Missile and Drone Strike Targets Saudi Arabia’s Prince Sultan Air Base Hosting US Aircraft
Saudi Air Defenses Intercept Drone Over Eastern Province as Iranian Strike Campaign Intensifies
Middle East War Reshapes Gulf Economies as Saudi Arabia and Oman Gain Strategic Leverage While UAE Faces Economic Shock
Iranian Ambassador in Riyadh Blames ‘Enemies’ for Attacks Across the Gulf
Israeli Envoy Ron Dermer Reportedly Visits Saudi Arabia for Discussions on Potential Lebanon Talks
Formula One Cancels Bahrain and Saudi Arabian Grands Prix Scheduled for April
Iran’s Ambassador in Riyadh Rejects Claims Tehran Targeted Saudi Oil Facilities
Saudi Arabia Declares 2026 ‘Year of Artificial Intelligence’ in Major Push for Data-Driven Economy
Saudi Arabia’s 2018 Budget Signals Strong Push for Non-Oil Economic Growth
Pakistan Envoy in Riyadh Says Regional Diplomacy Intensifying to Prevent Wider Middle East War
×