NordVPN confirms 2018 data centre breach

Personal virtual private network provider admits to a breach in March 2018 but claims no data was exfiltrated

NordVPN has admitted it was hacked in March 2018, after rumours circulated around a data breach the virtual private network (VPN) service provider had suffered. 

The company said that an expired internal private key, a tool that provides and secures machine identity, became exposed earlier this year, allowing for the construction of insecure NordVPN imitation servers.

Despite touting its VPN services as "a hack-proof, encrypted tunnel for online traffic to flow", an attacker accessed a data centre hosting NordVPN servers. 

By exploiting a remote management system left by the Finnish data centre provider, which NordVPN was not aware existed, the hacker managed to gain access to one of its servers which had only been active for about a month. The server essentially gave the hacker access some of the encryption keys that secure NordVPN user data. 

The company's blog post responding to the data breach claims: "No user credentials have been intercepted. No other server on our network has been affected. The affected server does not exist anymore and the contract with the server provider has been terminated."

While the breach occurred more than a year ago, NordVPN only discovered it "a few months ago", and had not revealed its existence until recently due to security concerns. 

"We did not disclose the exploit immediately because we had to make sure that none of our infrastructure could be prone to similar issues. This couldn't be done quickly due to the huge number of servers and the complexity of our infrastructure," the company said. 

VPN providers, which protect a customer's browsing traffic privacy from the internet provider and visiting sites, continue to gain popularity, particularly among journalists and activists working in hostile states.

VPNs make tracking a customer's internet and app usage more difficult by channelling their traffic through one encrypted pipeline, which typically relocates their browsing history from their internet provider to their VPN provider. This function has brought VPNs under increased scrutiny, as it is unclear whether each provider logs users' internet history.

"We don't track, collect, or share your private data," NordVPN claims. "It's none of our business."

For this reason, spokesperson Laura Tyrell told IT Pro, "even if the hacker could have viewed the traffic while being connected to the server, he could only see what an ordinary ISP would see, but in no way could it be personalised or linked to a particular username or email."

However, an anonymous security researcher told TechCrunch: "While this is unconfirmed and we await further forensic evidence, this is an indication of a full remote compromise of this provider's systems. That should be deeply concerning to anyone who uses or promotes these particular services."

In the wake of the breach, NordVPN reported it is "taking all the necessary means to enhance [its] security", including pursuing application security and no-logs audits as well as launching a bug bounty programme. Next year, the company plans to launch an independent external audit of its entire infrastructure.

Data security researchers project that similar breaches of machine identity will become increasingly common.

"It is imperative organisations have the agility to automatically replace every key and certificate that may have been exposed in breaches," said Kevin Bocek, vice president of security strategy and threat intelligence for Venafi.

"Quickly replacing machine identities is the reliable way to ensure privacy and security in a world where businesses run and depend on the cloud."

Featured Resources

Defeating ransomware with unified security from WatchGuard

How SMBs can defend against the onslaught of ransomware attacks

Free download

The IT expert’s guide to AI and content management

How artificial intelligence and machine learning could be critical to your business

Free download

The path to CX excellence

Four stages to thrive in the experience economy

Free download

Becoming an experience-based business

Your blueprint for a strong digital foundation

Free download

Recommended

Your essential guide to internet security
Security

Your essential guide to internet security

25 Jun 2021
Nigerian cyber criminals target Texas unemployment system
cyber security

Nigerian cyber criminals target Texas unemployment system

27 May 2021
Hackers use open source Microsoft dev platform to deliver trojans
Security

Hackers use open source Microsoft dev platform to deliver trojans

14 May 2021

Most Popular

What are the pros and cons of AI?
machine learning

What are the pros and cons of AI?

8 Sep 2021
Apple patches zero-day flaw abused by infamous NSO exploit
exploits

Apple patches zero-day flaw abused by infamous NSO exploit

14 Sep 2021
Hackers develop Linux port of Cobalt Strike for new attacks
Security

Hackers develop Linux port of Cobalt Strike for new attacks

14 Sep 2021