logo

NordVPN denies breach claims, says attackers have "dummy data"

ID: 82a9afa7-e8c3-58bc-973d-3e692e73bad4

STIX ID: report--82a9afa7-e8c3-58bc-973d-3e692e73bad4

Feed Name: Bleeping Computer

Threat Score
25/100

Date Published: 2026-01-05

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

A threat actor claimed to have stolen more than 10 databases containing Salesforce API keys and Jira tokens from a NordVPN development server; NordVPN says the files are dummy data from a temporary third-party testing environment that was never connected to production and contained no real customer or business information. The story is presented as a false alarm, with the company contacting the vendor for more details and reference to a separate 2019 breach for historical context.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.