NordVPN , a Virtual Private Network provider that promises to "protect your privacy online" has admitted that it was hacked. NordVPN confirms that some of there servers had been breached last year in March 2018. This News comes after some rumors surfaced that NordVPN's servers had been hacked.
This Problem had firstly arisen when hackers discovered that NordVPN was using expired internal private keys. This allowed hackers to use their own servers to imitate NordVPN's services.
NordVPN said, An unauthorized user accessed a lone server in Finland datacenter that NordVPN was renting from a unnamed provider, which apparently didn't disclose the hack and No username and passwords were intercepted.
In march 2018 hackers exploited one of the server of NordVPN, the server was hosted in a datacenter in Finland by targeting an insecure remote management system that was incorrectly managed and left insecure by the datacenter provider. NordVPN hasnot disclosed the name of the datacenter. NordVPN confirmed that it had installed on detection system that will detect breaches early on.
One of the Spokesperson from NordVPN said, " No-one could know about an undisclosed remote management system left by the datacenter provider". NordVPN said the expired private key that was exploited by the attacker could not have been used to decrypt the traffic on the VPN server any other server.
[ Conclusion by NordVPN after data breach ]
"The server itself didn't contain any user activity logs. None of our applications send user-created credentials for authentication, So usernames and passwords could not have been intercepted either", said the spokesperson. VPN services that are hosted offshore or do not keep logs are the most popular. NordVPN says that it doesnot keep logs of its users data.
NordVPN logs Policy :- https://nordvpn.com/features/strict-no-logs-policy/
Sources :- https://techcrunch.com/2019/10/21/nordvpn-confirms-it-was-hacked/
7 Comments
Awesome blog buddy thanks for sharing with us
ReplyDeleteScope of ethical Hacking
CISM training.
ReplyDeleteCISSP training.
ReplyDeleteaws course
ReplyDeleteaws training
aws certification training
aws online training
10 Hidden Truths that You Must Know to Crack PMP Exam
ReplyDeleteAzure training
ReplyDeleteAzure certification
Azure Online training
Azure devops
Great Work. Amazing way of writing things. Thanks for Posting.
ReplyDeleteGCP Training Online
Online GCP Training
Please do not enter any spam link in the comment box.