NordVPN Responds to Alleged Salesforce Breach Claims

NordVPN data breach

NordVPN has issued a public statement addressing recent online claims that suggested its Salesforce systems had been breached.

After reviewing the available information, NordVPN claim there is currently no evidence to indicate that their internal systems or customer data have been compromised.

The claims emerged after a data dump appeared on a breach forum, with a threat actor alleging access to a ‘NordVPN Salesforce development server’.

NordVPN says it immediately launched an internal investigation to verify the accuracy of those claims.

According to NordVPN’s security team, their initial forensic analysis found no signs of intrusion into NordVPN servers, production infrastructure, or internal Salesforce environments.

Instead, the company states that the files referenced in the leak originated from a third party platform that NordVPN briefly evaluated more than six months ago.

NordVPN explained that, during a standard proof of concept phase, a temporary test environment was created to assess an external vendor for automated testing.

This environment was isolated, never connected to NordVPN production systems, and only contained dummy data used for functionality checks. No customer information, production source code, or sensitive credentials were ever uploaded.

The vendor involved was ultimately not selected, no contract was signed, and the test environment was abandoned. NordVPN also stated that the leaked materials, such as API tables and database schemas, are consistent with artefacts from a standalone test setup rather than an internal system.

At the time of writing, they claim there is nothing in the leaked data that directly links it to NordVPN customer information or live services. NordVPN has confirmed it is continuing its investigation and has contacted the third party vendor involved to gather additional details.

From reviewing details across the net, we have not seen any evidence that contradicts NordVPN’s explanation. For existing NordVPN users, or those considering the service, there is currently no indication that personal data has been exposed or that any action is required.

We will continue to monitor developments closely and will update this article if any new, verified information emerges.

Author: Christopher Seward

Christopher is a VPN comparison expert with over a decade of experience independently testing and reviewing VPN services. Online since 1994, he launched one of the earliest VPN comparison websites in 2013. His hands-on evaluations focus on real-world performance, security, and privacy, helping thousands of users make informed decisions when choosing a VPN.

Leave a Reply

Your email address will not be published. Required fields are marked *

Sign up to our newsletter

Get the latest privacy news, expert VPN guides & TV unblocking how-to’s sent straight to your inbox.