In October 2024, NordVPN was served with a warrant by Panamanian authorities demanding user data for a criminal investigation. NordVPN's adherence to privacy meant all they could provide was payment-related data and email account confirmation. Though this incident showcases potential vulnerabilities, NordVPN's privacy commitment likely prevented more significant data exposure. They also boast robust security features such as a kill switch, multi-hop connections, and support for several protocols, making it suitable for high-risk situations when paired with Tor.
Source: https://www.wired.com/story/best-vpn/
TPRM report: https://scoringcyber.rankiteo.com/company/nord-vpn
"id": "nor000011625",
"linkid": "nord-vpn",
"type": "Vulnerability",
"date": "1/2025",
"severity": "25",
"impact": "1",
"explanation": "Attack without any consequences"
{'affected_entities': [{'industry': 'Cybersecurity',
'name': 'NordVPN',
'type': 'VPN Service Provider'}],
'data_breach': {'type_of_data_compromised': ['payment-related data',
'email account confirmation']},
'date_detected': 'October 2024',
'description': 'In October 2024, NordVPN was served with a warrant by '
'Panamanian authorities demanding user data for a criminal '
"investigation. NordVPN's adherence to privacy meant all they "
'could provide was payment-related data and email account '
'confirmation. Though this incident showcases potential '
"vulnerabilities, NordVPN's privacy commitment likely "
'prevented more significant data exposure. They also boast '
'robust security features such as a kill switch, multi-hop '
'connections, and support for several protocols, making it '
'suitable for high-risk situations when paired with Tor.',
'impact': {'data_compromised': ['payment-related data',
'email account confirmation']},
'motivation': 'Criminal Investigation',
'response': {'law_enforcement_notified': 'Yes'},
'threat_actor': 'Panamanian Authorities',
'title': 'NordVPN Served with Warrant by Panamanian Authorities',
'type': 'Data Request Warrant'}