A security researcher whose name was undefined made a post about the "expired private keys" by Nord which had been leaked and exploited at some point in time, the Nord VPN acknowledged the error that had long been known to them and made several tweets to acknowledge the error.
Join our Telegram Channel To Get Notified Of New Articles & Updates Join Channel
NordVPN Confirms It Was Hacked Due to Expired Private Keys
NordVPN Confirms It Was Hacked Due to Expired Private Keys |
Nord also said that information taken from the server cannot be used to decrypt traffic to any other server. It acknowledges that the stolen encryption key, which has now expired, could have been used to carry out a man-in-the-middle attack, hiding as a NordVPN server. But NordVPN says such an attack will need to be personalized and complicated and applied to one person at a time.
Nord also reported that they had cut ties with the company that maintained the defective server after the incident became public.