A threat actor identified as 1011 claimed to have breached NordVPN’s development infrastructure, leaking over ten database source codes, Salesforce API keys, and Jira tokens on a dark web forum. The attacker alleged that access was gained via a misconfigured development server in Panama, and released sample SQL dump files as proof, exposing the structure of sensitive backend database tables. Security researchers noted that the incident highlights the risks associated with poorly secured development environments, as the leaked credentials could potentially enable further attacks against NordVPN’s business tools and ecosystem.
NordVPN responded by denying that any sensitive internal systems were compromised, stating that the data originated from a temporary test environment used during a vendor evaluation for automated testing. According to NordVPN, the environment was isolated, contained only dummy data, and was never connected to production systems or real customer information. The company emphasized that no actual customer or business data was exposed, and that the threat actor’s claims were based on non-sensitive, non-production artifacts. The incident underscores the importance of securing all environments, including those used for testing and vendor trials, to prevent reputational and operational risks from similar claims.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
NordVPN responded that the allegedly stolen material came from an isolated test environment tied to a third-party vendor and did not involve production infrastructure, customer data, or live credentials. The company said it contacted the vendor, found no evidence of compromise in core systems, and told users no action was required.
SOCRadar said its Dark Web Team observed new underground forum posts this week in which threat actors claimed to possess internal NordVPN development data. The post framed the listing as a potential security risk to the company and its users.
A threat actor using the handle 1011 claimed on a dark web forum to have accessed a NordVPN Salesforce development environment by brute-forcing a misconfigured server. The actor posted sample database dumps and alleged source code, Salesforce API keys, and Jira tokens as proof.
NordVPN said the exposed files came from an isolated third-party automated testing platform used during a proof-of-concept evaluation about six months before the reports. The company said this temporary sandbox was never connected to production systems and contained only dummy data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
5 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcehackread.com
Open sourcesocradar.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.