NordVPN says one of its servers was breached in March 2018, exposing some of the browsing habits of customers who were using the VPN service to keep their data private. NordVPN says the server, located in Finland, did not contain activity logs, usernames, or passwords. But the attacker would have been able to see what websites users were visiting during that time, a company advisor said, although the content of the websites likely would have been hidden due to encryption.
The NordVPN service was compromised because of old unused accounts still being active on their servers according to other sources on the incident. Disabling former employees and no longer used accounts is such a simple security measure it often goes overlooked.