
As we reported in a recent article, the NordVPN service recently revealed that it had suffered a credential-stuffing attack, which resulted in the leakage of encryption.
The data leaked from the hack included email IDs, plaintext passwords, and other data related to a user account. Nearly 2,000 NordVPN users have now fallen victim to a credential-stuffing attack, which gives unauthorized access to their accounts.
Credential-stuffing is a type of attack that uses credentials from a leak to access other accounts that use the same username and password.
Ars Technica published a report where it investigated a small sample of users from a directory containing 753 login credentials and found that the same passwords were still being used for other accounts.
This attack brings to the surface a major problem that still exists and that is to some extent responsible for such breaches, and it is none other than the fact that users choose simple passwords which they use on many of their accounts.
NordVPN tried to downplay the attack, saying that malicious actors could simply use the private keys to monitor and control the movements of its customers.
The company says the attackers would have simply limited themselves to monitoring communications, having hacked only one of the company's more than 3,000 servers .
If you are a NordVPN user, you should check the Have I Been Pwnedto see if your email address is listed there. If you find it, you should change password , especially if you use it on other accounts.
The company made sure to give its own explanation for the incident:
Credential stuffing is an attack in which credentials obtained from a data breach on one service are used to log in to another, unrelated service. The listed credentials were obtained from previous leaks and breaches that had nothing to do with NordVPN. Credential stuffing is a major concern not only for NordVPN but for almost every other digital service and website. The reason behind this is that people reuse the same passwords and login names across different accounts or create weak passwords.
Our security team scans credential lists on both public and dark web sites and we urge our customers to change their passwords. In the past, we have notified approximately 50,000 customers to change their passwords. However, the password change rate is only about 50%. The database we use to check these credentials is constantly growing and consists of more than 30 billion entries.
2,000 accounts linked to a breach is a significant number, but we have 12M customers in total. We always work with proactive measures such as rate limiting systems, smart detection systems and, in the future, two-factor authentication (2FA). In addition, we always advise our customers through social media channels, blog and customer newsletters to keep their passwords unique and strong.
