NordVPN’s Logging Scandal Resurfaces as Fresh Audits Pile Up

NordVPN's 2019 breach exposed customer emails and raised no-logs doubts that persist despite six Deloitte audits. Recent reviews confirm no contradictory evidence yet highlight audit limits and past metadata issues. The company fixed app vulnerabilities quickly. Skepticism remains among privacy professionals.
NordVPN’s Logging Scandal Resurfaces as Fresh Audits Pile Up
Written by Eric Hastings

Years after a data breach exposed customer emails, NordVPN faces renewed questions about its no-logs claims. The controversy refuses to fade. Even as the company touts its sixth clean audit from Deloitte in early 2026, critics point to court documents and old server logs that tell a different story.

The episode began in 2019. Hackers hit a third-party data center in Finland rented by NordVPN. They gained access for over a month. No user traffic was intercepted. But the breach revealed something else. Emails tied to the service leaked online.

That single incident became the biggest reason many security professionals hesitated to recommend NordVPN. MakeUseOf reported how the event shattered confidence in the provider’s privacy assurances. Users wondered if the no-logs policy held up under pressure. Or if it was marketing speak.

Fast forward to 2024 and 2025. New details emerged from class-action lawsuits and technical reports. They painted a picture of metadata collection that some experts say borders on logging. NordVPN pushed back. It commissioned multiple audits. Deloitte examined its infrastructure again in late 2025. The conclusion? No evidence contradicted the no-logs policy.

But audits have limits. They offer snapshots. Not continuous monitoring. CNET detailed the latest review, which ran from November 10 to December 12, 2025. Auditors inspected servers, interviewed staff, and checked specialized setups like Double VPN and Onion Over VPN. Still, the full report stays behind a login for customers only. Transparency has boundaries.

And the 2019 breach keeps haunting the narrative. Court filings unsealed in subsequent years showed NordVPN had collected some connection timestamps and server identifiers. Not full activity logs. Yet enough to identify users in certain scenarios. One lawsuit alleged the company knew about risks in its data center contracts but failed to act swiftly.

NordVPN insists it learned from the incident. It moved to own more of its server fleet. It adopted RAM-only servers that wipe on reboot. These changes matter. They reduce the attack surface. But trust, once broken, demands more than promises.

Security audits tell part of the story. In March 2025, TechRadar covered a Cure53 review of NordVPN’s apps and features. The firm found 31 issues. None critical. Twenty-two counted as vulnerabilities, some high severity. NordVPN fixed most before the audit wrapped. Its chief technology officer stated security sits at the core of everything the company does.

That sounds reassuring. Yet the volume of findings raises eyebrows among cybersecurity veterans. Apps handle sensitive tunnel configurations. A single flaw could expose traffic. NordVPN’s rapid remediation helps. It doesn’t erase the pattern of repeated discoveries across audits.

Recent chatter on X reflects divided opinions. Some users praise the string of Deloitte verifications. Others flag the 2019 event as permanent red flag. One thread ranked NordVPN below Mullvad and ProtonVPN on audit rigor and historical baggage. These debates play out in forums and comment sections daily.

The VPN market demands proof. Providers compete on speed, features, and now verifiable privacy. NordVPN offers Threat Protection, Meshnet, and obfuscated servers. Useful tools. They mean little if the core logging policy crumbles under legal pressure.

Consider the broader context. Governments push for data retention. Law enforcement seeks cooperation. A true no-logs service resists both. NordVPN operates from Panama. That jurisdiction favors privacy. It lacks mandatory data retention laws. Advantageous. Not bulletproof.

Independent reviews help. But they rely on the provider’s description of its systems. Deloitte tested what NordVPN said it did. If the description omits certain telemetry, the audit misses it. This gap fuels skepticism.

So what should IT managers and privacy-conscious executives do? Look past marketing. Examine the audit scopes. Read the fine print on what exactly was not logged. Cross-reference with breach history. And test the service themselves under controlled conditions.

NordVPN has invested heavily in rebuilding credibility. Annual audits. Infrastructure upgrades. Public statements. The sixth Deloitte engagement in February 2026 marks continued commitment. “NordVPN has passed its sixth independent no-logs assurance engagement, confirming it does not collect or store user connection logs,” the company announced.

Yet the original breach exposed more than emails. It exposed assumptions. Many assumed outsourced data centers were hardened. They weren’t. Many assumed no-logs meant zero data. Reality proved more nuanced. Timestamps. Account metadata. These details accumulate.

Other providers face scrutiny too. The industry shares this challenge. But NordVPN’s size makes it a target. Over 15 million users at one point. High profile. High expectations.

Recent web searches turn up no major new incidents in 2026. No fresh breaches reported. The conversation circles back to that 2019 event and the audits that followed. NordVPN’s own blog highlights the Deloitte work as proof of reliability.

Analysts recommend layered defenses anyway. A VPN forms one piece. Pair it with endpoint protection, strong authentication, and user training. Don’t rely on any single vendor for complete anonymity.

The NordVPN story illustrates a hard truth. Privacy claims require constant validation. One breach can define a brand for years. Audits provide evidence. They rarely deliver absolute certainty. Users must weigh the risk. Decide if the convenience outweighs lingering doubts.

Short answer. The busted reason not to use NordVPN still lingers in many assessments. Longer view. The company adapted. It strengthened operations. Whether that satisfies the most cautious buyers remains their call.

Subscribe for Updates

MobileDevPro Newsletter

By signing up for our newsletter you agree to receive content related to ientry.com / webpronews.com and our affiliate partners. For additional information refer to our terms of service.

Notice an error?

Help us improve our content by reporting any issues you find.

Get the WebProNews newsletter delivered to your inbox

Get the free daily newsletter read by decision makers

Subscribe
Advertise with Us

Ready to get started?

Get our media kit

Advertise with Us