![]() | |
Developer(s) | NordVPN s.a.[1][2] |
---|---|
Initial release | February 13, 2012; 13 years ago (February 13, 2012)[3] |
Stable release | Android 8.3 (January 15, 2025; 2 months ago (2025-01-15)[4]) [±] iOS 8.37 (December 17, 2024; 3 months ago (2024-12-17)[5]) [±] |
Operating system | |
Platform | |
Type | Virtual Private Network |
License | Linux client: GPLv3 onlygithub |
Website | nordvpn |
NordVPN is a LithuanianVPN service with applications forMicrosoft Windows,macOS,Linux,Android,iOS,Android TV, andtvOS.[8][9][10] Manual setup is available forwireless routers,NAS devices, and other platforms.[11][12]
NordVPN is developed by Nord Security (formerly Nordsec Ltd),[13] acompany that createscybersecurity software and was initially supported by the Lithuanianstartup accelerator andbusiness incubator Tesonet. NordVPN states it operates in Panama, but Nord Security is incorporated in Amsterdam, the Netherlands.[14] Its offices are located inLithuania, theUnited Kingdom,Panama, and theNetherlands.[13]
NordVPN was established in 2012 by a group of childhood friends, which includedTomas Okmanas. It presented anAndroid app in late May 2016, followed by aniOS app in June the same year.[15] In October 2017, it launched abrowser extension forGoogle Chrome.[16] The service launched applications forAndroid TV in 2018[17] andtvOS in 2023.[18] As of September 2023,[update] NordVPN was operating 5,600 servers in 59 countries.[19]
In March 2019, it was reported that NordVPN received a directive fromRussian authorities to join a state-sponsored registry of banned websites, which would preventRussian NordVPN users from circumventingstate censorship. NordVPN was reportedly given one month to comply, or face blocking byRussian authorities.[20] The provider declined to comply with the request and shut down its Russian servers onApril 1. As a result, NordVPN still operates inRussia, but its Russian users have no access to local servers.
In September 2019, NordVPN announced NordVPN Teams, aVPN solution aimed at small and medium businesses, remote teams, and freelancers who need secure access to work resources.[21] Two years later, NordVPN Teams rebranded asNordLayer and moved towardSASE business solutions.[22] The press sources quoted the market rise in SASE technology as one of the key factors in the rebrand.[23][24]
On October 29, 2019, NordVPN announced additional audits and a publicbug bounty program.[25] The bug bounty was launched in December 2019, offering researchers monetary rewards for reporting critical flaws in the service.[26]
In December 2019, NordVPN became one of the five founding members of the newly formed VPN Trust Initiative, promising to promote online security as well as more self-regulation and transparency in the industry.[27] In 2020, the initiative announced five key areas of focus: security, privacy, advertising practices, disclosure and transparency, and social responsibility.[28]
In August 2020,Troy Hunt, an Australianweb security expert and founder ofHave I Been Pwned?, announced a partnership with NordVPN as a strategic advisor. On his blog, Hunt described this role as "work with NordVPN on their tools and messaging with a view to helping them make a great product even better."[29]
In 2022, NordVPN closed its physical servers in India in response to theCERT-In's order for VPN companies to store consumers' personal data for a period of five years.[30]
In April 2022, NordVPN's parent company Nord Security raised $100 million in a round of funding led by Novator. The company's valuation reached $1.6 billion.[31] In September 2023, the company grew and raised more funding, making it valued at $3 billion.[32]
In 2022,Surfshark andNord Security merged under one holding company.[33]
NordVPN routes users' internet traffic through a remote server run by the service, thereby hiding theirIP address andencrypting all incoming and outgoing data.[34] For encryption, NordVPN has been using theOpenVPN andInternet Key Exchange v2/IPsec technologies in its applications[35] and also introduced its proprietary NordLynx technology in 2019.[36] NordLynx is a VPN tool based on theWireGuard protocol, which aims for better performance than theIPsec andOpenVPNtunneling protocols.[37] According to tests performed byWired UK, NordLynx produces "speed boosts of hundreds of MB/s under some conditions."[38]
In April 2020, NordVPN announced the gradual roll-out of theWireGuard-based NordLynx protocol on all its platforms.[39] The wider implementation was preceded by a total of 256,886 tests, which included 47 virtual machines on nine different providers, in 19 cities, and eight countries. The tests showed higher average download and upload speeds than bothOpenVPN andIKEv2.
NordVPN once usedL2TP/IPSec andPoint-to-Point Tunneling Protocol (PPTP) connections for routers, but these were later removed, as they were largely outdated and insecure.
NordVPN has desktop applications forWindows,macOS, andLinux, as well as mobile apps forAndroid andiOS andAndroid TV app. Subscribers also get access to encrypted proxy extensions forChrome andFirefox browsers.[40] Subscribers can connect up to six devices simultaneously.[41] NordVPN has released their Linux client under the terms of the GPLv3 only.[42]
In November 2018, NordVPN claimed that its no-log policy was verified through an audit byPricewaterhouseCoopers AG.[43][44]
In 2020, NordVPN underwent a second security audit byPricewaterhouseCoopers AG. The testing focused on NordVPN's Standard VPN, Double VPN, Obfuscated (XOR) VPN, P2P servers, and the product's central infrastructure. The audit confirmed that the company's privacy policy was upheld and the no-logging policy was followed.[45]
In 2021, NordVPN completed an application security audit, carried out by a security research group VerSprite. VerSprite performedpenetration testing and, according to the company, found no critical vulnerabilities. One flaw and a few bugs that were found in the audit have since been patched.[46]
In October 2020, NordVPN started rolling out its firstcolocated servers inFinland to secure thehardware perimeter. The RAM-based servers are fully owned and operated by NordVPN in an attempt to keep full control.[47][48]
In December 2020, NordVPN initiated a network-wide rollout of 10Gbit/s servers, upgrading from the earlier 1 Gbit/s standard. The company's servers inAmsterdam andTokyo were the first to support 10 Gbit/s, and by December 21, 2020, over 20% of the company's network had been upgraded.[49][50]
In January 2022, NordVPN released an open-source VPN speed testing tool, available for download fromGitHub.[51]
Besides general-use VPN servers, the provider offers servers for specific purposes, includingP2P sharing, double encryption, and connection to theTor anonymity network.[52] NordVPN offers three subscription plans: monthly, yearly and bi-yearly.
In November 2020, NordVPN launched a feature that scans thedark web to determine if a user's personal credentials have been exposed. When the Dark Web Monitor feature finds any leaked credentials, it sends a real-time alert, prompting the user to change the affected passwords.[53]
In February 2022, NordVPN introduced anantivirus functionality available as part of the regular VPN license. The opt-in Threat Protection feature blocksweb trackers, warns users about malicious websites, and blocks downloaded files that containmalware.[54] As of March 2022, the feature is available on the Windows andmacOS apps and works without connecting to a VPN server.[55]
In June 2022, NordVPN launched the Meshnet feature that allows users to create their ownprivate network by linking up to 60 devices. Some of the promoted use cases includefile sharing between different devices,multiplayer gaming, andvirtual routing.[56]
Several publications, includingTom's Guide,[57]PC Magazine,[52]CNET,[58] andTechRadar[59] have reviewed NordVPN. Most noted that NordVPN's features such as choosing server location, and speed are good. They also noted the service's high price compared to others in the category.
On October 21, 2019, a security researcher disclosed onTwitter a server breach of NordVPN involving a leakedprivate key.[60][61][62] The cyberattack granted the attackersroot access, which was used to generate anHTTPScertificate that enabled the attackers to performman-in-the-middle attacks to intercept the communications of NordVPN users.[63] In response, NordVPN confirmed that one of its servers based inFinland was breached in March 2018, but there was no evidence of an actual man-in-the-middle attack ever taking place.[64][65] Theexploit was the result of avulnerability in a contracteddata center'sremote administration system that affected theFinland server between January 31 and March 20, 2018.[64] Evidence suggests that when the data center became aware of the intrusion, all accounts that had caused the vulnerabilities were deleted and NordVPN was not notified about the mistake.[66][67]
According to NordVPN, the data center disclosed the breach to NordVPN on April 13, 2019, and NordVPN ended its relationship with the data center.[65] In addition, experts state that there are no indications of any user’s private information such as user credentials, billing details, or any other profile-related information being compromised during that event.[68][69][70] Security researchers and media outlets criticized NordVPN for failing to promptly disclose the breach after the company became aware of it.[62][61][71] NordVPN stated that the company initially planned to disclose the breach after it completed the audit of its 5,000 servers for any similar risks[62] and later put regular updates on its blog.[72]
On November 1, 2019, in a separate incident, it was reported that approximately 2,000usernames andpasswords of NordVPN accounts were exposed throughcredential stuffing.[73][74]
In 2019, theAdvertising Standards Authority (United Kingdom) (ASA) advised NordVPN not to repeat claims that publicWiFi is so insecure it is equivalent to handing out your personal information to the people around you.[75] The ASA ruled that HTTPS already provides "a significant layer of security" and that the impression the ad gave that users were at a significant risk from data theft was erroneous.[76] In 2023, the ASA again ruled against NordVPN, this time over an advertisement which claimed NordVPN could "switch off... malware", holding that, in context, listeners were "likely to understand" it to mean the product would stop all malware, which NordVPN did not substantiate in response to the ASA.[77]
In January 2022, NordVPN updated its policy regarding law enforcement cooperation,[78] according to statements from PCMag[79] and TechRadar.[80] Previously, NordVPN had maintained a strict no-logs policy, preventing any user-identifying data from being stored. The 2023 update clarified that, while the no-logs policy continued, NordVPN would comply with law enforcement requests when required by local legal authorities. This change reflected increased regulatory pressures on VPN providers to support investigations related to cybersecurity and criminal activities.[78]
Privacy advocates, including VPN.com, expressed concern that this cooperation might compromise user privacy and set a precedent for other VPN services. Critics argued that any law enforcement compliance could challenge NordVPN’s commitment to anonymity, while NordVPN, as cited by TechRadar, asserted its dedication to privacy by only responding to legal requests and maintaining minimal data retention.[80] Transparency statements from the company outlined strict compliance conditions, aiming to reassure users about privacy safeguards under the revised policy.[81]