Nord Security A.I CyberSecurity Scoring
Nord Security
Company Information
Website:https://nordsecurity.com
Employees number:1,813
Number of followers:78,247
NAICS:541514
Industry Type:Computer and Network Security
Homepage:nordsecurity.com
Nord Security Risk Score (AI oriented)
Between 600 and 649
Nord SecurityComputer and Network Security
Updated:
20/03/2026
20/03/2026
624/1000
Poor
Caa
Nord Security Global Score (TPRM)
xxxx
Nord SecurityComputer and Network Security
Score locked

Nord SecurityPoor
Current Score
624Caa (POOR)
01000
3 incidents
-55.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
639
JULY 2026
637
JUNE 2026
634
MAY 2026
630
APRIL 2026
628
MARCH 2026
672
Cyber Attack
19 Mar 2026 • Nord Security
NordStellar and NordVPN: Infostealers New Cyber Security Threat: Nord Security
Infostealers Surge as Data Breaches Decline, Exposing Far More Credentials
624
CRITICAL-48
NOR1773973666
Infostealers Surge as Data Breaches Decline, Exposing Far More Credentials
A shift in cybercriminal tactics is reshaping the threat landscape, with infostealers malware designed to silently harvest sensitive data from infected devices now outpacing traditional data breaches in scale. While compromised databases dropped by 36% between 2024 and 2025 (from 4,804 to 3,069), infostealer activity surged by 35%, with logs increasing from 19.5 million to over 26 million in the same period.
The disparity in stolen credentials is stark: in 2025, breaches exposed 34 million passwords, while infostealers harvested 624 million an 18-fold difference. For email addresses, breaches leaked 542 million compared to infostealers’ 380 million, though the gap has narrowed in recent years.
Infostealers typically spread through pirated software, malicious downloads, and phishing emails, operating undetected to extract saved passwords, browser cookies, autofill data, and session tokens. Unlike high-profile breaches, these attacks are less visible but equally damaging to individuals, as a single infection can compromise a victim’s entire digital footprint.
The findings, from research by NordVPN and NordStellar, highlight how cybercriminals are prioritizing stealth and efficiency over large-scale breaches, making infostealers a growing risk for both personal and corporate security.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
670
JANUARY 2026
730
Breach
05 Jan 2026 • Nord Security
NordVPN: NordVPN Denies Breach After Hacker Claims Access to Salesforce Dev Data
NordVPN Development Server Alleged Breach by Hacker 1011
667
LOW-63
NOR1767632574
NordVPN Development Server Allegedly Breached by Hacker "1011"
A hacker operating under the alias 1011 claimed to have breached a NordVPN development server, posting purported database dumps and configuration samples on BreachForums. The leak, titled “nordvpn.com SalesForce – leaked, Download!”, included alleged Salesforce API keys, Jira tokens, and source code from over ten databases. The hacker asserted access was gained by brute-forcing a misconfigured system, though screenshots shared did not conclusively link the data to NordVPN’s production environment.
NordVPN swiftly denied the claims, stating that its internal systems remain uncompromised. In a blog post, the company clarified that the leaked files originated from a six-month-old test environment used to evaluate a third-party platform. The trial, which ended without a signed contract, involved an isolated sandbox with no connection to live systems. NordVPN confirmed the data contained only dummy content and was never integrated into its operational infrastructure.
The company emphasized that the environment was not part of its active Salesforce setup and that no customer data, real API keys, or internal source code were exposed. NordVPN has contacted the third-party vendor for further details but maintains that the incident poses no risk to users. As of now, no verifiable evidence ties the leaked samples to NordVPN’s production systems.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
730
NOVEMBER 2025
729
OCTOBER 2025
728
SEPTEMBER 2025
726
JANUARY 2025
761
Cyber Attack
01 Jan 2025 • Nord Security
NordVPN and NordStellar: Research: Data breaches down, password theft up
Infostealers Surge as Cybercriminals Shift Tactics Away from Data Breaches
715
CRITICAL-46
NORNOR1773829992
Infostealers Surge as Cybercriminals Shift Tactics Away from Data Breaches
A growing threat is quietly eclipsing traditional data breaches as cybercriminals pivot to more efficient methods of stealing sensitive information. Research from NordVPN and NordStellar reveals that while compromised databases declined by 36% between 2024 and 2025 dropping from 4,804 to 3,069 infostealer malware logs surged by 35%, rising from 19.5 million to over 26 million in the same period.
Unlike high-profile breaches, infostealers operate stealthily, extracting saved passwords, browser cookies, autofill data, and session tokens directly from victims’ devices. Mantas Sabeckis, senior threat intelligence researcher at Nord Security, notes that while breaches may be decreasing, the shift to infostealers represents a more insidious risk: "A single infection can silently harvest everything, often without the victim ever knowing."
The trend aligns with findings from Cloudflare’s 2026 Threat Report, which highlights a broader shift in attacker behavior. Cybercriminals are prioritizing efficiency over sophistication, favoring stolen credentials over costly exploits. In 2025, infostealers harvested 624 million passwords 18 times more than the 34 million exposed in breaches. For email addresses, breaches leaked 542 million, while infostealers captured 380 million, with the gap narrowing rapidly.
Marijus Briedis, CTO at NordVPN, underscores the danger: "Breaches trigger alerts and remediation, but infostealers operate in silence. Victims often only discover the theft when their accounts are already compromised." The malware typically spreads through pirated software, fake downloads, and phishing emails, running undetected in the background.
While basic security measures such as password managers, software updates, and anti-malware tools can mitigate risks, awareness remains a critical gap. As Briedis points out, "Most people understand data breaches, but few recognize infostealers a threat that bypasses corporate defenses entirely."
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Nord Security ??
What was Nord Security's A.I Rankiteo Cyber Score in July 2026 ??
What was Nord Security's A.I Rankiteo Cyber Score in June 2026 ??
What was Nord Security's A.I Rankiteo Cyber Score in May 2026 ??
What was Nord Security's A.I Rankiteo Cyber Score in April 2026 ??
What was Nord Security's A.I Rankiteo Cyber Score in March 2026 ??
What was Nord Security's A.I Rankiteo Cyber Score in February 2026 ??
What was Nord Security's A.I Rankiteo Cyber Score in January 2026 ??
What was Nord Security's A.I Rankiteo Cyber Score in December 2025 ??
What was Nord Security's A.I Rankiteo Cyber Score in November 2025 ??
What was Nord Security's A.I Rankiteo Cyber Score in October 2025 ??
What was Nord Security's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Nord Security's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Nord Security ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Nord Security's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?