>NordVPN said it found out about the breach a “few months ago,” but the spokesperson said the breach was not disclosed until today because the company wanted to be “100% sure that each component within our infrastructure is secure.” So instead of allowing their customers to do their own damage limitation, they left their customers in the dark and continued to expose them to a breach they weren't sure they had fully c…
I think that is pretty criminal already. Basically: 1- Nord falsely blames its server provider. 2- Nord hides it from their users. 3- Nord claims all will be well with an “audit” (again, since they were already “audited”) This is either criminal negligence, “security theater”, or both.
I don't see anything in the article about those claims being false. Where did you get that?