NordVPN acknowledged that an expired internal cryptographic key on a leased Finnish server infrastructure allowed a malicious third party to access the server's management interface and audit internal system configurations.