Is NordPass Safe? What Happens If It's Hacked
Last verified: August 3, 2026
There is a specific fear that keeps people off password managers, and it has nothing to do with technology. It is the fear of putting every key you own onto one keyring, then handing that keyring to a company you had never heard of until last week, headquartered in a country you would struggle to find on a map.
That fear is reasonable. I would rather answer it properly than talk you out of it.
I have spent ten years in IT, four of them in DevSecOps, and I recommend NordPass on this site. I also earn a commission if you sign up through my links, which is exactly why this page includes the parts Nord does not put in its advertising.
The short answer
NordPass is safe for the vast majority of people. Your passwords are scrambled on your own device before they ever reach Nord's servers, so Nord cannot read them even if it wanted to. Independent auditors at Cure53 have examined the system repeatedly since 2020. NordPass itself has never been breached.
Three things should still give you pause, and I cover them below.
Who actually owns NordPass
This trips people up, so let me untangle it.
NordPass is built by Nord Security, a Lithuanian company headquartered in Vilnius. The founders are Lithuanian. The engineering is Lithuanian. Lithuania is in the European Union, which means the company answers to GDPR, one of the stricter privacy regimes in the world.
You may have read that Nord is based in Panama. That applies to NordVPN, a different product from the same parent, which operates through a Panamanian legal entity because Panama has no mandatory data retention laws. Your password vault is not governed by that arrangement.
One more piece of context: Nord Security and Surfshark became part of the same corporate group following a merger completed in 2022. If you were planning to hedge by using NordPass for passwords and Surfshark for your VPN, you would be buying from the same parent company. That is not a security problem. It is worth knowing.
Nord Security also owns NordVPN, NordLocker, NordLayer, and Coveron, the identity protection product formerly called NordProtect.
Can NordPass employees read my passwords?
No, and the reason is worth understanding because it is the whole basis of trusting any password manager.
Picture a safe deposit box where the bank never gets a key. You bring your own lock, you snap it shut, and you hand the bank a sealed metal box. The bank stores the box, ships it to your other branches, and keeps it safe from fire. At no point can anyone at the bank open it.
That is roughly what NordPass does. Your master password never leaves your device. It is used locally to scramble everything in your vault, and only the scrambled result gets uploaded. Nord's servers hold sealed boxes. The technical term is zero-knowledge architecture, and it means the company genuinely has no way to look inside.
The scrambling itself uses a cipher called XChaCha20-Poly1305, with a key-strengthening step called Argon2id. Most competitors use AES-256. Both are strong enough that the encryption will never be the weak link in your security. If anyone tells you one of these is dramatically safer than the other, they are selling something.
The weak link is always the same thing: your master password, and whether you reused it somewhere else. Generate that one with a free client-side password generator and never type it into anything but NordPass.
Has NordPass ever been hacked?
NordPass has not been breached since it launched in 2019.
Its sibling product has, and you deserve the full story rather than a reassuring sentence.
In March 2018, an attacker accessed a single NordVPN server rented from a data center in Finland. The attacker exploited an insecure remote management system that the data center provider had left in place, which NordVPN says it did not know existed. NordVPN was notified on April 13, 2019 and destroyed the server the same day. The attacker obtained an expired TLS certificate key. The server held no user activity logs, and no usernames or passwords were on it.
The part that bothers me is the timeline. NordVPN did not disclose publicly until October 2019, and the delay drew heavy criticism. The company said it needed to audit the rest of its infrastructure first. That explanation is plausible and it is also convenient, and reasonable people landed on both sides of it.
Since then Nord moved its VPN network to RAM-only servers, added a bug bounty program, and committed to recurring third-party audits. The response was substantive.
Two things are true at once here. That incident happened to a rented VPN server, not to a password vault, and the two systems are architecturally unrelated. It also tells you something real about how the company handled bad news in 2019, and you are allowed to weigh that.
Who has checked their work?
Nord did not just publish a whitepaper and ask you to believe it.
NordPass has been independently audited by Cure53, the German security firm. The 2020 audit covered the cryptographic design, source code, background processes, desktop apps, browser extensions, iOS, and Android. It found nine vulnerabilities, which NordPass fixed before the auditors finished the remaining areas. A 2021 audit additionally covered the admin panel and Nord Account. Cure53 is the same Berlin firm that audits Proton, Mullvad, and 1Password, and NordPass has refreshed the audit on roughly an annual cadence since. The company also holds SOC 2 certification.
An audit does not prove a product is unbreakable. It proves that qualified strangers went looking for problems and that the problems they found got fixed. That is a meaningfully higher bar than most software you use clears.
Three reasons to hesitate
Any page that lists only reassurances is an advertisement. These are the real caveats.
1. You cannot inspect the code yourself.
NordPass is closed source. Nobody outside Nord and its auditors can read the software and confirm it does what the documentation claims. You are trusting Nord's engineers plus Cure53's periodic review. For most people that is a perfectly rational trade. If you want software that anyone can inspect at any time, Proton Pass and Bitwarden are open source, and I compare the options in the 2026 password manager rankings.
2. The free plan is more limited than it looks.
NordPass Free stores unlimited passwords, which sounds generous. It also limits you to one active device session at a time. Log in on your phone and you get logged out on your laptop. For anyone who uses both a computer and a phone, which is nearly everyone, the free tier becomes annoying within a week. Budget for the paid plan or pick a manager with a more usable free tier.
3. If you lose your master password and your recovery code, your data is gone permanently.
This is not a NordPass flaw. It is the direct consequence of zero-knowledge design, and every serious password manager works this way. Nord cannot reset your vault because Nord cannot open your vault. Write your recovery code on paper and put it somewhere you would keep a passport. People lose vaults over this far more often than they get hacked.
What happens if NordPass gets breached tomorrow?
This is the question underneath the question, so let me answer it directly.
If an attacker walked out of Nord's data center with the entire customer database, they would have millions of sealed boxes and no keys. Your vault would be an unreadable block of scrambled data. Cracking it would require guessing your master password, and Argon2id is specifically designed to make each guess slow and expensive.
Which brings the risk back to you. A vault protected by a strong, unique 16-plus character master password is realistically uncrackable. A vault protected by your dog's name and a birth year is not.
Compare that to the alternative most people are actually using. Passwords saved in Chrome are tied to your Google account and unlock whenever your computer does, which means anyone with access to your unlocked laptop has access to everything. I broke down why that matters in why browser password managers are not as safe as you think.
So should you use it?
NordPass is a good fit if you want something that works without a learning curve, you have a family to cover, or you already use NordVPN and want one bill. The family plan covers six people for about $3.69 a month in the first year, the best value in this portfolio, though it renews higher.
Look elsewhere if you specifically want open-source software you or the community can inspect, you need a genuinely usable free tier across multiple devices, or the 2019 disclosure delay sits badly with you. Proton Pass and Bitwarden are the two obvious alternatives, and I put NordPass head to head with one of them in NordPass vs Bitwarden 2026.
Frequently asked questions
Is NordPass safe to use in 2026?
Yes. NordPass encrypts your vault on your own device using XChaCha20-Poly1305 and Argon2id, so Nord cannot read your passwords. It has been independently audited by Cure53 since 2020, holds SOC 2 certification, and has never been breached.
Who owns NordPass?
Nord Security, a privately held Lithuanian company headquartered in Vilnius. The same company owns NordVPN, NordLocker, NordLayer, and Coveron. Nord Security and Surfshark have been part of the same corporate group since a 2022 merger.
Is NordPass based in Panama?
No. Nord Security is headquartered in Lithuania. NordVPN, a separate product, operates through a Panamanian legal entity. Your password vault is not governed by that arrangement.
Has NordPass ever been hacked?
NordPass has not been breached since its 2019 launch. A single NordVPN server in Finland was accessed in March 2018 through a data center misconfiguration. No usernames, passwords, or activity logs were on that server, and it was a different product.
Can NordPass employees see my passwords?
No. NordPass uses zero-knowledge architecture, meaning your master password never leaves your device and your vault is encrypted before it is uploaded. Nord's servers only hold encrypted data they cannot decrypt.
What happens if I forget my NordPass master password?
You can recover your vault with your recovery code. If you lose both the master password and the recovery code, the vault is permanently unrecoverable. Nord cannot reset it, because Nord cannot open it. Store your recovery code on paper somewhere safe.
Is NordPass free version good enough?
For most people, no. The free plan stores unlimited passwords but allows only one active device session at a time, so logging in on your phone signs you out on your computer. If you use both a phone and a computer, plan on the paid tier.