NordVPN vs ExpressVPN: Reformed Sinner vs Alleged Ex-Malware Owner
Table of Contents
You’re searching “NordVPN vs ExpressVPN” because these are the two biggest VPN brands.
🚨 Here’s the problem: NordVPN hid a 2018 server breach for over a year. ExpressVPN is owned by Kape Technologies - the company formerly known as Crossrider, an alleged malware and adware distributor until 2018.
My recommendation hierarchy:
- Mullvad - No email, €5/mo forever, actually independent
- ProtonVPN - Swiss jurisdiction, open source
- NordVPN - Reformed but compromised past (if you must choose one of these two)
- ExpressVPN - Kape ownership is disqualifying for privacy software
This comparison will expose why both have fatal trust issues, then present actually trustworthy alternatives.
⚡ Quick Verdict: NordVPN vs ExpressVPN
TL;DR: ExpressVPN owned by Kape (alleged ex-malware distributor). NordVPN hid 2018 breach for 18 months. Neither is ideal. Use Mullvad or ProtonVPN instead.
NordVPN vs ExpressVPN
Feature | NordVPN | ExpressVPN |
---|---|---|
Owner | NordSec | Kape Technologies |
Kape = Ex-Crossrider | No | Yes (alleged malware) |
Monthly Price | $12.99/mo | $12.95/mo |
2-Year Intro | $3.09/mo | $4.99/mo |
Renewal | $12.99/mo | $9.75/mo |
Renewal Increase | 320% | 95% |
Devices | 10 | 10-14 (tiered) |
Port Forwarding | No | Router only |
Netflix Libraries | 30+ libraries | 24+ libraries |
Been Hacked | Yes (2018, hid 18mo) | No |
Open Source | No | No |
Security Audits | Deloitte, Cure53 | 19 audits (most) |
Winner: Neither - Kape ownership vs 2018 breach hiding = both have fatal trust issues.
Why: ExpressVPN’s Kape ownership is disqualifying for privacy software - Kape (formerly Crossrider) was an alleged adware/malware distributor. NordVPN’s 2018 breach wasn’t catastrophic, but hiding it for 18 months destroys trust.
The real alternative: Mullvad is independent, has no affiliate program, and charges €5/mo forever with no email required.
My Rankings Explained
Mullvad (#1):
- No email required, no affiliate program, proven no-logs in police raid, actually independent
ProtonVPN (#2):
- Swiss jurisdiction, open source, port forwarding
NordVPN (#3):
- 2018 breach hidden for 18 months, Panama marketing theater, closed-source apps
ExpressVPN (#4):
- Owned by Kape Technologies (alleged ex-malware distributor Crossrider)
You shouldn’t trust me blindly. Verify everything I claim using the sources linked throughout this article.
The Kape Problem: Why ExpressVPN Ownership Matters
Crossrider: The Alleged Malware History
Before 2018, Kape Technologies was called Crossrider - an alleged adware and malware distributor.
What Crossrider did:
- Made tools for building browser extensions that forced ads onto users’ screens
- 2015 UC Berkeley + Google study identified Crossrider as major affiliate of ad injectors (including SuperFish)
- MalwareBytes argued Crossrider’s browser hijacking was “indistinguishable from a virus”
- Crossrider malware was still causing havoc as late as August 2019
The name change:
- 2018: Crossrider rebranded as “Kape Technologies”
- CEO Ido Erlichman admitted name change was to distance from “controversial past activities”
- Started buying VPN companies immediately after rebranding
Kape’s VPN acquisition spree:
- 2017: CyberGhost for €9.1M
- 2018: Private Internet Access for $127M, ZenMate for €4.8M
- 2021: ExpressVPN for $936 million
Why this matters for privacy software:
A company that allegedly distributed malware and adware now owns multiple VPNs - software designed to protect privacy. The conflict of interest is obvious.
Sources: The Register coverage, Privacy Journal Kape analysis
My take: Kape’s alleged malware past is disqualifying for a privacy company. Even with 19 security audits, the ownership structure itself is a trust issue.
The 2018 NordVPN Breach: What They Hid
March 2018: NordVPN server in Finland breached through insecure remote management system added by datacenter without NordVPN’s knowledge.
April 2019: NordVPN notified about breach, immediately shredded compromised server.
October 2019: NordVPN publicly disclosed breach - 18 months after it occurred.
What was compromised:
- One expired TLS key from one server
- No user data (no logs existed to steal)
- No usernames, passwords, or traffic logs
Why it matters:
The breach itself wasn’t catastrophic. Hiding it for 18 months is what destroys trust. When you discover a breach, you disclose it. NordVPN didn’t.
What they’ve done since:
- Annual third-party audits (Deloitte 2024, Cure53 2024)
- RAM-only servers
- Transparency reports
- Proactive security disclosures
Sources: NordVPN official response, TechCrunch coverage
My take: NordVPN has spent 6 years rebuilding trust. They’ve done the work. But the 18-month hiding period still matters when choosing privacy software.
NordVPN vs ExpressVPN: The Direct Comparison
Pricing: ExpressVPN Better Renewal Terms
NordVPN Pricing
Advertised pricing:
- “Starting at $3.09/month!”
Actual pricing:
- Month-to-month: $12.99/mo
- 2-year intro: $3.09/mo (requires 24-month prepayment = $74 upfront)
- Renewal: $12.99/mo (320% increase from intro)
- Annual cost after renewal: $156/year
Source: NordVPN official pricing
ExpressVPN Pricing
Advertised pricing:
- “Starting at $4.99/month!”
Actual pricing:
- Month-to-month: $12.95/mo
- 2-year intro: $4.99/mo (requires 24-month prepayment = $120 upfront)
- Renewal: $9.75/mo (95% increase from intro)
- Annual cost after renewal: $117/year
Tiered pricing (2025):
- Basic: 10 devices
- Advanced: 12 devices
- Pro: 14 devices
Source: ExpressVPN official pricing
Pricing Winner
On intro pricing: NordVPN wins ($3.09 vs $4.99/mo)
On renewal pricing: ExpressVPN wins ($9.75 vs $12.99/mo)
On renewal increase: ExpressVPN wins (95% vs 320% increase)
On long-term cost: ExpressVPN cheaper after renewal ($117 vs $156/year)
Winner: ExpressVPN for more honest renewal pricing (but still owned by Kape)
Performance: Both Fast, Similar
NordVPN Performance
Server network:
- ~7,900 servers in 118 countries
- NordLynx protocol (WireGuard-based)
- RAM-only servers
Documented performance:
- Average speed: Up to 892 Mbps on fast connections
- Supports 4K streaming
- Some Reddit users report random disconnects on iOS/Mac
ExpressVPN Performance
Server network:
- ~3,000 servers in 105 countries
- Lightway protocol (custom WireGuard alternative)
- TrustedServer technology (RAM-only)
Documented performance:
- Fast speeds competitive with NordVPN
- Consistent performance across platforms
- Generally stable connections
Performance Winner
On server count: NordVPN (~7,900 vs ~3,000)
On speed: Tie - both very fast
Winner: NordVPN for more server options
Streaming Services & Connected Devices
NordVPN Streaming & Devices
Streaming services that work:
- Netflix: 30+ libraries (US, UK, Canada, France, Germany, Japan, etc.)
- Disney+: Works reliably
- Amazon Prime Video: Works
- Hulu: Works (US servers)
- HBO Max: Works with obfuscated servers
- BBC iPlayer: Works (400+ UK servers)
- SmartPlay technology: Auto-bypasses geo-blocks
Simultaneous connections: 10 devices
Supported platforms:
- Windows, macOS, Linux
- iOS, Android
- Android TV, Fire TV Stick, Apple TV
- Smart TVs (Samsung, LG)
- Gaming consoles (PlayStation, Xbox)
- Routers
- Browser extensions
Streaming verdict: 30+ Netflix libraries, excellent streaming
ExpressVPN Streaming & Devices
Streaming services that work:
- Netflix: 24+ libraries (extensive but fewer than Nord)
- Disney+: Works
- Amazon Prime Video: Works
- Hulu: Works
- HBO Max: Works
- BBC iPlayer: Works
- Apple TV+, Showtime, Sling TV: All supported
Simultaneous connections: 10-14 devices (tiered plans)
- Basic: 10 devices
- Advanced: 12 devices
- Pro: 14 devices
Supported platforms:
- Windows, macOS, Linux
- iOS, Android
- Android TV, Fire TV Stick, Apple TV
- Smart TVs
- Gaming consoles
- Routers
- Browser extensions
Streaming verdict: 24+ Netflix libraries, works with all major platforms
Source: ExpressVPN streaming guide
Streaming & Devices Winner
Winner: NordVPN for more Netflix libraries (30+ vs 24+)
However: ExpressVPN offers up to 14 simultaneous connections (Pro plan) vs NordVPN’s 10
Trade-off: More Netflix regions (Nord) vs more devices (ExpressVPN Pro)
Torrenting & P2P: Both Bad (No Practical Port Forwarding)
NordVPN Torrenting
P2P support:
- Allows torrenting on dedicated P2P servers
- No port forwarding (removed for security reasons)
- Can’t seed effectively without port forwarding
- Good for casual downloaders, bad for power seeders
DMCA policy:
- Panama jurisdiction = no DMCA compliance required
- No-logs policy verified by Deloitte 2024
- Can’t identify users from legal requests
Verdict: Casual torrenting only, no seeding.
ExpressVPN Torrenting
P2P support:
- Allows torrenting on all servers
- Port forwarding only via router (impractical for most users)
- Can’t seed effectively without app-level port forwarding
- Good for casual downloaders, bad for power seeders
DMCA policy:
- British Virgin Islands jurisdiction
- No-logs policy verified by KPMG 2025
- Can’t identify users from legal requests
Verdict: Casual torrenting only, router port forwarding too complex.
Source: ExpressVPN port forwarding
Torrenting Winner
Winner: Neither - both lack practical port forwarding
If you seed torrents or need port forwarding, use ProtonVPN (has app-level port forwarding) or Mullvad (also has port forwarding).
Customer Support: ExpressVPN Faster Responses
NordVPN Support
Live chat:
- 24/7 availability
- Response time: Usually within 2-3 minutes
- Quality: Helpful according to reviews
Refund policy:
- 30-day money-back guarantee
- Full refund within 30 days (not prorated)
- Only applies to first purchase (renewals not refundable)
Support score: 8/10 (24/7 live chat, full refund)
ExpressVPN Support
Live chat:
- 24/7 availability
- Response time: Under 1 minute (often under 20 seconds)
- Quality: Highly responsive and helpful
Refund policy:
- 30-day money-back guarantee
- Full refund within 30 days (not prorated)
- 14-day guarantee for renewals (unique)
- Only applies to first-time users
Important exception:
- Apple App Store subscriptions handled by Apple (not ExpressVPN)
Support score: 9/10 (fastest response times, full refund + 14-day renewal guarantee)
Source: ExpressVPN refund policy
Support Winner
Winner: ExpressVPN for faster response times and renewal refund option
Security & Privacy: Both Closed Source, ExpressVPN More Audits
NordVPN Security
Apps: Closed source (you can’t verify the code)
Latest audits:
- Deloitte (November-December 2024): Verified no-logs claim
- Cure53 (June-August 2024): Penetration test and source code review
Privacy features:
- Kill switch
- DNS leak protection
- Split tunneling
- Double VPN
- Onion over VPN
- NordWhisper (obfuscation)
Logging policy: No logs (verified by audits)
2018 breach: Expired TLS key compromised, no user data leaked, but hid breach for 18 months
ExpressVPN Security
Apps: Closed source (you can’t verify the code)
Latest audits:
- KPMG (February 2025): Third no-logs audit
- Cure53 (multiple): Lightway protocol, Aircove router
- PwC (previous audits)
- 19 total third-party audits (most in VPN industry)
Privacy features:
- Kill switch (Network Lock)
- DNS leak protection
- Split tunneling
- TrustedServer technology (RAM-only servers)
- Lightway protocol (open source)
Logging policy: No logs (verified by KPMG 2025)
No breach history
Source: ExpressVPN KPMG audit
Security Winner
Winner: ExpressVPN for most audits (19 vs Nord’s handful)
However: Kape ownership negates audit advantage - alleged ex-malware company owning privacy software is the bigger issue.
Why Both Are Wrong for You
You searched “NordVPN vs ExpressVPN” because:
- Both are massive brands
- Both advertise privacy and no-logs
- Both have audits and certifications
- YouTubers recommend both (for the $40-95 commissions)
Here’s what they’re not telling you:
About ExpressVPN:
- Owned by Kape Technologies (alleged ex-malware distributor Crossrider)
- Name change in 2018 to distance from “controversial past”
- Kape also owns CyberGhost, PIA, ZenMate
- Closed-source apps (can’t verify what they do)
- I don’t promote them despite affiliate program existence
About NordVPN:
- 2018 breach hidden for 18 months
- Panama jurisdiction is marketing theater
- Closed-source apps (can’t verify what they do)
- No port forwarding (useless for seeding)
- $40/sale affiliate commissions drive recommendations
The better question: “What VPN isn’t owned by alleged ex-malware companies and didn’t hide breaches?”
What You Should Actually Use Instead
If You Need Hardcore Privacy
Don’t use: ExpressVPN (Kape-owned) or NordVPN (hid breach)
Use instead: Mullvad
Why:
- No email required: Random 16-digit account number
- No affiliate program: Actually independent
- Pay with cash: Mail €5 in an envelope (or crypto, cards)
- €5/month forever: No intro discount, no renewal increase
- Open source: Apps verifiable on GitHub
- Port forwarding: Available for torrenting/seeding
- Proven no-logs: 2023 Swedish police raid found nothing
- Actually independent: Not owned by Kape, NordSec, or anyone else
If You Need Streaming + Privacy
Don’t use: Mullvad (doesn’t try to unblock streaming)
Use instead: ProtonVPN
Why:
- Swiss jurisdiction with real privacy laws
- Open-source apps (verifiable)
- Port forwarding for torrenting
- Works with 10 Netflix libraries + major streaming services
- No Kape ownership
- No breach history
- Actually independent
If You Must Choose Between NordVPN and ExpressVPN
Choose NordVPN if:
- Kape ownership bothers you more than 6-year-old breach
- You want more Netflix libraries (30+ vs 24+)
- You want lower long-term cost ($156 vs $117/year after discount ends)
- You can tolerate closed-source apps
Choose ExpressVPN if:
- 18-month breach hiding bothers you more than Kape ownership
- You want more audits (19 vs handful)
- You want 14 devices (Pro plan) vs 10
- You want better renewal terms (95% vs 320% increase)
But honestly: Neither. Both have fatal trust issues for privacy software.
Real User Experiences: Reddit Reality
NordVPN User Complaints
From Reddit (2024-2025):
Common issues:
- 2018 breach trust issues persist among privacy-focused users
- Billing issues with slow support response during promo periods
- Removed port forwarding (frustrates torrenting users)
- Split tunneling problems on Windows devices
- Random disconnects on iOS/Mac reported
Positive feedback:
- Fast speeds for streaming
- Netflix works reliably
- Reformed trust through audits and transparency
Pattern: Users appreciate performance but question trust given 18-month breach hiding.
ExpressVPN User Complaints
From Reddit (2024-2025):
Common issues:
- Kape ownership concerns (alleged ex-malware distributor)
- Expensive pricing compared to competitors
- Split tunneling DNS issues (Nov 2024)
- Apps excluded from VPN still routing DNS through VPN
Positive feedback:
- Excellent support (under 1 minute response)
- Reliable streaming
- Good for gaming (low latency)
Pattern: Users praise performance but distrust Kape ownership for privacy software.
The Common Thread
Both VPNs share these issues:
- Closed-source apps (can’t verify)
- No practical port forwarding (useless for seeding)
- Affiliate marketing drives recommendations ($40-95/sale)
- Trust issues: Kape ownership vs breach hiding
The Bottom Line: NordVPN vs ExpressVPN
Direct comparison verdict:
NordVPN vs ExpressVPN is choosing between a company that hid a breach for 18 months and a company owned by an alleged ex-malware distributor.
If you must choose between them: NordVPN is less problematic than Kape ownership. The 2018 breach wasn’t catastrophic (expired TLS key, no user data), and they’ve rebuilt trust with 6 years of audits and transparency. Kape’s alleged malware past is ongoing and structural.
But honestly? You’re choosing between two fatally flawed options.
What you should actually do:
- Need hardcore privacy? → Mullvad (€5/mo, no email)
- Need streaming + privacy? → ProtonVPN (Swiss jurisdiction, open source)
- Forced to choose? → NordVPN (less problematic than Kape ownership)
Verify This Yourself
Want to see the raw data behind my claims? Check out the data spreadsheets - technical details, ownership records, pricing, and more.
Don’t trust me. Verify everything:
Kape/Crossrider claims:
- Windscribe investigation: What is Kape Technologies?
- ExpressVPN acquisition: The Register coverage
- Privacy Journal analysis: Kape Technologies guide
NordVPN claims:
- 2018 breach: Official response, TechCrunch
- Pricing: NordVPN official pricing
- 2024 audit: Deloitte audit announcement
- NordVPN review
ExpressVPN claims:
- Pricing: ExpressVPN official pricing
- 2025 audit: KPMG no-logs audit
- Kape ownership: ExpressVPN About page
- ExpressVPN review
My commission claims:
- ExpressVPN affiliate program exists (verified)
- NordVPN affiliate program exists (verified)
- Mullvad has no affiliate program: Verify on their site
Better alternatives:
- Try Mullvad for €5 (no email, no commitment)
- Try ProtonVPN with 30-day money-back guarantee
- Read independent reviews on NYTimes/WireCutter and Wired
Legal Note: This comparison contains both documented facts (linked to sources) and my personal opinions based on those facts. All opinions are clearly marked as such. Kape/Crossrider’s alleged malware distribution is documented in multiple sources linked above.
Affiliate disclosure: I make money from affiliate links to NordVPN and ProtonVPN. I make nothing from Mullvad (no affiliate program) and nothing from ExpressVPN (I don’t promote Kape-owned products). I’m ranking Mullvad highest despite no commission, and warning about ExpressVPN despite affiliate availability.
Top Comments (8)
nordvpn forces you to give them all your personal information, name, credit number, etc. to even sign up. mullvad goes out of its way to let you decide what to share, which is a massive difference.
nordvpn has given us nothing but unverifiable words to trust them whereas mullvad has given us am...
But overall, ProtonVPN was better for me. With MV I had too many issues with connections.
It's $5 just try it.
Why not give it a try ? no need credentials, you can pay for a month and try. 1 months or 1 year, monthly cost is the same