I'm looking at Mullvad and NordVPN. I know Nord had a MITM attack on a Finnish datacenter a few months ago and didn't immediately notify affected users. I'm having trouble understanding what it says about Nord's culture and likely behavior in the future. On a technical level, it's pretty bad when users of a VPN like this can be MITM'd. Blaming the datacenter's remote admin tools doesn't help me as a user because the same thing could happen again. I know they have a bug bounty program and audits now, but still I'm concerned that they didn't notify people which might indicate a cultural problem.
How would Nord handle a problem like this in the future, and can we still trust them?