Surfshark VPN says hackers breached internal testing, proxy servers
by Bill Toulas · BleepingComputerSurfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet.
The VPN service provider said the incident did not affect its customers and did not extend to other parts of its infrastructure, but it exposed service configurations and build-related credentials.
“Due to a human error, an internal test server used by our engineering teams was misconfigured in a way that made it reachable from the internet,” Surfshark explained on its website.
The exposed environment also contained portions of system binaries and code history.
Surfshark said that the unauthorized party accessed a separate server used for content-accessibility optimization. The machine acted as a proxy and did not have access to any sensitive data, like user identity, IP addresses, encryption keys, or browsing traffic.
The company did not specify which specific binaries, configurations, services, credentials, or files were exposed, but confirmed that production VPN infrastructure and customer data were not impacted.
“Personal information was never held and accessible from here [the breached server], VPN traffic and browsing activity are not logged or retained in the first place, and the apps and browser extensions on your devices were not altered in any way,” the VPN vendor assured.
The company detected suspicious activity on August 31 and contained the incident on September 2. Three days later, the company completed the remediation process.
It also said there was no evidence that the exposed credentials had been misused or that the compromise had spread to other systems.
In response to the incident, Surfshark rotated all internal credentials that may have been impacted, revoked the exposed tokens, and implemented additional threat detection, activity monitoring, and system hardening measures.
These measures include implementing production-level security controls to test environments, improving build-process credential management, and commissioning an independent audit of its broader infrastructure.
Surfshark promised to provide further updates if the ongoing investigation reveals additional important findings.
Based on the published information, Surfshark users do not need to take any action to protect their accounts. However, vigilance against suspicious activity or unsolicited communications is still recommended.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.