
Surfshark has disclosed a security incident in which an improperly configured internal test server was exposed to the internet and accessed by an unauthorized third party.
The VPN provider says the breach did not affect customer data, VPN traffic, production systems, apps, or browser extensions.
According to an incident report published on September 9, Surfshark first detected suspicious activity on August 31 through its security monitoring systems. Because the alert originated from an isolated test environment that did not contain user or sensitive data, it was initially treated as a lower-risk event.
The company confirmed unauthorized access on September 2 and contained the affected server the same day. Surfshark said the exposure resulted from human error that left an internal engineering server reachable from the public internet.
Through the server, the intruder accessed limited engineering material, including parts of system binaries and internal configurations for certain services. Surfshark also found that some build-related credentials had previously been committed to its code history.
The company said none of those credentials provided access to customer data or production infrastructure. Although its review of available logs found no evidence that the credentials had been abused, Surfshark rotated or retired every potentially affected secret as a precaution.
Surfshark operates a consumer VPN service that routes internet traffic through encrypted connections and reduces exposure of users' real IP addresses. The company says its production systems are segregated from internal testing environments and that it does not log or retain VPN traffic or browsing activity.
The unauthorized party also accessed an isolated virtual private server used for content accessibility optimization. Surfshark said the VPS functioned as a proxy and had no access to user identities, IP addresses, browsing traffic, or encryption keys. Credentials protecting sensitive systems were stored separately in dedicated vaults.
As part of its response, Surfshark took snapshots and backups of the affected system, disconnected external access, inspected other servers in the same subnet for backdoors, and revoked or rotated potentially exposed secrets. Additional remediation and infrastructure hardening continued through September 5.
Surfshark said it found no evidence that the compromise spread to other systems.
Following the incident, the company plans to apply production-level security standards to test and experimental infrastructure, strengthen credential management during software builds, improve monitoring for unintended internet exposure, and deploy the same operating-system and service-hardening measures used in production.
Surfshark also plans to commission an independent security audit of its broader infrastructure.
As the company says no customer systems or data were affected, users do not need to change passwords, reinstall applications, or take other action in response to the incident. However, users should remain vigilant for suspicious account activity.







Leave a Reply