Surfshark has confirmed that hackers accessed one of its internal test servers after a configuration mistake accidentally exposed the system to the internet.

The VPN provider said the incident did not affect customer data or its production VPN infrastructure. However, the compromised environment contained parts of system binaries, internal configurations and some build-related credentials.

Surfshark said the affected server was used by its engineering teams for testing. A human error left the server reachable from the internet, allowing an unauthorized party to gain access to limited internal engineering material.

The compromised environment did not store or process customer information. Surfshark also said it does not log or retain VPN traffic and browsing activity, and that its apps and browser extensions were not affected.

The company also discovered that an isolated server used for content accessibility optimization had been accessed. That machine operated as a proxy and did not have access to user identities, IP addresses, encryption keys or browsing traffic.

Some internal credentials had previously been included in the company’s code history. Surfshark said it reviewed the available access logs and found no evidence that the exposed credentials had been misused. As a precaution, however, it rotated or retired all potentially affected secrets.

Surfshark first detected suspicious activity on August 31. The company confirmed the security incident and contained the affected server by September 2, before completing further remediation by September 5.

READ
Thomson Reuters Discloses C-Track Data Breach Affecting U.S. and Canadian Courts

The company said there was also no evidence that the attackers moved from the compromised environment into other systems.

Following the incident, Surfshark removed the exposure, investigated its broader infrastructure, revoked potentially exposed tokens and introduced additional monitoring and security controls.

The company is also raising the security standards of its testing environments to match those used in production systems. It plans to improve credential management, strengthen monitoring of test infrastructure and conduct an additional independent security audit.


Buy ExpressVPN with PayPal or Credit Card

For Surfshark users, the company says no action is required. Based on its investigation so far, customer information and VPN services were not affected.

Advertisement