Hackers Accessed Misconfigured Surfshark Test Server

A misconfigured Surfshark test server and an isolated proxy were accessed; exposed build credentials were rotated and the firm reports no user data or VPN services were affected.

Surfshark reported that a threat actor accessed an internal test server that had been unintentionally reachable from the internet and an isolated virtual private server used as a proxy. The company discovered the activity on August 31 and confirmed the full scope on September 2, after which it moved to contain and remediate the exposure.

The affected test server held limited engineering material, including parts of system binaries and internal configuration files. Investigators also found build-related credentials that had been committed to the company’s code history. Those credentials were rotated after discovery, and Surfshark confirmed they did not provide access to user data or to production systems that deliver its VPN service. Centralized secrets management reduces the risk of build credentials remaining exposed in source-code history and makes rapid rotation easier after an incident.

Surfshark reported that no encryption keys, user identities, IP addresses or browser traffic were exposed. The firm described the compromised systems as internal engineering environments that do not store or process user data and are kept separate from production infrastructure. Surfshark also reiterated its policy of not logging or retaining VPN traffic or browsing activity and said no application or browser extension on users’ devices was altered.

After confirming the incident scope on September 2, the company contained the affected systems, removed the external exposure and rotated the relevant credentials. Additional security controls were implemented and Surfshark plans an independent security audit of its broader infrastructure.

“Based on our investigation, we have confirmed that no user data and VPN services were affected,” the firm wrote in its incident report.

Surfshark did not report any ransom demands and has not provided a timeline for how long the server was exposed before discovery. The company initially treated the event as low risk on August 31 and escalated containment once the full impact was understood two days later.

Articles by this author