Surfshark reported that one of its internal test servers was breached by hackers. The incident occurred because a human error led to the server being misconfigured, making it accessible from the internet. This exposed service configurations, build-related credentials, portions of system binaries, and code history.
In addition to the test server, an unauthorized party also accessed a separate server used for content-accessibility optimization, which functioned as a proxy. Surfshark confirmed that this proxy server did not store sensitive data such as user identity, IP addresses, encryption keys, or browsing traffic. The company emphasized that production VPN infrastructure and customer data remained unaffected.
Surfshark detected suspicious activity on August 31 and contained the incident by September 2. The remediation process was completed three days later. The company found no evidence that the exposed credentials were misused or that the compromise spread to other systems.
Following the breach, Surfshark rotated all potentially impacted internal credentials and revoked exposed tokens. The company also implemented additional threat detection, activity monitoring, and system hardening measures. These include applying production-level security controls to test environments, improving build-process credential management, and commissioning an independent audit of its broader infrastructure. Surfshark stated that users do not need to take any action to protect their accounts.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Surfshark disclosed that hackers accessed an internal test server and a separate proxy server after a configuration error exposed them to the internet. The company stated that no customer data or production VPN infrastructure was impacted, and users do not need to take action.