Skip to content
Tech News
← Back to articles

Surfshark VPN says hackers breached internal testing, proxy servers

read original get NordVPN Subscription Card → more articles
Why This Matters

A VPN provider's core promise is that it protects user privacy, so any breach — even of non-production systems — tests that trust. Surfshark says a misconfigured internal test server was exposed to the internet and accessed by an unauthorized party, along with a proxy server, but insists no customer data, keys, or traffic logs were involved. The episode is a reminder that test environments are often the weakest link in otherwise hardened infrastructure.

Key Takeaways
Worth a Look

NordVPN Subscription Card — If this breach has you rethinking who guards your traffic, NordVPN is one of the most widely used alternatives and its subscription cards make setup simple across your phone, laptop, and router. You get encrypted connections on public Wi-Fi and apps for all the major platforms under one account.

See NordVPN Subscription Card on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet.

The VPN service provider said the incident did not affect its customers and did not extend to other parts of its infrastructure, but it exposed service configurations and build-related credentials.

“Due to a human error, an internal test server used by our engineering teams was misconfigured in a way that made it reachable from the internet,” Surfshark explained on its website.

The exposed environment also contained portions of system binaries and code history.

Surfshark said that the unauthorized party accessed a separate server used for content-accessibility optimization. The machine acted as a proxy and did not have access to any sensitive data, like user identity, IP addresses, encryption keys, or browsing traffic.

The company did not specify which specific binaries, configurations, services, credentials, or files were exposed, but confirmed that production VPN infrastructure and customer data were not impacted.

“Personal information was never held and accessible from here [the breached server], VPN traffic and browsing activity are not logged or retained in the first place, and the apps and browser extensions on your devices were not altered in any way,” the VPN vendor assured.

The company detected suspicious activity on August 31 and contained the incident on September 2. Three days later, the company completed the remediation process.

It also said there was no evidence that the exposed credentials had been misused or that the compromise had spread to other systems.

In response to the incident, Surfshark rotated all internal credentials that may have been impacted, revoked the exposed tokens, and implemented additional threat detection, activity monitoring, and system hardening measures.

... continue reading