Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet.
The VPN service provider said the incident did not affect its customers and did not extend to other parts of its infrastructure, but it exposed service configurations and build-related credentials.
“Due to a human error, an internal test server used by our engineering teams was misconfigured in a way that made it reachable from the internet,” Surfshark explained on its website.
The exposed environment also contained portions of system binaries and code history.
Surfshark said that the unauthorized party accessed a separate server used for content-accessibility optimization. The machine acted as a proxy and did not have access to any sensitive data, like user identity, IP addresses, encryption keys, or browsing traffic.
The company did not specify which specific binaries, configurations, services, credentials, or files were exposed, but confirmed that production VPN infrastructure and customer data were not impacted.
“Personal information was never held and accessible from here [the breached server], VPN traffic and browsing activity are not logged or retained in the first place, and the apps and browser extensions on your devices were not altered in any way,” the VPN vendor assured.
The company detected suspicious activity on August 31 and contained the incident on September 2. Three days later, the company completed the remediation process.
It also said there was no evidence that the exposed credentials had been misused or that the compromise had spread to other systems.
In response to the incident, Surfshark rotated all internal credentials that may have been impacted, revoked the exposed tokens, and implemented additional threat detection, activity monitoring, and system hardening measures.
... continue reading