Surfshark confirms breach of internal test and proxy servers, no user data affected
Surfshark disclosed that hackers gained access to an internal engineering test server after a misconfiguration left it exposed to the internet, along with a separate proxy server used for content-accessibility optimization. The company says the exposed systems contained build credentials, code history and system binaries, but no user identities, IP addresses, encryption keys or browsing traffic were compromised. Suspicious activity was spotted on August 31, contained by September 2, and remediation finished three days later.