Surfshark Systems Targeted by Hackers, User Data and VPN Services Left Unscathed
Cybersecurity services provider Surfshark recently disclosed a security incident that exposed certain internal data, but reassuringly, no user data or VPN services were affected. The incident occurred when an internal test server became accessible from the internet after being misconfigured, allowing a threat actor to access it.
According to an incident report released by Surfshark, the compromised server contained limited internal engineering material, including parts of system binaries and internal configurations for certain services. Additionally, internal build-related credentials that had been committed to its code history were accessed, but these did not provide access to user data or production systems serving users. The hackers also gained access to an isolated content accessibility optimization server (VPS) used as a proxy, although no encryption keys, user identities, IP addresses, or browser traffic were exposed.
It’s worth noting that the system involved in the incident was an internal engineering environment designed to keep user data and production systems separate. By design, it does not store or process any user data, making it a low-risk zone for such incidents. Surfshark also pointed out that it does not log or retain VPN traffic and browsing activity, further emphasizing the robustness of its security measures.
In response to the incident, Surfshark took swift action to contain the affected system and remove the exposure. The company rotated relevant internal credentials, implemented additional security measures, and conducted a thorough investigation to confirm the full scope of the compromise. Moreover, an independent security audit will be executed to evaluate the broader infrastructure environment’s security posture.
This incident serves as a reminder that even with robust security measures in place, misconfigurations can still occur, allowing attackers to gain unauthorized access. It highlights the importance of continuous monitoring and auditing to identify potential vulnerabilities before they are exploited. As Surfshark has demonstrated, swift action and transparency can help mitigate the impact of such incidents.
In conclusion, while the incident is a cause for concern, it’s reassuring that no user data or VPN services were affected. This incident serves as a reminder to organizations to regularly review their security posture and take proactive measures to prevent similar incidents from occurring in the future.
Source: SecurityWeek — 2026-09-11