ZeroHour
BleepingComputerpublished ()ingested Bill Toulas
Part of a story covered by 2 sources: “Surfshark VPN says hackers accessed misconfigured internal test and proxy servers; no customer data affected” — merged summary and timeline →

Surfshark VPN says hackers breached internal testing, proxy servers

mediumData breach exploited in the wildimportance 42
AI summary · glm-5.3-flash

Surfshark disclosed that hackers accessed misconfigured internal test and proxy servers, exposing build credentials but not customer data, VPN traffic, or production infrastructure.

Surfshark said a human error left an internal engineering test server reachable from the internet, exposing service configurations, build-related credentials, and portions of system binaries and code history. A separate proxy server used for content-accessibility optimization was also accessed, but it stored no user identity data, IP addresses, encryption keys, or browsing traffic. Suspicious activity was detected on August 31, contained on September 2, and remediation completed on September 5, with no evidence of credential misuse or spread to other systems. The company rotated impacted credentials, revoked exposed tokens, added monitoring and hardening, and commissioned an independent infrastructure audit; no customer action is required.

  • Misconfigured internal test server was internet-reachable, exposing service configurations and build-related credentials
  • Separate proxy server for content-accessibility optimization was also accessed but held no sensitive data
  • Suspicious activity detected August 31; contained September 2; remediation completed September 5
  • Surfshark rotated impacted credentials, revoked tokens, and commissioned an independent infrastructure audit
  • No evidence credentials were misused; customers need not take any action
VendorsSurfshark
VictimsSurfshark
OrganizationsSurfshark
Full article395 words · extracted from bleepingcomputer.com · click to collapse

Surfshark VPN says hackers breached internal testing, proxy servers

Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet.

The VPN service provider said the incident did not affect its customers and did not extend to other parts of its infrastructure, but it exposed service configurations and build-related credentials.

“Due to a human error, an internal test server used by our engineering teams was misconfigured in a way that made it reachable from the internet,” Surfshark explained on its website.

The exposed environment also contained portions of system binaries and code history.

Surfshark said that the unauthorized party accessed a separate server used for content-accessibility optimization. The machine acted as a proxy and did not have access to any sensitive data, like user identity, IP addresses, encryption keys, or browsing traffic.

The company did not specify which specific binaries, configurations, services, credentials, or files were exposed, but confirmed that production VPN infrastructure and customer data were not impacted.

“Personal information was never held and accessible from here [the breached server], VPN traffic and browsing activity are not logged or retained in the first place, and the apps and browser extensions on your devices were not altered in any way,” the VPN vendor assured.

The company detected suspicious activity on August 31 and contained the incident on September 2. Three days later, the company completed the remediation process.

It also said there was no evidence that the exposed credentials had been misused or that the compromise had spread to other systems.

In response to the incident, Surfshark rotated all internal credentials that may have been impacted, revoked the exposed tokens, and implemented additional threat detection, activity monitoring, and system hardening measures.

These measures include implementing production-level security controls to test environments, improving build-process credential management, and commissioning an independent audit of its broader infrastructure.

Surfshark promised to provide further updates if the ongoing investigation reveals additional important findings.

Based on the published information, Surfshark users do not need to take any action to protect their accounts. However, vigilance against suspicious activity or unsolicited communications is still recommended.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.bleepingcomputer.com/news/security/surfshark-vpn-says-hackers-breached-internal-testing-proxy-servers/