ZeroHour
SecurityWeekpublished ()ingested Ionut Arghire
Part of a story covered by 2 sources: “Surfshark VPN says hackers accessed misconfigured internal test and proxy servers; no customer data affected” — merged summary and timeline →

Surfshark Systems Targeted by Hackers

mediumData breach exploited in the wildimportance 48
AI summary · glm-5.3-flash

Surfshark discloses hackers accessed a misconfigured internal test server; no user data or VPN services affected.

Surfshark discovered on August 31 that a threat actor accessed an internal test server exposed to the internet through misconfiguration, obtaining some system binaries and internal configurations. Build-related credentials committed to code history were rotated, and an isolated content optimization VPS was also accessed, though no user data, encryption keys, or browsing activity were exposed. The company contained the system, rotated credentials, and announced an independent security audit.

  • Misconfigured internal test server was internet-accessible and breached
  • Exposed data included system binaries and internal service configurations
  • Build credentials were rotated; did not grant access to user data
  • Isolated content accessibility optimization VPS also accessed by attacker
  • Independent security audit of broader infrastructure planned
VendorsSurfshark
VictimsSurfshark
OrganizationsSurfshark
Full article333 words · extracted from securityweek.com · click to collapse

VPN and cybersecurity services provider Surfshark this week disclosed a cybersecurity incident impacting certain internal data.

The incident, it says, was discovered on August 31, but initially treated as low risk. By September 2, however, the company confirmed the scope and moved to containment and remediation.

An internal test server that became accessible from the internet after being misconfigured was accessed by a threat actor, Surfshark explains in an incident report.

The server contained limited internal engineering material, including “parts of the system binaries and internal configurations for certain services,” Surfshark said.

Surfshark also identified internal, build-related credentials that had been committed to its code history and rotated them, although they did not provide access to user data or production systems serving users.

Additionally, the hackers accessed an isolated content accessibility optimization server (VPS) used as a proxy. However, no encryption keys, user identities, IP addresses, or browser traffic were exposed.

Advertisement. Scroll to continue reading.

“Based on our investigation, we have confirmed that no user data and VPN services were affected,” the company said.

“The system involved was an internal engineering environment. By design, it does not store or process any user data, and it is kept separate from the production systems that deliver our service,” it added.

The company also pointed out that it does not log or retain VPN traffic and browsing activity and that no application or browser extension running on users’ devices was altered.

In response to the incident, the company contained the affected system and removed the exposure, rotated the relevant internal credentials, implemented additional security measures, and confirmed the full scope of the compromise.

“We will also execute an additional independent security audit to evaluate the security posture of the broader infrastructure environment,” Surfshark said.

Related: 4.1 Million Impacted by AdaptHealth Data Breach

Related: Mathspace Data Breach Exposes Over 1 Million People

Related: Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal

Related: 153 Million Driver License Images Offered on Dark Web

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/surfshark-systems-targeted-by-hackers/