Surfshark VPN says hackers breached internal testing, proxy servers

Surfshark VPN says hackers breached internal testing, proxy servers
Surfshark said a misconfigured internal test server was exposed to the internet, allowing unauthorized access to build-related credentials, service configurations, and some system binaries without affecting customer data or production VPN infrastructure. The company contained and remediated the incident, rotated credentials, and said there is no evidence of misuse or broader compromise. #Surfshark

Keypoints

  • A Surfshark internal test server was exposed because of a configuration error.
  • Unauthorized access was limited to a non-production environment.
  • The exposure included service configurations, build credentials, and portions of code history.
  • Surfshark said customer data, VPN traffic, and production systems were not affected.
  • The company rotated credentials, revoked tokens, and added stronger security controls.

Read More: https://www.bleepingcomputer.com/news/security/surfshark-vpn-says-hackers-breached-internal-testing-proxy-servers/