Surfshark confirmed a security incident after an unauthorized party gained access to one of the company's internal engineering test servers.
According to Surfshark, the server had been misconfigured and made reachable from the Internet. The intruder accessed limited internal engineering material, including portions of system binaries and internal service configurations. Some build-related credentials had also previously been committed to code history. Surfshark
Surfshark says the affected environment was isolated from its production infrastructure and did not contain customer data. The company also says VPN traffic, browsing activity, IP addresses and encryption keys were not exposed. Potentially affected secrets were revoked or rotated as a precaution. Surfshark
The incident was identified August 31, confirmed and contained September 2, and remediation continued through September 5.
So while searches for “Surfshark breach” make it sound like customer VPN data was compromised, the company's disclosed incident was an intrusion into an improperly exposed internal test environment, not a confirmed breach of customer VPN data.
According to Surfshark, the server had been misconfigured and made reachable from the Internet. The intruder accessed limited internal engineering material, including portions of system binaries and internal service configurations. Some build-related credentials had also previously been committed to code history. Surfshark
Surfshark says the affected environment was isolated from its production infrastructure and did not contain customer data. The company also says VPN traffic, browsing activity, IP addresses and encryption keys were not exposed. Potentially affected secrets were revoked or rotated as a precaution. Surfshark
The incident was identified August 31, confirmed and contained September 2, and remediation continued through September 5.
So while searches for “Surfshark breach” make it sound like customer VPN data was compromised, the company's disclosed incident was an intrusion into an improperly exposed internal test environment, not a confirmed breach of customer VPN data.