VPN and cybersecurity services provider Surfshark this week disclosed a cybersecurity incident impacting certain internal data.
The incident, it says, was discovered on August 31, but initially treated as low risk. By September 2, however, the company confirmed the scope and moved to containment and remediation.
An internal test server that became accessible from the internet after being misconfigured was accessed by a threat actor, Surfshark explains in an incident report .
The server contained limited internal engineering material, including “parts of the system binaries and internal configurations for certain services,” Surfshark said.
Surfshark also identified internal, build-related credentials that had been committed to its code history and rotated them, although they did not provide access to user data or production systems serving users.
Additionally, the hackers accessed an isolated content accessibility optimization server (VPS) used as a proxy. However, no encryption keys, user identities, IP addresses, or browser traffic were exposed.
“Based on our investigation, we have confirmed that no user data and VPN services were affected,” the company said.
“The system involved was an internal engineering environment. By design, it does not store or process any user data, and it is kept separate from the production systems that deliver our service,” it added.
The company also pointed out that it does not log or retain VPN traffic and browsing activity and that no application or browser extension running on users’ devices was altered.
In response to the incident, the company contained the affected system and removed the exposure, rotated the relevant internal credentials, implemented additional security measures, and confirmed the full scope of the compromise.
“We will also execute an additional independent security audit to evaluate the security posture of the broader infrastructure environment,” Surfshark said.
Related: 4.1 Million Impacted by AdaptHealth Data Breach
Related: Mathspace Data Breach Exposes Over 1 Million People
Related: Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal
Related: 153 Million Driver License Images Offered on Dark Web
Ionut Arghire is an international correspondent for SecurityWeek.
More from Ionut Arghire
PaperCut Flaws Exploited in AI-Powered Attacks
Critical NetScaler Vulnerability Exploited in Attacks
4.1 Million Impacted by AdaptHealth Data Breach
New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender
Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks
HelmGuard Raises $7.3 Million for Agentic GRC and Security
Android’s September 2026 Updates Patch 180 Vulnerabilities
Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories
Phishing Research Challenges Conventional Security Awareness Testing
GitLab Vulnerability Exploited One Day After Disclosure
In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review
Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack
Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison
Check Point Patches Critical VPN Vulnerabilities
Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance
Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion
Flipboard Whatsapp Whatsapp Email
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
