Surfshark Says Hackers Breached Internal Test Server After Configuration Error

VPN provider Surfshark has disclosed that hackers accessed one of its internal engineering test servers after a configuration error left the machine reachable from the public internet. The company said the incident did not affect customers or its production VPN infrastructure.

According to Surfshark, it first detected suspicious activity on the test server on August 31, 2026, contained the affected system by September 2, and completed remediation by September 5, ahead of its public disclosure on September 10. “Due to a human error, an internal test server used by our engineering teams was misconfigured in a way that made it reachable from the internet,” the company said.

A separate proxy server used for content-accessibility optimization was also accessed, Surfshark said, but that machine did not hold sensitive data such as user identity information, IP addresses, encryption keys, or browsing traffic. The exposed environment contained service configurations, build-related credentials, and portions of system binaries and code history.

Surfshark said it reviewed available access logs and found no evidence that exposed credentials were misused, but rotated or replaced all potentially affected secrets as a precaution. The incident underscores a recurring theme in enterprise breaches: internal, non-production environments used for testing and builds are frequently held to lower security standards than customer-facing systems, even though they can hold credentials capable of reaching production infrastructure.

Sources: BleepingComputer, Surfshark.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *