Particle.news
Download on the App Store

Surfshark Confirms Misconfigured Test Server Was Accessed but Says No User Data Exposed

Rotating exposed secrets and commissioning an independent audit are meant to tighten security for the company's test environments.

Overview

  • Surfshark detected unusual activity in an internal test environment and says an unauthorized party accessed a misconfigured test server that was reachable from the public internet.
  • The company says the breached environment contained limited engineering materials such as parts of system binaries, internal configurations and some build-related credentials, plus an isolated proxy used for content accessibility.
  • Surfshark reports production VPN systems, user identities, IP addresses, encryption keys and browsing traffic were not stored on the exposed servers and were not affected.
  • The firm contained the incident after confirming the scope, completed remediation and rotated or revoked the identified secrets by Saturday, September 5, and found no evidence of credential misuse in its logs.
  • Surfshark has commissioned an independent infrastructure audit, will apply production-level controls to test environments, and advises users no action is required while urging vigilance for suspicious communications.