Surfshark has confirmed it was hacked after human error left an internal test server exposed to the internet. An unauthorized third party accessed the system and obtained limited internal engineering material, although the VPN provider says customer data and its production VPN services were not affected.
The incident began on August 31, when Surfshark’s security monitoring detected suspicious activity in an isolated test environment. The company finished its initial evaluation on September 2, classified the activity as a security incident, and contained the affected server that same day.
According to Surfshark, the server had been misconfigured in a way that made it reachable from the public internet. The unauthorized party was able to access parts of system binaries and internal configurations for certain services.
Perhaps more concerning, Surfshark says some internal build-related credentials had at various times been committed to its code history. The company says none of those credentials provided access to customer data or the production systems used to provide its VPN service.
Surfshark reviewed the available access logs and says it found no malicious activity involving those credentials. As a precaution, however, it rotated or retired every exposed secret it identified.
The attacker also gained access to an isolated content accessibility optimization server that operated as a proxy. Surfshark says that system had no access to user identities, IP addresses, encryption keys, or browsing traffic. Credentials protecting systems containing sensitive information are stored separately in vaults and were not affected, according to the company.
For Surfshark customers, the company says no action is necessary. Its VPN apps and browser extensions were not modified, and the incident did not affect its VPN service. Surfshark also says VPN traffic and browsing activity are not logged or retained in the first place.
Still, the timeline raises some questions. Surfshark first detected suspicious activity on August 31, but the incident wasn’t confirmed and contained until September 2.
The company explains that the alert originated from an isolated testing environment containing no user or sensitive information, so it was initially handled as a lower-risk event rather than under the urgent procedures reserved for systems containing private data.
Surfshark now acknowledges that delay as something it needs to address. The company says it will raise its test and experimental environments to the same security standards applied to production systems.
Planned changes include improving access controls and credential management throughout the build process, strengthening monitoring of testing infrastructure, detecting accidental internet exposure faster, and applying the same security tools and operating system hardening to testing infrastructure.
Surfshark also plans to commission an additional independent security audit to examine its broader infrastructure.
There is no evidence in Surfshark’s disclosure that customer information, VPN traffic, encryption keys, or production infrastructure was compromised. That’s an important detail, especially when dealing with a company whose entire business revolves around privacy and security.
But this was still a hack. An internal server was accidentally exposed, an unauthorized party got inside, engineering material was accessed, and credentials had appeared in code history. Calling it anything less would unnecessarily soften what happened.
The good news for Surfshark customers is that the company says their data was never in danger. The more uncomfortable question is why an internet-facing misconfiguration and credentials in code history were possible in the first place.
Surfshark says it is fixing those problems. Now it needs to make sure the lessons from this incident extend beyond the test server that exposed them.
Support independent tech journalism
NERDS.xyz is independently owned and operated. If you enjoy my coverage of Linux, AI, hardware, cybersecurity, and tech culture, consider supporting the site on Ko-fi.
Support NERDS.xyz