Even organisations specialising in digital protection are not immune to security incidents. The experience of Surfshark, a well-known VPN and cybersecurity services provider, illustrates this.
The company detected suspicious activity in one of its test environments on 31 August. It was initially treated as low risk because the environment held no sensitive information. On 2 September, Surfshark confirmed that it was a security incident and moved to contain it, according to a report published by the company. The subsequent recovery work continued until 5 September.
An unauthorised third party accessed an internal test server that had been misconfigured due to human error and left exposed to the internet.
The server contained a limited amount of internal engineering material, including parts of system binaries and internal configurations for certain services.
“Following our investigation, we have confirmed that neither user data nor VPN services were affected,” the company said.
“The system in question was an internal engineering environment. By design, it does not store or process any user data and is kept separate from the production systems that deliver our service,” it added.
Surfshark says that, in addition to containing the affected system and removing its exposure to the internet, it rotated the relevant internal credentials and implemented additional security measures to strengthen the detection, monitoring and protection of its systems and infrastructure.
The company will also commission an additional independent security audit to “assess the security posture of the broader infrastructure environment”.
The server was not the only weak point
During the investigation, the cybersecurity company found that some internal build-related credentials had at times been committed to the code history. As a precaution, Surfshark immediately rotated or retired every credential it identified, stressing that none provided access to user data or the production systems used to deliver the service.
The unauthorised access also reached an isolated server used to optimise content accessibility that acted as a proxy. According to Surfshark, the system had no access to user identities, IP addresses, encryption keys or browsing traffic, meaning the incident did not affect user privacy or security. Credentials protecting systems that contain sensitive data are stored separately in vaults and were also unaffected.
