logo

Surfshark VPN says hackers breached internal testing, proxy servers

ID: 1fde587c-e847-5d68-a8aa-d9bec5df7ed6

STIX ID: report--1fde587c-e847-5d68-a8aa-d9bec5df7ed6

Feed Name: Bleeping Computer

Threat Score
30/100

Date Published: 2026-09-10

Date Updated: 2026-09-10

Author: Bill Toulas

...
...

Surfshark disclosed that a misconfigured internal test server was exposed to the internet and accessed by an unauthorized party, revealing service configurations, build-related credentials, portions of system binaries, and code history. The vendor says production VPN infrastructure and customer data were not affected, detected the activity on August 31, contained it on September 2, rotated impacted credentials, revoked tokens, hardened systems, and commissioned an independent audit while finding no evidence of credential misuse or lateral spread.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.