Surfshark has disclosed a data breach involving an internally used test environment that was mistakenly exposed to the internet, allowing an unauthorised party to access server configurations and build-related credentials.
The VPN provider said the incident was contained within its testing infrastructure and did not affect customers, its production VPN systems or personal data.
The exposed environment included a server used by Surfshark’s engineering teams, along with portions of system binaries and code history. A separate machine used to optimise access to online content was also accessed and operated as a proxy.
Surfshark said the proxy server did not contain sensitive customer information such as identities, IP addresses, encryption keys or browsing activity. It added that VPN traffic is not logged or retained, and said its apps and browser extensions had not been altered.
“Due to a human error, an internal test server used by our engineering teams was misconfigured in a way that made it reachable from the internet,” the company said.
Surfshark has not specified which binaries, files, service configurations or credentials were exposed. However, it said there was no evidence that any compromised credentials had been used or that the intrusion had spread to other systems.
The company detected suspicious activity on 31 August and contained the incident by 2 September. Remediation work was completed three days later, it said.
Surfshark says customer data was not exposed
In response, Surfshark rotated internal credentials that may have been affected and revoked exposed access tokens. It has also introduced additional threat detection, activity monitoring and hardening measures.
The provider said its test environments would now be subject to security controls used in production systems. It is also reviewing how credentials are managed during the build process and has commissioned an independent audit of its wider infrastructure.
Surfshark said users do not need to take any action as a result of the incident. It nevertheless advised customers to remain alert to suspicious activity or unsolicited messages while its investigation continues.
The company said it would issue further updates if the investigation identifies any additional significant findings.
