Surfshark Suffers Security Breach on Internal Test Servers
yesterday
10 September, 20:241 min read
As reported by BleepingComputer, VPN service provider Surfshark has disclosed a security incident. According to the company, hackers were able to access internal test servers due to a configuration error. The server was left exposed on the internet due to incorrect settings, which provided an entry point for the attackers.
What actually happened?
The incident affected only a portion of the internal infrastructure used by the company for testing purposes. Surfshark representatives stated that while hackers gained access to specific proxy servers, the company emphasises that user personal data, activity logs, or accounts were not compromised. The core VPN infrastructure and user databases remain secure.
The company's response
Once the security flaw was identified, Surfshark immediately took measures to secure the servers and restricted the unauthorised access. The company states that it will further tighten its security protocols to prevent similar incidents in the future. Although user data was not put at risk, this case serves as another reminder to technology companies of how critical the correct configuration of internal systems is.
For users in Georgia who utilise Surfshark, this incident does not pose a direct threat; however, such news is always a good reminder to strengthen account security. Experts advise users to regularly update their software and use two-factor authentication (2FA) for all services where it is available.