Surfshark disclosed that attackers accessed an internal test server that had been accidentally exposed to the internet through a configuration error. The exposed environment contained service configurations, software-build credentials, system binaries, portions of a source-code repository, and access to a separate content-access optimization proxy server. Suspicious activity was detected on August 31; Surfshark contained the incident on September 2 and completed primary remediation three days later.
The company said it found no evidence that the exposed credentials were used or that the attackers laterally moved into its internal infrastructure, production environment, or customer systems. Surfshark rotated potentially affected internal credentials, revoked compromised tokens, and increased monitoring; it also plans to extend production-grade protections to test systems, revise build-credential management, and commission an independent infrastructure audit.

Map this exposure pattern across your cloud, code, and identities.
5 events from the most recent confirmed update back to the earliest known activity.
Three days after containment, Surfshark completed its main remediation work, including rotating potentially exposed internal credentials, revoking compromised tokens, and increasing monitoring and threat detection.
Surfshark contained the incident after detecting the unauthorized activity on its exposed test environment.
Surfshark detected suspicious activity associated with the unauthorized access and began investigating the incident.
Following the intrusion, Surfshark said it plans to conduct an additional independent security audit of its broader infrastructure environment.
A configuration error exposed an internal Surfshark engineering test server to the internet, allowing attackers to access service configurations, software-build credentials, some binaries, and source-code repository fragments. The attackers also accessed a separate content-access optimization proxy server, which Surfshark said held no user data, IP addresses, encryption keys, or traffic information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
4 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcexakep.ru
Open sourcecyberveille.ch
Open sourcesurfshark.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.