Find notable cyber news and cases, enriched with sources, timelines, and signals.

Surfshark hit by cyberattack

Incident
First reported
Last updated
Happening score
H score 10
1 unique sources, 1 articles

Summary

Hide ▲

Surfshark confirmed a breach of internal systems after a configuration error exposed an internal test server to the internet, creating risk for its engineering environment even though customer data was not impacted. The exposure also reached a separate proxy server used for content-accessibility optimization, and the accessed environment held service configurations and build-related credentials. The company detected suspicious activity on August 31, contained it on September 2, and finished remediation three days later.

Timeline

  1. 10.09.2026 22:15 1 articles · 3h ago

    Surfshark detects suspicious activity on an exposed test server

    Detection Ioc Update

    Surfshark said it detected suspicious activity after a configuration error made an internal test server reachable from the internet. The activity was tied to unauthorized access involving the engineering test environment and a separate proxy server used for content-accessibility optimization.

    Show sources
  2. 10.09.2026 22:15 1 articles · 3h ago

    Surfshark contains unauthorized access to internal test and proxy servers

    Mitigation Patch Update

    Surfshark said it contained the incident on September 2 after suspicious activity was detected, and reported no evidence that the exposed credentials were misused or that the compromise spread to other systems.

    Show sources
  3. 10.09.2026 22:15 1 articles · 3h ago

    Surfshark completes remediation and rotates internal credentials

    Mitigation Patch Update

    Three days after containment, Surfshark said it completed remediation, rotated internal credentials that may have been impacted, revoked the exposed tokens, and implemented additional threat detection, activity monitoring, and system hardening measures.

    Show sources
  4. 10.09.2026 22:15 2 articles · 3h ago

    Surfshark discloses exposure of internal test and proxy servers

    Initial Disclosure

    Surfshark disclosed that a configuration error made an internal test server used by engineering teams reachable from the internet and that an unauthorized party also accessed a separate server used for content-accessibility optimization. The exposed environment contained service configurations, build-related credentials, some system binaries, and code history, while production VPN infrastructure and customer data were not impacted.

    Show sources