← BACK TO FEED
TAG

misconfiguration1 article

Surfshark Misconfigured Server Breach: User Data Unaffected, But It's Still Embarrassing

Surfshark disclosed a cybersecurity incident discovered on August 31, in which a misconfigured internal test server was accessed by a threat actor, exposing limited engineering data such as system binaries, internal configurations, and build-related credentials. However, the company confirmed that no user data, VPN services, encryption keys, IP addresses, or browser traffic were compromised, as the affected server was isolated from production systems. In response, Surfshark contained the breach, rotated affected credentials, implemented additional security measures, and announced plans for an independent security audit.

12 Sept 2026