Surfshark VPN says hackers breached internal testing, proxy servers
-
Surfshark has disclosed that hackers gained access to one of its internal test servers after a configuration error left the system exposed to the internet. The VPN provider says the incident was limited to internal testing and proxy servers, not its core VPN infrastructure or customer data.
According to the company, the misconfigured server was reachable from the public internet due to an error in its setup. Once inside, the attackers moved to a proxy server. Surfshark has not released specific details about how long the access lasted or exactly what data, if any, was viewed.
Key points from the disclosure:
- A configuration error exposed an internal test server to the internet.
- Attackers accessed that test server and a proxy server.
- The breach did not affect the core VPN service or customer accounts, per Surfshark.
- No specific CVE ID or advisory number has been provided in the report.
Users and administrators should watch for any follow-up guidance from Surfshark, especially if they operate their own proxy or test infrastructure that might be similarly exposed. As always, keep internal testing environments off the public internet unless absolutely necessary, and audit configurations regularly.
Source: Unknown
Has your organization reviewed whether any internal test or proxy servers are inadvertently exposed to the internet?
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login