Surfshark VPN says hackers breached internal testing, proxy servers
Summary
Surfshark VPN has disclosed that hackers gained access to its internal testing environment and proxy servers due to a configuration error. The breach allowed attackers to access some of the company's customer data, including email addresses and subscription information.
IFF Assessment
FOE
The breach of Surfshark's internal systems and customer data represents a negative development for defenders as it highlights potential vulnerabilities in VPN provider infrastructure.
Defender Context
This incident underscores the importance of robust server configuration management and access controls, even for companies that provide security services. Defenders should be aware of the potential for misconfigurations to lead to significant data exposures.