People use VPNs for a variety of reasons, but for a lot of people, a VPN is a great option for the security-conscious.
They can protect sensitive data from open Wi-Fi networks, help prevent identity theft, and yes, sure, they’re a great way to circumvent restrictions against viewing certain content and even age assurance checks.
So it can be more than a little alarming if your VPN of choice discloses a cyber security incident, which is exactly what Surfshark did overnight – thankfully, the incident appears to be a relatively benign one, at least for the company’s customers.
“On the 2nd of September we confirmed an unusual activity within one of our internal test servers and immediately began our response,” Surfshark said in a September 9 blog post.
“After identifying that the server has been accessed by an unauthorised party, we contained the incident on the same day. Further remediation was done by 5th September. Based on our investigation, we have confirmed that no user data and VPN services were affected.”
According to Surfshark, the compromised system does not store user data and is separate from the company’s production systems. Nor does the system keep track of or store any VPN traffic.
Surfshark is attributing the unauthorised server access to human error, which led to a misconfiguration of the system that left it accessible via the internet.
“Through that server, limited internal engineering material stored in one of our environments was accessed by an unauthorised third party. It contained parts of the system binaries and internal configurations for certain services. Some internal, build-related credentials had at times been committed to our code history,” Surfshark said.
“Although none of these credentials provided access to user data or to the production systems that serve our users, we reviewed the available access logs; and while no malicious activity was detected, as a precaution, we rotated or retired every secret we identified.”
The unidentified threat actor also gained access to a content accessibility optimisation server’ however, that too was isolated, and merely acted as a proxy.
Ultimately, Surfshark said it had been able to contain the system, rotate any relevant credentials, and that the company had implemented additional security measures. All up, while the incident was detected on August 31, full containment and remediation were completed by September 5.
“We hold ourselves to a high standard, and we believe being open about security is part of earning customer trust,” Surfshark said.
“We remain committed to protecting your privacy and keeping you informed.”
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.