Cybersecurity
Surfshark detects unauthorised access to one of its internal servers
A configuration error left the server exposed to the internet, although the company says neither user data nor its VPN services were affected.
- Lenovo ID flaw enabled unauthorised access to around 5,000 Dropbox accounts
- Metabase hacked in major breach affecting more than 100,000 companies
- 1
The Falklands, Ceuta and proxy warfare: Is the United States using third parties to pressure its allies?
- 2
Hundreds of millions of driving licences surface on the dark web as IDScan confirms security breach
- 3
Extortion emerges as Mexico’s biggest economic threat, survey finds
- 4
E. Nieva (Check Point): “Employees are entering source code, trade secrets and financial data into AI tools”
- 5
A growing number of Google Play apps promise cash but block users just before payout
- Alberto Payo
- Technology Journalist
- Published on
14 September 2026 at 07:15
Even organisations specialising in digital protection are not immune to security incidents. The experience of Surfshark, a well-knownVPN and cybersecurity services provider, illustrates this.
The company detected suspicious activity in one of its test environments on 31 August. It was initially treated as low risk because the environment held no sensitive information. On 2 September, Surfshark confirmed that it was a security incident and moved to contain it, according to a report published by the company. The subsequent recovery work continued until 5 September.
An unauthorised third party accessed an internal test server that had been misconfigured due to human error and left exposed to the internet.
The server contained a limited amount of internal engineering material, including parts of system binaries and internal configurations for certain services.
“Following our investigation, we have confirmed that neither user data nor VPN services were affected,” the company said.
“The system in question was an internal engineering environment. By design, it does not store or process any user data and is kept separate from the production systems that deliver our service,”it added.
Surfshark says that, in addition to containing the affected system and removing its exposure to the internet, it rotated the relevant internal credentials and implemented additional security measures to strengthen the detection, monitoring and protection of its systems and infrastructure.
The company will also commission an additional independent security audit to “assess the security posture of the broader infrastructure environment”.
The server was not the only weak point
During the investigation, the cybersecurity company found that some internal build-related credentials had at times been committed to the code history.As a precaution, Surfshark immediately rotated or retired every credential it identified, stressing thatnone provided access to user data or the production systemsused to deliver the service.
The unauthorised access also reached an isolated server used to optimise content accessibility that acted as a proxy.According to Surfshark, the system had no access to user identities, IP addresses, encryption keys or browsing traffic, meaning the incident did not affect user privacy or security. Credentials protecting systems that contain sensitive data are stored separately in vaults and were also unaffected.
Become a premium member for free!
You may be interested in
- CybersecurityLenovo ID flaw enabled unauthorised access to around 5,000 Dropbox accountsAlberto Payo
- CybersecurityMetabase hacked in major breach affecting more than 100,000 companiesAlberto Payo
- CybersecurityItalian hacktivist collective Autistici/Inventati shuts down after US terrorist designationAlberto Payo
- CybersecurityAI-powered fake fashion stores offering deep discounts are on the riseSergio Delgado Martorell
“;
$(“#container-comentar-comentarios”).html(respuesta);
} else if (data == 2) { //TIEMPO
var respuesta =
“No ha pasado aún un minuto desde tu último comentario. Espera un poco y podrás comentar de nuevo una noticia.
“;
$(“#container-comentar-comentarios”).html(respuesta);
} else if (data == 3) { //PALABROTA
var respuesta = “Por favor, utiliza un lenguaje correcto para comentar las noticias.”;
Swal.fire({
text: respuesta,
icon: “warning”
});
} else { //NO LOGUEADO
var respuesta =
“Lo sentimos, al parecer no tienes una sesión iniciada. Vuelve a Iniciar Sesión y podrás publicar este comentario.”;
Swal.fire({
text: respuesta,
icon: “warning”
});
}
},
error: function(request, error) {
//console.log(error);
}
});
}
function sumarPositivo(id_comentario, id_usuario) {
$.ajax({
type: “POST”,
xhrFields: {
withCredentials: true
},
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/sumar_reaccion_comentario.php?t=` +
generarCadenaAlfanumerica(),
data: {
tipo: ‘positivo’,
id_comentario: id_comentario,
id_usuario: id_usuario
},
success: function(data) {
//console.log(data);
if (data == 1) {
var likes = parseInt($(“#like_” + id_comentario + ” span”).text());
$(“#like_” + id_comentario + ” span”).text(parseInt(likes + 1));
}
},
error: function(request, error) {
//console.log(error);
}
});
}
function sumarNegativo(id_comentario, id_usuario) {
$.ajax({
type: “POST”,
xhrFields: {
withCredentials: true
},
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/sumar_reaccion_comentario.php?t=` +
generarCadenaAlfanumerica(),
data: {
tipo: ‘negativo’,
id_comentario: id_comentario,
id_usuario: id_usuario
},
success: function(data) {
//console.log(data);
if (data == 1) {
var dislikes = parseInt($(“#dislike_” + id_comentario + ” span”).text());
$(“#dislike_” + id_comentario + ” span”).text(parseInt(dislikes + 1));
}
},
error: function(request, error) {
//console.log(error);
}
});
}
function recargar_widgets_sesion() {
recargar_cabecero_sesion();
recargar_menu_sesion();
recargar_comentar_sesion();
recargar_comentar_comentar();
comprobar_user_sesion_215_articulo(0);
}
function iniciarSesion() {
var continuar = true;
var msg = “”;
var usuario_log = $(“#usuario_log”).val();
var password_log = $(“#password_log”).val();
var valor_periodico = $(‘#valor_periodico’).val();
// console.log(valor_periodico);
if (usuario_log.length == 0) {
continuar = false;
msg += “Es necesario rellenar el correo electrónico n”;
}
if (password_log.length == 0) {
continuar = false;
msg += “Es necesario rellenar la contraseña.n”;
}
if (continuar) {
$.ajax({
type: “POST”,
data: $(“#formulario_login”).serialize(),
xhrFields: {
withCredentials: true
},
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/login-user.php?t=` +
generarCadenaAlfanumerica(),
success: function(data) {
// console.log(data);
if (data == 1) {
recargar_widgets_sesion();
$(“#modal-login .modal-action.modal-close.close-btn”).trigger(“click”);
$(“#usuario_log”).val(“”);
$(“#password_log”).val(“”);
if (window.location.href.includes(“area-usuario”)) {
// window.location.reload();
}
} else {
var respuesta =
“No hemos encontrado ningún usuario con el correo electrónico y la contraseña introducidos. Por favor, vuelve a intentarlo o recupera la contraseña pulsando el botón inferior.”;
Swal.fire({
text: respuesta,
icon: “warning”
});
}
}
});
} else {
Swal.fire({
text: msg,
icon: “warning”
});
}
}
function comprobar_user_sesion_215_articulo(es_premium) {
$.ajax({
type: “POST”,
xhrFields: {
withCredentials: true
},
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/comprobar_sesion_user.php?t=` +
generarCadenaAlfanumerica(),
success: function(data) {
console.log(“COMPROBADO SESION USUARIO ” + data);
if (data == 1) {
$(“#art-cuerpo-visible”).removeClass(“d-none”);
$(“#art-cuerpo-visible”).removeClass(“art-cuerpo-no-visible”);
$(“#art-cuerpo-visible”).addClass(“art-cuerpo-visible”);
$(“#art-cuerpo-visible-premium”).removeClass(“art-cuerpo-visible”);
$(“#art-cuerpo-visible-premium”).addClass(“d-none”);
$(“#banner-premium”).addClass(“d-none”);
} else {
// $(“#art-cuerpo-visible”).removeClass(“art-cuerpo-visible”);
// $(“#art-cuerpo-visible”).addClass(“art-cuerpo-no-visible”);
if (es_premium) {
$(“#art-cuerpo-visible”).removeClass(“d-none”);
$(“#art-cuerpo-visible”).removeClass(“art-cuerpo-no-visible”);
$(“#art-cuerpo-visible”).addClass(“d-none”);
$(“#art-cuerpo-visible-premium”).addClass(“art-cuerpo-visible”);
$(“#art-cuerpo-visible-premium”).removeClass(“d-none”);
$(“#banner-premium”).removeClass(“d-none”);
} else {
$(“#art-cuerpo-visible-premium”).removeClass(“art-cuerpo-visible”);
$(“#art-cuerpo-visible-premium”).addClass(“d-none”);
$(“#banner-premium”).addClass(“d-none”);
$(“#art-cuerpo-visible”).removeClass(“d-none”);
$(“#art-cuerpo-visible”).removeClass(“art-cuerpo-no-visible”);
$(“#art-cuerpo-visible”).addClass(“art-cuerpo-visible”);
}
}
}
});
}
function comprobar_user_sesion_215() {
$.ajax({
type: “POST”,
xhrFields: {
withCredentials: true
},
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/comprobar_sesion_user.php?t=` +
generarCadenaAlfanumerica(),
success: function(data) {
console.log(“COMPROBADO SESION USUARIO ” + data);
if (data == 1) {
$(‘.col-comparador-registro-login’).addClass(‘w-auto’)
} else {
$(‘.col-comparador-registro-login’).removeClass(‘w-auto’)
}
}
});
}
function cerrarSesion() {
$.ajax({
type: “POST”,
xhrFields: {
withCredentials: true
},
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/delete-session-user.php?t=` +
generarCadenaAlfanumerica(),
success: function(data) {
//console.log(data);
recargar_widgets_sesion();
$(“#offCanvasClose”).trigger(“click”);
if (window.location.href.includes(“area-usuario”)) {
window.location.href = ‘/’;
}
}
});
}
function registrarCuenta() {
var continuar = true;
var msg = “”;
var email_registro = $(“#email_reg”).val();
var pass_registro = $(“#password_reg”).val();
var pass_registro2 = $(“#password_reg_2”).val();
var nombre_registro = $(“#nombre_reg”).val();
var apellidos_registro = $(“#apellidos_reg”).val();
var ref_id_periodico = $(“#ref_id_periodico”).val();
if (pass_registro2 != pass_registro) {
continuar = false;
msg += “Deben coincidir ambas contraseñas. n”;
}
if (email_registro.length == 0) {
continuar = false;
msg += “Es necesario rellenar el correo electrónico. n”;
}
// if (pass_registro.length < 8) {
// continuar = false;
// msg += “Cal omplir la contrasenya amb un mínim de 8 caràcters. n”;
// }
if (nombre_registro.length == 0) {
continuar = false;
msg += “Hay que llenar el nombre. n”;
}
if (!$(“#aceptopoliticas”).is(“:checked”)) {
continuar = false;
if (ref_id_periodico == 8) {
msg += “You must accept the privacy policy. n”;
} else {
msg += “Debes aceptar la política de privacidad. n”;
}
}
if (continuar) {
$.ajax({
type: “POST”,
xhrFields: {
withCredentials: true
},
data: $(“#formulario_registro”).serialize(),
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/register-user.php?t=` +
generarCadenaAlfanumerica(),
success: function(data) {
if (data == 0) {
var respuesta = “Este correo electrónico ya está registrado.”;
Swal.fire({
text: respuesta,
icon: “warning”
});
} else {
var respuesta = “¡Enhorabuena! Te has registrado con éxito.”;
Swal.fire({
text: respuesta,
icon: “warning”
});
recargar_widgets_sesion();
$(“#email_reg”).val(“”);
$(“#password_reg”).val(“”);
$(“#nombre_reg”).val(“”);
}
}
});
} else {
Swal.fire({
text: msg,
icon: “warning”
});
}
}
function recuperarPass() {
$.ajax({
type: “POST”,
xhrFields: {
withCredentials: true
},
data: $(‘#formulario_recuperarpass’).serialize(),
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/reset-pass-user.php?t=` +
generarCadenaAlfanumerica(),
success: function(data) {
//console.log(data);
var respuesta =
“Revisa tu e-mail y sigue las instrucciones para recuperar tu contraseña.”;
Swal.fire({
text: respuesta,
icon: “info”
});
$(“#modal-pass .modal-action.modal-close”).trigger(“click”);
$(“email_recuperar”).val(“”);
}
});
}
function resetearPass() {
if ($(“#nuevo-pass”).val() == $(“#nuevo-pass-repeat”).val()) {
if ($(“#nuevo-pass”).val().length >= 8) {
$.ajax({
type: “POST”,
xhrFields: {
withCredentials: true
},
data: $(‘#resetear-clave’).serialize(),
url: `https://api.v.1.2.3.escudodigital.newscript.es/api/resetear-pass.php?t=` +
generarCadenaAlfanumerica(),
success: function(data) {
//console.log(data);
$(“#email_recuperar”).val(“”);
var respuesta = “La contraseña se ha actualizado. Ya puedes volver a Iniciar Sesión.”;
Swal.fire({
text: respuesta,
icon: “success”
}).then((result) => {
window.location.href = ‘http://www.escudodigital.com/’;
});
}
});
} else {
var respuesta = “La contraseña debe tener un mínimo de 8 caracteres.”;
Swal.fire({
text: respuesta,
icon: “warning”
});
}
} else {
var respuesta = “Ambas contraseñas deben coincidir.”;
Swal.fire({
text: respuesta,
icon: “warning”
});
}
}
$(document).ready(function() {
recargar_widgets_sesion(); //DESCOMENTAR ESTO
});
‘)
.text(msg)
.insertAfter($el);
}
function esEmailValido(email) {
return /^[^s@]+@[^s@]+.[^s@]{2,}$/.test(String(email).trim());
}
function validar() {
limpiarErrores();
let ok = true;
const $nombre = $(“#nombre”);
const $email = $(“#email”);
const $motivo = $(“#motivo”);
const $check = $(“#checkbox”);
const nombre = $nombre.val().trim();
const email = $email.val().trim();
const motivo = $motivo.val().trim();
if (nombre.length < 2) {
marcarError($nombre, “Enter your full name.”);
ok = false;
}
if (!esEmailValido(email)) {
marcarError($email, “Enter a valid email.”);
ok = false;
}
if (motivo.length < 5) {
marcarError($motivo, “Briefly explain how we can help you.”);
ok = false;
}
if (!$check.is(“:checked”)) {
marcarError($check, “You must accept the legal terms.”);
ok = false;
}
return ok;
}
function setLoading(isLoading) {
$btn.prop(“disabled”, isLoading);
$btn.text(isLoading ? “Sending…” : “Sent”);
}
function submitFormWithToken(token) {
setLoading(true);
const payload = {
nombre: $(“#nombre”).val().trim(),
email: $(“#email”).val().trim(),
motivo: $(“#motivo”).val().trim(),
legal: $(“#checkbox”).is(“:checked”) ? 1 : 0,
periodico_id_periodico: 8,
periodico: ‘www.escudodigital.com’,
url: window.location.href,
periodico_nombre: ‘DigitalShield’,
token: token
};
$.ajax({
url: URL_ENDPOINT,
method: “POST”,
data: payload,
dataType: “json” // Expects JSON response from server
})
.done(function(res) {
if (res && (res === 1 || res === “1” || res.ok)) {
$(“#msgFormContacto”).html(‘Message sent successfully.
‘);
$form[0].reset();
} else {
$(“#msgFormContacto”).html(‘Message not sent. Try again.
‘);
}
})
.fail(function(xhr) {
$(“#msgFormContacto”).html(‘Connection error. Try again.
‘);
})
.always(function() {
setLoading(false);
});
}
$btn.on(“click”, function(e) {
e.preventDefault();
e.stopPropagation(); // Stop default button behavior if any
if (!validar()) return;
// Execute reCAPTCHA
if (window.grecaptcha) {
grecaptcha.ready(function() {
grecaptcha.execute(RECAPTCHA_SITE_KEY, {
action: ‘submit’
}).then(function(token) {
submitFormWithToken(token);
});
});
} else {
// Fallback or error if grecaptcha not loaded
alert(“reCAPTCHA not loaded. Please refresh.”);
}
});
$(“#nombre,#email,#motivo,#checkbox”).on(“input change”, function() {
$(this).removeClass(“is-invalid”);
$(this).next(“.error-text”).remove();
});
});
