On the 2nd of September we confirmed an unusual activity within one of our internal test servers and immediately began our response. After identifying that the server has been accessed by an unauthorized party, we contained the incident on the same day. Further remediation was done by 5th September. Based on our investigation, we have confirmed that no user data and VPN services were affected.
Does it affect the customers?
No, it does not affect our customers and no user action is required. The system involved was an internal engineering environment. By design, it does not store or process any user data, and it is kept separate from the production systems that deliver our service. Personal information was never held and accessible from here, VPN traffic and browsing activity are not logged or retained in the first place and the apps and browser extensions on your devices were not altered in any way.
What happened:
Due to a human error, an internal test server, used by our engineering teams was misconfigured in a way that made it reachable from the internet. Through that server, limited internal engineering material stored in one of our environments was accessed by an unauthorized third party. It contained parts of the system binaries and internal configurations for certain services. Some internal, build-related credentials had at times been committed to our code history. Although none of these credentials provided access to user data or to the production systems that serve our users, we reviewed the available access logs; and while no malicious activity was detected, as a precaution, we rotated or retired every secret we identified. Access was also gained to an isolated content accessibility optimisation server (VPS). This server acted as a proxy with no access to user identities, IP addresses, encryption keys, or browsing traffic, meaning user privacy and security was not affected. The credentials protecting systems that contain sensitive data are held separately in vaults and therefore were also unaffected.
What we did about it:
- We contained the affected system and removed the exposure.
- We conducted a thorough investigation across our environment to determine the full scope of an incident.
- As a precaution, we rotated the relevant internal credentials. Where any credentials had at any point been included in our code history, we reviewed them and rotated or retired every one identified.
- We confirmed the activity did not spread to other systems and did not reach any user data.
- We implemented additional security measures to improve detection and monitoring and harden our systems and infrastructure.
Next steps:
The first signs of the incident were detected on 31 August. The alert came from an isolated test environment that holds no user or sensitive data. Because of this, initially it was handled as a lower-risk case, rather than under the urgent protocols reserved for systems that store or access private data. Once we confirmed the scope, we contained and removed the threat by 2 September. We see this gap as a key lesson, and we are now raising our test and experimental environments to the same security standards as our production systems. To further harden our security posture, we will:
- Improve access controls and credentials management throughout our build process
- Improve detection and monitoring of testing infrastructure to ensure non-exposure to the internet and faster response to IT and security events
- Ensure the same security tools implementation and hardening of OS and services in testing infrastructure
We will also execute an additional independent security audit to evaluate the security posture of the broader infrastructure environment.
We hold ourselves to a high standard, and we believe being open about security is part of earning customer trust. We remain committed to protecting your privacy and keeping you informed. We will update this blog post with relevant progress or any additional details as we continue strengthening our service.
Incident timeline
- 2026-08-31 – Identification. A suspicious event was noticed in the security monitoring system.
- 2026-09-02 – Confirmation and containment. Initial evaluation was finished and the identified event was classified as a security incident. Affected server was backed up, snapshot was made and disconnected external connection.
- 2026-09-02 – Eradication. Affected server, other servers in the same subnet and other accessible assets were evaluated for backdoor, all potentially affected secrets were revoked or rotated.
- 2026-09-05 – Remediation/Recovery. Additional security posture evaluation, secret rotation, and infrastructure hardening for all environments is active and will remain ongoing as a continuous process.