Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Surfshark

Surfshark Vendor Cyber Rating & Cyber Score

surfshark.com

Surfshark is a fast-growing cybersecurity company focused on developing humanized privacy & security protection solutions to secure people's digital lives. Its core product is one of the TOP 3 VPNs globally, trusted by millions of users around the world. Additionally, Surfshark has been developing solutions such as Antivirus, Alert - a data leak detection system, a private search tool - Search, Incogni, Dedicated IP, and Alt-ID. Founded in 2018 as a VPN, Surfshark has quickly managed to become one of the leading brands in the VPN industry and offers a security bundle that goes beyond the VPN. Today, Surfshark is a second unicorn in Lithuania with 400+ employees in Vilnius, Kaunas, Warsaw, and Berlin, and securing the digital lives of


Surfshark A.I CyberSecurity Scoring

Surfshark
Company Information
Website:https://surfshark.com/career
Employees number:495
Number of followers:24,823
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:surfshark.com
Surfshark Risk Score (AI oriented)
Between 0 and 549
logo
SurfsharkIT Services and IT Consulting
Updated:
25/05/2026
485/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Surfshark Global Score (TPRM)
xxxx
logo
SurfsharkIT Services and IT Consulting
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Surfshark
SurfsharkCritical
Current Score
485C (CRITICAL)
01000
3 incidents
-101.33 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
490Before Incident
MAY 2026
482Before Incident
APRIL 2026
481Before Incident
MARCH 2026
474Before Incident
FEBRUARY 2026
469Before Incident
JANUARY 2026
576Before Incident
Breach
01 Jan 2026Surfshark
Surfshark: Nigeria Hit By 24.1m Data Breaches Amid Rising Cyberattacks

Nigeria Ranks Third in Sub-Saharan Africa for Compromised Accounts

458After Incident
CRITICAL-118
SUR1778164255
Nigeria Ranks Third in Sub-Saharan Africa for Compromised Accounts, Surfshark Report Reveals Nigeria has recorded 24.1 million compromised user accounts since 2004, making it the third most affected country in Sub-Saharan Africa, according to a recent report by cybersecurity firm Surfshark. The analysis, covering global data breach trends for Q1 2026, found that Nigeria experienced 281,500 leaked accounts between January and March 2026, ranking it 34th globally during that period. Globally, 210.3 million accounts were breached in Q1 2026 a sharp increase from previous quarters. The United States led with 29% of all reported breaches, followed by France, India, Brazil, and the UK. Nigerian users faced escalating risks, including identity theft, account hijacking, extortion, and financial fraud, with 7.5 million unique email addresses and 13 million passwords exposed since 2004. The report highlighted that over half of breached Nigerian users remain vulnerable, with 10% of the population affected by data leaks. Compromised data included highly sensitive information, such as: - 3,900 Social Security-related records - 1,600 payment card details - 1.9 million phone numbers - 925,000 residential addresses Surfshark attributed the surge in breaches to the rapid adoption of AI technologies, which has expanded the volume of user data collected and stored. 20.2% of companies used AI in 2025 up from 8.7% in 2023 increasing attack surfaces for cybercriminals. The firm’s Chief Security Officer, Tomas Stamulis, warned that AI-driven systems, while boosting efficiency, also create new vulnerabilities, as hackers exploit combo lists datasets combining old and new leaks for fraud and identity theft. The report further noted that global breaches in Q1 2026 tripled year-over-year and rose 22% from Q4 2025, underscoring the growing sophistication of cyberattacks.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Identity theftAccount hijackingExtortionFinancial fraud
IMPACT
Data Compromised: 24.1 million accounts since 2004, 281,500 in Q1 2026Identity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Social Security-related recordsPayment card detailsPhone numbersResidential addressesEmail addressesPasswordsNumber Of Records Exposed: 24.1 million accounts since 2004, 281,500 in Q1 2026Sensitivity Of Data: HighSocial Security-related recordsPayment card detailsPhone numbersResidential addressesEmail addresses
DECEMBER 2025
576Before Incident
NOVEMBER 2025
589Before Incident
Cyber Attack
01 Nov 2025Surfshark
Signal, Surfshark and UltraViewer: Silver Fox Abuses Stolen EV Certificates in AtlasCross RAT Malware Campaign

Silver Fox APT Targets Chinese-Speaking Users with Stealthy AtlasCross RAT Campaign

569After Incident
HIGH-20
SURSIGULT1774535812
Silver Fox APT Targets Chinese-Speaking Users with Stealthy AtlasCross RAT Campaign A Chinese-nexus advanced persistent threat (APT) group, tracked as Silver Fox (also known as Void Arachne and SwimSnake), is conducting a sophisticated campaign targeting Chinese-speaking users and professionals. Security researcher Maurice Fielenbach of Hexastrike uncovered the operation, which leverages typosquatted domains impersonating trusted brands like Surfshark, Signal, and Zoom to distribute malware. The attackers use stolen Extended Validation (EV) code-signing certificates issued to a Vietnamese entity, DUC FABULOUS CO.,LTD (valid until May 2027) to bypass security checks and establish deep persistence in enterprise networks. Victims are lured into downloading a ZIP archive containing a triple-nested Setup Factory installer, which deploys a trojanized Autodesk component (Schools.exe) alongside legitimate decoy applications like UltraViewer to avoid suspicion. The malware employs advanced evasion techniques, including Process Environment Block (PEB) walking and ROR13 hashing, to dynamically resolve APIs and evade static analysis. It retrieves a second-stage shellcode payload from its command-and-control (C2) server over raw TCP, then loads the AtlasCross RAT entirely in memory using a reflective loader, leaving no disk footprint. At the core of the attack is AtlasCross RAT, which integrates a custom PowerShell execution engine (PowerChell). This framework disables critical security mechanisms, including: - Antimalware Scan Interface (AMSI) - Event Tracing for Windows (ETW) - Constrained Language Mode (CLM) - ScriptBlock logging The RAT communicates with its C2 infrastructure using ChaCha20 encryption and hardware-generated random keys. To maintain persistence, it terminates TCP connections used by Chinese security tools like 360 Total Security and Huorong, preventing signature updates without killing processes. Additional tactics include DLL injection into WeChat (Wxfun.dll) for data harvesting and RDP session hijacking via tscon.exe. The campaign, active between November 2025 and March 2026, demonstrates Silver Fox’s evolution from driver-based process termination to network-level disruption, signaling a rapidly maturing threat actor. Key indicators of compromise (IOCs) include the stolen EV certificate (2C1D12F8BBE0827400A8440AF74FFFA8DCC8097C), C2 domain (bifa668.com), and typosquatted domains (www-surfshark[.]com, signal-signal[.]com). Security teams are advised to monitor for non-standard processes loading System.Management.Automation.dll and scheduled tasks under \Microsoft\Windows\AppID\.
INCIDENT DETAILS -
TYPE
APT Campaign
IMPACT
Data Compromised: Potential data harvesting via WeChat DLL injection and RDP session hijackingEnterprise networksWindows systemsOperational Impact: Disruption of security tools (360 Total Security, Huorong), potential RDP session hijackingIdentity Theft Risk: High (due to potential PII harvesting)
DATA BREACH
Personally Identifiable Information (PII)Potential WeChat dataSensitivity Of Data: HighData Exfiltration: Possible via AtlasCross RATData Encryption: ChaCha20 encryption for C2 communicationsPersonally Identifiable Information: Likely (via WeChat DLL injection)
OCTOBER 2025
754Before Incident
Breach
14 Oct 2025Surfshark
Surfshark and Statista: Data records breached worldwide Q3 2025

Global Data Breaches Reach Record Highs, Exposing Over 1 Billion Accounts in 2025

588After Incident
LOW-166
STASUR1779668969
Global Data Breaches Reach Record Highs, Exposing Over 1 Billion Accounts in 2025 A recent report by Surfshark, published on October 14, 2025, and analyzed by Statista, reveals a sharp rise in global data breaches, with over 1 billion user accounts exposed worldwide between the first quarter of 2020 and the third quarter of 2025. The data, compiled from cybersecurity tracking, highlights a persistent and escalating threat landscape, with breaches affecting individuals and organizations across 150+ countries. The report underscores a steady upward trend in account exposures, driven by increasingly sophisticated cyberattacks, including ransomware, phishing, and supply chain vulnerabilities. While the exact breakdown of affected sectors remains unspecified, the scale of the breaches suggests widespread impact across industries, from finance and healthcare to e-commerce and social media. The findings serve as a stark indicator of the growing challenges in cybersecurity, with attackers leveraging both technical exploits and human error to compromise sensitive data. The report’s timeline spanning five years of quarterly data provides a longitudinal view of the evolving threat environment, offering critical context for security professionals and policymakers.
INCIDENT DETAILS -
TYPE
data_breach
IMPACT
Data Compromised: over 1 billion user accounts
DATA BREACH
Number Of Records Exposed: over 1 billion
SEPTEMBER 2025
754Before Incident
AUGUST 2025
754Before Incident
JULY 2025
754Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Surfshark ?
?
What was Surfshark's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Surfshark's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Surfshark's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Surfshark's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Surfshark's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Surfshark's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Surfshark's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Surfshark's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Surfshark's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Surfshark's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Surfshark's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Surfshark's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Surfshark ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Surfshark's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?