Surfshark, a provider of virtual private network (VPN) services, has confirmed that an unauthorized third party accessed an internal test server in early September 2026. The company has assured customers that no personal data or browsing activity was compromised during the incident. The breach was traced back to a human error that left an internal engineering test server misconfigured and exposed to the public internet. The unauthorized party accessed limited internal engineering materials, including system binaries and internal configurations.
Surfshark emphasized that personal information "was never held and accessible from here," and customer VPN traffic is never logged in the first place. The compromised system was kept completely separate from live production systems, which do not store or process any user data. The first signs of unusual activity were detected on August 31, and the company initially handled it as a lower-risk case. However, once the full scope was confirmed on September 2, Surfshark immediately contained the incident, backed up the affected server, and disconnected its external connections.
The provider noted that the unauthorized actor also gained access to an isolated content accessibility optimization server, which acted purely as a proxy with no access to user IP addresses or encryption keys. Although none of these credentials provided access to user data or to the production systems that serve users, Surfshark rotated or retired every secret it identified as a precaution. Complete infrastructure remediation and secret rotation were finalized by September 5.
Surfshark acknowledged the ongoing challenges of securing internal testing infrastructure and intends to raise its test and experimental environments to the same security standards as its live production systems. The company vows to improve access controls and credential management throughout its build process and enhance the detection and monitoring of its testing infrastructure to ensure internal servers are never accidentally exposed to the internet again.
Surfshark has committed to a new independent security audit and confirmed that other third-party assessments are ongoing, including an audit of its proprietary protocol, Dausos. These steps are part of the company's broader commitment to ensuring the security and privacy of its users and systems.
Surfshark Addresses Unauthorized Access to Internal Test Server
AI-rewritten from original reportingHow it works
security-breachsurfsharkdata-protectioncybersecuritythird-party-audit



