AUTO-UPDATED

'No user data affected' — Surfshark reveals details of September's security incident

VPN provider Surfshark confirmed that an unauthorized party accessed an internal test server in early September 2026, though the company stated no user data or traffic was compromised.

Key Points

  • An unauthorized party accessed an internal engineering test server and a content optimization proxy between August 31 and September 2, 2026.
  • Surfshark confirmed that the breach did not affect live production systems, user data, or VPN traffic logs.
  • The incident was caused by a misconfigured server that was accidentally exposed to the public internet.
  • The company finalized infrastructure remediation and rotated all identified security credentials by September 5.
  • Surfshark plans to conduct a new independent cybersecurity audit to further strengthen its infrastructure and testing environments.

Why it Matters

This incident highlights the critical importance of maintaining rigorous security standards for internal testing environments, which are often overlooked compared to live production systems. By proactively disclosing the breach and committing to further audits, Surfshark aims to maintain user trust and demonstrate transparency regarding its no-log privacy claims.
TechRadar Published by Rene Millman
Read original