VPN provider Surfshark confirmed that an unauthorized party accessed an internal test server in early September 2026, though the company stated no user data or traffic was compromised.
Key Points
- An unauthorized party accessed an internal engineering test server and a content optimization proxy between August 31 and September 2, 2026.
- Surfshark confirmed that the breach did not affect live production systems, user data, or VPN traffic logs.
- The incident was caused by a misconfigured server that was accidentally exposed to the public internet.
- The company finalized infrastructure remediation and rotated all identified security credentials by September 5.
- Surfshark plans to conduct a new independent cybersecurity audit to further strengthen its infrastructure and testing environments.