Surfshark VPN says hackers accessed misconfigured internal test and proxy servers; no customer data affected
Surfshark disclosed that a threat actor accessed an internet-exposed internal engineering test server and a separate isolated proxy server due to misconfiguration, exposing service configurations, system binaries, and build-related credentials — but no…
Surfshark disclosed (reported September 10-11, 2026 by BleepingComputer and SecurityWeek) that a threat actor accessed an internal engineering test server that was reachable from the internet due to a misconfiguration the company attributes to human error. The exposed server contained service configurations, portions of system binaries, and build-related credentials committed to code history. A separate, isolated proxy server used for content-accessibility optimization was also accessed; both outlets report it stored no user identity data, IP addresses, encryption keys, or browsing traffic. Per BleepingComputer, suspicious activity was detected on August 31, 2026, contained on September 2, and remediation completed on September 5; SecurityWeek confirms the August 31 discovery but does not give the containment or remediation dates. Surfshark says there is no evidence the credentials were misused or that the intrusion spread to other systems, and that no customer action is required. The company rotated the impacted credentials, revoked exposed tokens, and added monitoring and hardening, and it commissioned an independent audit of its infrastructure (BleepingComputer describes the audit as commissioned; SecurityWeek describes it as announced/planned).
- A threat actor accessed an internal engineering test server exposed to the internet via misconfiguration, which Surfshark attributes to human error
- Exposed material included internal service configurations, portions of system binaries, and build-related credentials committed to code history
- A separate, isolated proxy server used for content-accessibility optimization was also accessed; it held no user identity data, IP addresses, encryption keys, or browsing traffic
- Timeline: suspicious activity detected August 31, 2026; contained September 2; remediation completed September 5 (dates from BleepingComputer)
- No evidence of credential misuse or spread to other systems; no customer data, VPN traffic, or encryption keys affected; no customer action required
- Surfshark rotated impacted credentials, revoked exposed tokens, and added monitoring and hardening
- An independent audit of Surfshark's infrastructure was commissioned (SecurityWeek: announced/planned); sources agree on the audit but differ slightly on whether it was already commissioned
Coverage timelineoldest first · each row is one article
- · 5d agoSurfshark VPN says hackers breached internal testing, proxy servers
BleepingComputer· 42
Surfshark disclosed that hackers accessed misconfigured internal test and proxy servers, exposing build credentials but not customer data, VPN traffic, or production infrastructure.
- · 4d agoSurfshark Systems Targeted by Hackers
SecurityWeek· 48
Surfshark discloses hackers accessed a misconfigured internal test server; no user data or VPN services affected.