← Surfshark

2026 Surfshark — misconfigured internal test/proxy servers accessed (no customer data)

2026 Unknown records affected Share on X

Data compromised

Internal engineering material: parts of system binaries, internal service configurations, and build-related credentials in code history. Company states no user identities, IP addresses, encryption keys, browsing traffic, or production VPN data were accessible.

Technical writeup

Verified Surfshark incident report — published September 9, 2026 (BleepingComputer Sep 10). First signs August 31; confirmed unauthorized access September 2 and contained same day; remediation completed September 5. A misconfigured internal test server reachable from the internet exposed limited engineering binaries/configs and historical build credentials; a separate isolated proxy VPS used for content-accessibility optimization was also accessed. Surfshark states customer/user data and production VPN services were not affected; credentials rotated; independent audit commissioned. recordsAffected 0 (no customer census); companyConfirmed true.

Root cause

Human misconfiguration exposed an internal engineering test server to the internet; unauthorized access also reached an isolated content-accessibility proxy VPS

References