Surfshark has published a report on a security incident involving an internal engineering test server that was exposed to the public internet after a configuration error. The company said the server was accessed by an unauthorized third party in early September 2026.
Surfshark said its live production systems remained separate and secure. According to the provider, “no user data and VPN services were affected.” The exposed server did not store or process user data, and Surfshark said customer VPN traffic is not logged. The unauthorized party accessed limited engineering materials, including system binaries and internal configurations.
The company’s timeline says unusual activity was first detected on August 31. After confirming the incident’s scope on September 2, Surfshark contained it, backed up the affected server, and disconnected its external connections. An isolated content accessibility optimization server was also accessed, but Surfshark said it had no access to user IP addresses or encryption keys.
Surfshark reviewed access logs, found no malicious activity, and rotated or retired every identified secret as a precaution. Remediation and secret rotation were completed by September 5. The provider plans to apply the same security standards to test environments, improve access and credential controls, and strengthen monitoring. It is also selecting an independent cybersecurity firm for a broad infrastructure audit.
Comments
0No comments yet. Be the first to comment.