< Back to all clusters
[TECHNOLOGY] · 4 sources

started · updated

Surfshark confirms security incident did not affect user data

Surfshark has disclosed a security incident involving an internal test server that was accessed by an unauthorized third party in early September 2026. The company confirmed that the breach was caused by human error, which left a misconfigured test server reachable from the public internet.

According to the company, the affected environment was isolated from live production systems and did not store or process customer information. Surfshark stated that “no user data and VPN services were affected” and emphasized that customer VPN traffic and browsing activity are not logged or retained. The unauthorized access was limited to engineering materials, including system binaries, internal configurations, and certain build-related credentials.

Surfshark detected unusual activity on August 31 and contained the incident by September 2. In response, the company rotated all affected secrets, hardened its infrastructure, and has committed to conducting a new independent security audit to ensure continued protection.

Entities

Surfshark