AI News Feed
Market watch
Cybersecurity

Surfshark says September test-server breach did not affect user data or VPN traffic

Surfshark disclosed that an unauthorized third party accessed a misconfigured internal test server in early September 2026, but said no user data or VPN traffic was compromised. The VPN provider has contained the incident, rotated credentials and plans a new independent infrastructure audit.

According to the report, no user data and VPN services were affected. Surfshark traced the breach to human error that left an internal engineering test server misconfigured and exposed to the public internet. Through that server, the unauthorized party accessed limited internal engineering materials, including system binaries and internal configurations. Surfshark emphasized that personal information was never held and accessible from there, and that customer VPN traffic is never logged in the first place.

Patricija Cerniauskaite, Head of Communications at Surfshark, told TechRadar that the compromised system was kept completely separate from live production systems. 'By design, it does not store or process any user data,' she said. 'While the incident does not affect our customers, we take it very seriously and believe that being open about security is an important part of earning customer trust. We remain committed to protecting our customers' privacy and security.'

According to Surfshark's incident timeline, the first signs of unusual activity were detected on August 31. Because the alerts originated from an isolated test environment that held no sensitive data, the company initially handled the matter as a lower-risk case rather than triggering its most urgent protocols. Once the full scope was confirmed on September 2, Surfshark immediately contained the incident, backed up the affected server and disconnected its external connections.

The provider noted that the unauthorized actor also gained access to an isolated content accessibility optimization server, which acted purely as a proxy with no access to user IP addresses or encryption keys. 'Although none of these credentials provided access to user data or to the production systems that serve our users, we reviewed the available access logs, and while no malicious activity was detected, as a precaution, we rotated or retired every secret we identified,' Surfshark said in its blog post. Complete infrastructure remediation and secret rotation were finalized by September 5.

The incident highlights the challenges of securing internal testing infrastructure, a gap Surfshark openly acknowledged. The provider now says it intends to raise its test and experimental environments to the same security standards as its live production systems. To further harden its security posture, Surfshark has vowed to improve access controls and credential management throughout its build process. It will also enhance detection and monitoring of its testing infrastructure to ensure internal servers are never accidentally exposed to the internet again.

Surfshark has built a reputation for transparency, often working with the security community to validate its services. Independent auditors confirm Surfshark's VPN infrastructure as secure on a regular basis, and the provider regularly backs up its no-log claims with third-party audits. Because the service is fundamentally designed not to retain or monitor browsing activity, incidents involving isolated test servers are far less likely to result in catastrophic user data leaks.

Following the incident, Cerniauskaite told TechRadar that the team is currently selecting an independent cybersecurity firm to conduct a new broad infrastructure audit. She also confirmed that other third-party assessments are ongoing, including an audit of Dausos, its proprietary protocol.