Surfshark VPN says hackers breached internal testing, proxy servers

Surfshark VPN has suffered a significant security breach, with hackers gaining unauthorized access to one of its internal test servers and another server used as a proxy. The incident has left many wondering about the potential impact on customer data and the company’s overall cybersecurity posture.

According to Surfshark’s explanation, the breach was caused by a human error that exposed an internal test server to the internet. This misconfigured server allowed hackers to access sensitive information, including service configurations and build-related credentials. The affected environment also contained system binaries and code history, which could potentially be used for malicious purposes.

However, it’s essential to note that Surfshark assures its customers that production VPN infrastructure and customer data were not impacted by the breach. The company claims that user identity, IP addresses, encryption keys, or browsing traffic were never exposed, and that no evidence suggests any misuse of the leaked credentials. Additionally, the apps and browser extensions on users’ devices were not altered in any way.

The breach was detected on August 31, and Surfshark claims to have contained it by September 2. The company completed the remediation process three days later, which involved rotating internal credentials, revoking exposed tokens, and implementing additional security measures such as threat detection, activity monitoring, and system hardening. These measures also include production-level security controls for test environments, improved credential management, and an independent audit of its broader infrastructure.

It’s worth noting that the breach was limited to two servers, and there is no evidence to suggest any further compromise or spread to other systems. While Surfshark users do not need to take any action to protect their accounts, it’s still recommended to remain vigilant against suspicious activity or unsolicited communications.

The incident highlights the importance of robust cybersecurity practices, even for companies that provide security services themselves. As a leading VPN provider, Surfshark has a responsibility to its customers and should strive to maintain the highest standards of security and transparency in the event of any breach. By doing so, it can help rebuild trust with its users and demonstrate its commitment to protecting their data.

For readers who are concerned about the security of their own online activities, this incident serves as a reminder to stay informed and vigilant about potential threats. While Surfshark’s breach may not have directly impacted customer data, it underscores the importance of regular security checks, password management, and being cautious when engaging with unknown communications or websites.


Source: Bleeping Computer — 2026-09-10