SURFSHARK , the VPN and cybersecurity services provider, disclosed a cybersecurity incident affecting certain internal data. The company says the issue was detected on 31 August 2026 and initially treated as low risk, with a later expansion of the scope confirmed on 2 September 2026, leading to containment and remediation. An internal test server, which had been misconfigured and exposed to the internet, was accessed by threat actors.
Surfshark notes the server housed limited internal engineering material, including parts of system binaries and internal configurations for certain services.
The hackers also accessed isolated internal resources, including a content accessibility optimisation server (a VPS used as a proxy). Surfshark emphasises that no user data or production systems serving customers were affected, and that the compromised environment does not store or process user data and is kept separate from production systems. The company states it does not log or retain VPN traffic or users’ browsing activity, and that no applications or browser extensions on user devices were altered.
In response, Surfshark says it contained and removed the exposure, rotated the relevant internal credentials, and implemented additional security measures. It also plans an independent security audit to assess the broader infrastructure’s security posture.