LmCast :: Stay tuned in

Surfshark VPN says hackers breached internal testing, proxy servers

Recorded: Sept. 10, 2026, 8 p.m.

Original Summarized

Surfshark VPN says hackers breached internal testing, proxy servers

News

Featured
Latest

AdaptHealth confirms 4.1 million people exposed in July cyberattack

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Over 36,000 exposed Plex servers vulnerable to recent flaws

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

Surfshark VPN says hackers breached internal testing, proxy servers

Microsoft Excel KB5002914 update breaks copy and paste for some users

This refurbished Lenovo Chromebook streams and browses for $75

AI-powered attack exploited PaperCut flaws to hack 395 organizations

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecuritySurfshark VPN says hackers breached internal testing, proxy servers

Surfshark VPN says hackers breached internal testing, proxy servers

By Bill Toulas

September 10, 2026
03:15 PM
0

Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet.
The VPN service provider said the incident did not affect its customers and did not extend to other parts of its infrastructure, but it exposed service configurations and build-related credentials.
“Due to a human error, an internal test server used by our engineering teams was misconfigured in a way that made it reachable from the internet,” Surfshark explained on its website.
The exposed environment also contained portions of system binaries and code history.
Surfshark said that the unauthorized party accessed a separate server used for content-accessibility optimization. The machine acted as a proxy and did not have access to any sensitive data, like user identity, IP addresses, encryption keys, or browsing traffic.
The company did not specify which specific binaries, configurations, services, credentials, or files were exposed, but confirmed that production VPN infrastructure and customer data were not impacted.
“Personal information was never held and accessible from here [the breached server], VPN traffic and browsing activity are not logged or retained in the first place, and the apps and browser extensions on your devices were not altered in any way,” the VPN vendor assured.
The company detected suspicious activity on August 31 and contained the incident on September 2. Three days later, the company completed the remediation process.
It also said there was no evidence that the exposed credentials had been misused or that the compromise had spread to other systems.
In response to the incident, Surfshark rotated all internal credentials that may have been impacted, revoked the exposed tokens, and implemented additional threat detection, activity monitoring, and system hardening measures.
These measures include implementing production-level security controls to test environments, improving build-process credential management, and commissioning an independent audit of its broader infrastructure.
Surfshark promised to provide further updates if the ongoing investigation reveals additional important findings.
Based on the published information, Surfshark users do not need to take any action to protect their accounts. However, vigilance against suspicious activity or unsolicited communications is still recommended.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat

Related Articles:
Get a year of Surfshark One+ and Incogni for $95 (reg. $250.20)Get 3 years of Surfshark VPN on unlimited devices for just $83.99This 3-year Surfshark VPN deal covers unlimited devices for $84A year of Surfshark One+ & Incogni is $95 for a limited timeA Surfshark VPN plan for all your devices is now 84% off

Security Breach
Software
SurfShark
VPN

Bill Toulas
Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

Sponsor Posts

Overdue a password health-check? Audit your Active Directory for free

Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. 

See how attackers exploit passkey enrollment, and why hardware-bound biometrics raise enterprise identity assurance.

EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

Surfshark VPN reported that unauthorized access occurred on one of its internal test servers stemming from a configuration error that inadvertently exposed the server to the internet. The service provider clarified that this incident did not impact customers or other segments of their infrastructure, but it did expose certain service configurations and build-related credentials. The compromised server was a separate machine utilized for content-accessibility optimization and functioned solely as a proxy, meaning it did not possess access to any sensitive customer data, such as user identities, IP addresses, encryption keys, or browsing traffic records. The company explicitly assured that no personal information was stored or accessible from this breached server, and that VPN traffic and browsing activities were neither logged nor retained in the first place.

The timeline of the event involved the detection of suspicious activity on August 31 and the containment of the incident on September 2, followed by the completion of the remediation process three days later. In response to the breach, Surfshark implemented several security enhancements, including rotating all potentially affected internal credentials and revoking the exposed tokens. Furthermore, the company introduced additional security measures, such as deploying production-level security controls to test environments, improving the management of build-process credentials, and commissioning an independent audit of the broader infrastructure. This proactive approach focused on system hardening, enhanced activity monitoring, and improved threat detection. The organization also confirmed that there was no evidence suggesting the exposed credentials had been misused or that the compromise had propagated to other systems. Based on the information released, Surfshark users were advised that no immediate action was required, though general vigilance regarding suspicious communications remained recommended. This incident, detailed by Bill Toulas, underscores the importance of securing testing environments and credential management within complex infrastructure systems.