Surfshark confirms that an unauthorized third party has gained access to the internal server No user data or browsing traffic was compromised. The firm has committed to carrying out a new independent safety audit. Surfshark published a detailed report of a security incident that occurred in early September 2026, confirming that an unauthorized third party had access to its internal test server. If you rely on the best VPN to protect your online privacy, the provider is quick to reassure users that its production systems remain completely secure. According to the official statement, “no user data or VPN services were affected during the incident.” The breach was ultimately attributed to human error in which an internal engineering test server was misconfigured and exposed publicly on the Internet. Through this server, an unauthorized party gained access to a limited amount of internal engineering material, including system binaries and internal configurations. It’s important to note that Surfshark emphasized that personal information was “never stored or accessed from here” and client VPN traffic is never logged at all. Speaking to TechRadar, Patricia Cherniauskaite, head of communications at Surfshark, confirmed that the compromised system was completely separate from live production systems. “By its design, it does not store or process any user data,” Cherniauskaite explained. “While the incident does not impact our customers, we take it very seriously and believe that being transparent about security is an important part of earning customer trust. We remain committed to protecting the privacy and security of our customers.” How Surfshark responded to the hack According to Surfshark’s official incident timeline, the first signs of unusual activity were detected on August 31st. Because the alerts came from an isolated test environment that contained no sensitive data, the company initially treated it as a low-risk incident rather than running the most urgent protocols. However, once the full scope was confirmed on September 2, Surfshark immediately contained the incident, backed up the affected server, and disabled its external connections. The provider noted that the unauthorized attacker also gained access to an isolated Content Availability Optimization server, which acted solely as a proxy server without access to users’ IP addresses or encryption keys. “While none of these credentials provided access to user data or to the production systems that serve our users, we reviewed the available access logs, and while no malicious activity was detected, as a precaution we changed or removed any secrets we discovered,” Surfshark explained in a blog post. Full infrastructure restoration and secret rotation were completed by September 5. The incident highlights ongoing challenges with securing internal testing infrastructure, a gap that Surfshark has openly acknowledged. The vendor now confirms its commitment to bringing its test and development environments to the same security standards as its live production systems. To further strengthen its security, Surfshark promises improved access control and credential management throughout the build process. It will also improve discovery and monitoring of testing infrastructure to ensure that internal servers are never accidentally connected to the Internet again. (Image credit: Future) NEW: Leave no trace — A weekly newsletter on digital privacy and online surveillance. Leave No Trace examines the companies and governments putting our digital freedom at risk, and the people who are fighting back. 📩 Subscribe now to receive each edition in your inbox every Friday, starting this September. Commitment to Transparency Surfshark has built a strong reputation for maintaining customer trust, often working alongside the security community to validate its services. Independent auditors regularly confirm the security of Surfshark’s VPN infrastructure. The vendor also regularly backs up its log-free claims with third-party audits. Because the service is designed by design to not store or track browsing activity, incidents with isolated test servers are much less likely to result in catastrophic user data breaches. However, following this incident, Cerniauskaite told TechRadar that the team is now selecting an independent cybersecurity firm to conduct a new, broad audit of the infrastructure. She also confirmed that other third-party assessments are ongoing, including an audit of Dausos, its own protocol. Follow TechRadar on Google News. And add us as your preferred source to get our expert news, reviews and opinions in your feeds. Be sure to click the “Subscribe” button! Post navigation What in the World – Why some people take anxiety medication in the evening – BBC Sounds Deco explains why Barcelona wanted Anthony Gordon more than Marcus Rashford