Data Breaches Surfshark Systems Targeted by Hackers A misconfigured test server containing engineering material, including internal configurations, was accessed by threat actors. By Ionut Arghire | September 11, 2026 (5:41 AM ET) Flipboard Reddit Whatsapp Whatsapp Email VPN and cybersecurity services provider Surfshark this week disclosed a cybersecurity incident impacting certain internal data. The incident, it says, was discovered on August 31, but initially treated as low risk. By September 2, however, the company confirmed the scope and moved to containment and remediation. An internal test server that became accessible from the internet after being misconfigured was accessed by a threat actor, Surfshark explains in an incident report . The server contained limited internal engineering material, including “parts of the system binaries and internal configurations for certain services,” Surfshark said. Surfshark also identified internal, build-related credentials that had been committed to its code history and rotated them, although they did not provide access to user data or production systems serving users. Additionally, the hackers accessed an isolated content accessibility optimization server (VPS) used as a proxy. However, no encryption keys, user identities, IP addresses, or browser traffic were exposed. Advertisement. Scroll to continue reading. “Based on our investigation, we have confirmed that no user data and VPN services were affected,” the company said. “The system involved was an internal engineering environment. By design, it does not store or process any user data, and it is kept separate from the production systems that deliver our service,” it added. The company also pointed out that it does not log or retain VPN traffic and browsing activity and that no application or browser extension running on users’ devices was altered. In response to the incident, the company contained the affected system and removed the exposure, rotated the relevant internal credentials, implemented additional security measures, and confirmed the full scope of the compromise. “We will also execute an additional independent security audit to evaluate the security posture of the broader infrastructure environment,” Surfshark said. Related: 4.1 Million Impacted by AdaptHealth Data Breach Related: Mathspace Data Breach Exposes Over 1 Million People Related: Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal Related: 153 Million Driver License Images Offered on Dark Web Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Critical NetScaler Vulnerability Exploited in Attacks 4.1 Million Impacted by AdaptHealth Data Breach New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks HelmGuard Raises $7.3 Million for Agentic GRC and Security Android’s September 2026 Updates Patch 180 Vulnerabilities Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension Latest News Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion PaperCut Flaws Exploited in AI-Powered Attacks Mandiant Founder Kevin Mandia Joins Amazon Board Cybersecurity M&A Roundup: 33 Deals Announced in August 2026 Anthropic Researcher Resigns With Warning About the Dangers of AI Development Hacker Conversations: Vinnie Liu, Performer Turned Ringmaster Deceptive Android Apps Exploit Google Play Early Access to Evade Reviews Webinar Today: Keep Pace With AI – A New Operating Model for Endpoint Remediation Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the Move Amazon has elected Kevin Mandia to its Board of Directors. Gigamon has named Grant Yacomeni as Chief Information Security Officer. SSH Communications Security has appointed Lars Bell as Chief Executive Officer. More People On The Move Expert Insights This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Flipboard Reddit Whatsapp Whatsapp Email
A threat actor accessed a misconfigured internal test server at Surfshark, which was inadvertently exposed to the internet and contained engineering materials including system binaries and internal configurations. The company confirmed no user data or production systems were affected, as the compromised environment was isolated by design. In response, Surfshark contained the system, rotated exposed internal credentials, and will conduct an independent security audit.