Surfshark disclosed on its website that a misconfigured internal test server used by its engineering teams was made reachable from the internet due to a human error. The company detected suspicious activity on August 31 and contained the incident by September 2, completing remediation three days later.
The exposed environment contained system binaries, code history, and build-related credentials, but Surfshark stated that the unauthorized party also accessed a separate server used for content-accessibility optimization. That machine acted as a proxy and did not have access to sensitive data such as user identity, IP addresses, encryption keys, or browsing traffic.
“Personal information was never held and accessible from here [the breached server], VPN traffic and browsing activity are not logged or retained in the first place, and the apps and browser extensions on your devices were not altered in any way,” the VPN vendor assured in its report.
The company said there is no evidence that the exposed credentials were misused or that the breach spread to other systems. In response, Surfshark rotated all potentially impacted internal credentials, revoked exposed tokens, and implemented additional threat detection, activity monitoring, and system hardening measures.
These measures include applying production-level security controls to test environments, improving build-process credential management, and commissioning an independent audit of its broader infrastructure. Surfshark promised further updates if the ongoing investigation reveals additional findings.
Based on published information, Surfshark users do not need to take any action to protect their accounts, but the company recommends vigilance against suspicious activity or unsolicited communications.