Surfshark says hackers breached internal testing and proxy servers

Surfshark VPN disclosed on 10 September 2026 that hackers accessed an internal test server and a separate proxy server following a configuration error, according to BleepingComputer.
The company said the breach exposed service configurations, build-related credentials, system binaries and code history, but did not impact customer data, user traffic or production infrastructure.
Surfshark detected the unauthorized activity on 31 August and contained the incident on 2 September, before completing remediation three days later.
The VPN provider rotated impacted internal credentials, revoked exposed tokens and commissioned an independent security audit following the breach.