Surfshark Discloses Internal Test Server Breach, Assures No Customer Data Compromised
VPN provider **Surfshark** has revealed that an internal test server was accessed by unauthorized parties due to a configuration error. While the incident exposed service configurations and build-related credentials, the company states that no customer data, VPN traffic, or sensitive user information was compromised.
VPN service provider **Surfshark** recently disclosed a security incident involving unauthorized access to one of its internal test servers. The breach, attributed to a human error that exposed the server to the internet, occurred between August 31 and September 2.

### The Incident Details
**Surfshark** explained on its website that a misconfigured internal test server, used by engineering teams, became internet-accessible. This exposed environment contained portions of system binaries, code history, service configurations, and build-related credentials.
Additionally, the unauthorized party accessed a separate server acting as a proxy for content-accessibility optimization. **Surfshark** emphasized that this proxy machine did not store any sensitive data such as user identities, IP addresses, encryption keys, or browsing traffic.
### No Customer Impact
Crucially, **Surfshark** has assured users that its production VPN infrastructure and customer data remained unaffected. The company stated, βPersonal information was never held and accessible from here [the breached server], VPN traffic and browsing activity are not logged or retained in the first place, and the apps and browser extensions on your devices were not altered in any way.β
### Remediation and Future Measures
Upon detecting suspicious activity on August 31, **Surfshark** contained the incident by September 2 and completed remediation three days later. The company confirmed there is no evidence that the exposed credentials were misused or that the compromise spread to other systems.
In response, **Surfshark** has rotated all potentially impacted internal credentials, revoked exposed tokens, and implemented enhanced threat detection and activity monitoring. Future measures include applying production-level security controls to test environments, improving build-process credential management, and commissioning an independent audit of its broader infrastructure.
### User Action Not Required
Based on the information provided, **Surfshark** users are not required to take any immediate action to protect their accounts. However, general vigilance against suspicious activity or unsolicited communications remains a recommended cybersecurity practice. **Surfshark** has committed to providing further updates should the ongoing investigation uncover additional significant findings.