Surfshark VPN Confirms Internal Test Server Breach Due to Configuration Error
Unauthorized access to testing infrastructure raises questions on cloud security hygiene

Key Takeaways
- Surfshark confirmed a breach of an internal test server due to a configuration error.
- No customer data or production systems were compromised.
- The exposed server was part of internal testing and proxy infrastructure.
- Surfshark has restricted access and is reviewing security configurations.
- No end-user patch is required; the incident highlights risks of misconfigured cloud assets.
Quick answers
- What happened?
- Surfshark VPN disclosed that hackers gained access to an internal test server after a configuration error exposed it to the public internet. The company confirmed no customer data or production systems were compromised, but the incident highlights the risks of misconfigured cloud assets.
- Which products are affected?
- Surfshark VPN
- What should defenders do?
- Surfshark has restricted access to the exposed test server and is reviewing security configurations to prevent recurrence. No patch required for end-users.
Surfshark VPN has confirmed a security incident involving unauthorized access to one of its internal test servers. According to a disclosure reported by BleepingComputer, the breach occurred due to a configuration error that inadvertently exposed the test server to the internet. The company stated that the exposed server was part of its internal testing infrastructure and proxy-related development environment.
Surfshark emphasized that no customer data, production systems, or core VPN services were compromised as a result of the incident. The company has since restricted access to the exposed server and is conducting a review of its security configurations to prevent recurrence. No software patch is required for end-users, as the issue stemmed from an internal misconfiguration rather than a vulnerability in the VPN client itself.
The incident serves as a reminder of the importance of securing testing and development environments, particularly those that may be hosted on cloud infrastructure. Details regarding the exact method of exploitation, the volume of data potentially accessed, and whether any credentials or test data were exfiltrated remain under investigation.
Security Details
Unauthorized access to an internal test server exposed due to a configuration error. The exact exploitation method and data exfiltration status are under investigation. No customer or production systems were affected.
Affected products
Surfshark VPN
Mitigation
Surfshark has restricted access to the exposed test server and is reviewing security configurations to prevent recurrence. No patch required for end-users.
Sources
BleepingComputer
Surfshark VPN says hackers breached internal testing, proxy servers
Sep 10, 2026 · 19:15
Original link
Related Security News

Times Car Confirms Data Breach Affecting 6.6 Million User Accounts
Times Car, a Japanese car-sharing service, has confirmed a data breach compromising approximately 6.6 million user accounts. The incident was disclosed late last week, with the exact attack vector and nature of exposed personal information yet to be fully specified. Authorities and the company are reportedly investigating the breach.

French Tax Administration Data Breach Exposed Hundreds of Thousands of Records via Stolen Staff Credentials
An unauthorized access incident at France's Direction Générale des Finances Publiques (DGPP) compromised tax data belonging to hundreds of thousands of taxpayers and businesses between June and July 2026. According to a report published by France's national cybersecurity agency ANSSI on 29 September 2026, the attacker used stolen staff passwords to gain entry. The agency stated the attack was 'not sophisticated' and went undetected for seven weeks due to weak security controls. ANSSI noted that neither the tax administration nor the agency itself observed data exfiltration, though the breach resulted in unauthorized access to sensitive fiscal information.



