'No user data affected' — Surfshark reveals details of September's security incident
- Surfshark confirms an unauthorized third party accessed an internal server
- No user data or browsing traffic was compromised
- The firm has committed to a new independent security audit
Surfshark has published a detailed incident report regarding a security breach that occurred in early September 2026, confirming that an internal test server was accessed by an unauthorized third party.
If you rely on the best VPN to protect your online privacy, the provider was quick to reassure users that its live production systems remained completely secure. According to the official disclosure, "no user data and VPN services were affected" during the incident.
The breach was ultimately traced back to a human error that left an internal engineering test server misconfigured and exposed to the public internet. Through this server, the unauthorized party accessed limited internal engineering materials, including system binaries and internal configurations.
Crucially, Surfshark emphasized that personal information "was...
Copyright of this story solely belongs to www.techradar.com. To see the full text click HERE