-
Hackers slipped into an internal test server after a setup mistake left it open on the internet.
-
Surfshark says no customer information, VPN traffic, or encryption keys were exposed.
-
The company has changed all affected passwords and codes, and it will hire outside experts to check its systems.
A threat actor broke into one of Surfshark’s internal test servers and a separate proxy server. According to the VPN company, a setup mistake left both systems open to the public internet.
Surfshark shared the news on September 9. The company said the server belonged to its engineering team. It was never meant to hold or handle customer information.
Surfshark first noticed strange activity on August 31. It confirmed the break-in on September 2 and moved fast to lock down the affected systems.
Hackers slip through a test server gap
According to Surfshark, the hacked server held pieces of system files and internal setup notes for some of its tools. Some login codes tied to the company’s build process had also shown up in its code history before.
Surfshark checked its access records closely. The company found no proof that anyone used those exposed codes. Still, it changed or shut down every code that might have been at risk, just to be safe.
The hackers also reached a second, separate server. This one worked as a proxy to help content load faster for users. Surfshark says this machine never stored user names, IP addresses, encryption keys, or browsing history.
The security news site BleepingComputer reported that the break-in touched both the test setup and the proxy server. The outlet also noted that the exposed area held service setup files, build codes, and pieces of the company’s code history.
Surfshark says customer data stayed safe
Surfshark said the hacked servers sat apart from the systems that run its actual VPN service. That gap, the company says, kept the attackers away from anything tied to customer accounts.
The company also said it never stored personal details on the affected server. Surfshark does not log or keep records of user traffic or browsing activity, either. Its apps and browser add-ons stayed untouched during the break-in.
TechRadar also looked into the incident. The outlet reported that Surfshark’s main systems stayed separate from the hacked area the whole time. TechRadar added that Surfshark’s team repeated, more than once, that user data and browsing habits were never at risk.
Surfshark’s own review backs this up. Based on its findings, the company says users do not need to do anything right now.
Company tightens security after the breach
Surfshark has already closed the gap that let hackers in. It checked other parts of its system for signs of trouble, too. The company changed or dropped every code that might have been exposed. It also added fresh monitoring tools to catch future threats sooner.
The company admitted its test systems were not as well guarded as they should have been. Because of this, Surfshark now plans to treat test and trial systems with the same care it gives its live, working systems.
Surfshark also plans to improve how it manages passwords and access codes during its build process. It wants to watch its test systems more closely from now on. The company will also toughen up the operating systems and tools those test areas use. On top of that, Surfshark will bring in outside security experts. These experts will check the safety of its whole system, not just the part that got hacked.
Nextcloud initially blamed a July 2026 outage on infrastructure problems but later confirmed a cyberattack. The company said customer servers and downloads were unaffected but could not rule out the WP2Shell WordPress flaw as the entry point.
No proof points to stolen customer data so far. Still, this case shows a real risk. Test systems left open by mistake can turn into open doors for hackers. A single forgotten server or a leaked code can sometimes lead attackers straight to bigger, more sensitive systems.
Surfshark said it will share more updates if its ongoing check turns up anything new and important. The full incident report sits on Surfshark’s own blog, where the company laid out its timeline and next steps in detail.
This case is a reminder for every company, not just VPN providers. Even a small, forgotten corner of a system can open the door to bigger trouble. Simple habits, like double-checking server settings and locking down test environments, can stop a small mistake from becoming a major breach.
For now, Surfshark says its users have nothing to worry about, and the company is using this incident to build stronger walls around the rest of its systems.