A Configuration Error Exposes Surfshark Internal Infrastructure

Published September 11, 2026

A misconfigured test server at Surfshark accidentally exposed internal company files and some user data. The breach did not affect real customer accounts or the main VPN service.

Report priority
Medium

What to do

If you are a Surfshark customer, check if your email or payment details were exposed. Surfshark says no passwords or VPN connection data were leaked. The company has a breach notice with details at Surfshark's official breach page.

Surfshark has fixed the test server issue and says no action is needed for customers. Monitor your accounts for unusual activity and check Surfshark's official updates for further guidance.

Reported details

Discover the details of the Surfshark test server breach. Learn how a configuration error exposed internal secrets and how the VPN provider responded.