// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-newsDTG 0600Z
ColdRecon / Breach Radar / Surfshark
Breach Record

Surfshark

DISCLOSED 2026-09-11 · MISCONFIG

Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet. The company did not specify what data was accessed or when the breach occurred. No ransomware or threat actor was named.

The record

What we know

Disclosed
2026-09-11
Attack vector
Misconfig
Sector
VPN/cybersecurity
Domain
surfshark.com
ENDPOINT INVOLVED
ColdRecon assessment

Could a positive-security control have prevented this?

Verdict · would prevent · opinion

A positive-security model that snapshots known-good configurations and rejects unauthorized changes would likely have prevented this breach by blocking the misconfiguration that exposed the server to the internet.

Our assessments are opinion, grounded in the cited public facts. Read them critically.

Sources

Cited reporting

Similar vector · recent

Other misconfig breaches on file

This page is the permanent ColdRecon entry for the Surfshark disclosure. It updates if new public reporting emerges. All tracked breaches →

Surfshark just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →