u/Surfshark_Privacy

The EU just published the world's first official cybersecurity standard for VPNs, and we co-authored it

The European Telecommunications Standards Institute (ETSI) has just released EN 304 620, the world's first official cybersecurity standard for VPNs. It sits under the EU's Cyber Resilience Act, which will be enforced from December 11, 2027, and it defines the minimum security requirements every VPN sold in Europe will eventually have to meet.

"Until now, there were no official rules for how safe a VPN had to be. Any provider could call its app 'secure' without having to prove it. That is now changing. The shift is comparable to the arrival of safety rules for cars. Before crash tests and seatbelt laws, drivers simply had to hope their car was safe. Once official safety standards existed, every car had to meet them," says Miguel Fornés, Surfshark’s Information Security Manager.

Surfshark participated as an official ETSI Member Delegate alongside ZTE Corporation, BSI, Palo Alto Networks, Google, and Nord Security. Miguel authored and refined a lot of the rules that VPN products are now expected to follow.

A few examples of what we pushed into the standard:

  • Strict no-logs deployments on RAM-only servers;
  • Personal data stays on the device, telemetry is optional, and permanent storage of user data on servers is blocked;
  • Passwords stripped from diagnostic logs, plus a warning before users export settings that contain credentials;
  • Safe memory handling and strong encryption of stored data, protecting it even if a device is lost or stolen;
  • Automated and manual testing for known exploits before updates reach users;
  • Critical security patches installed the very first time the VPN is switched on;
  • Clear labeling of the security and privacy level for different use cases (journalists vs. households, for example);
  • Protection extended to modern, decentralized infrastructure like mesh networks.

TL;DR: for years, "secure VPN" was a marketing phrase anyone could use. Now it's a technical standard with defined requirements, and providers actually have to prove it. That's a much better world for users, whichever VPN they end up choosing.

Happy to answer questions in the comments.

u/Surfshark_Privacy — 13 hours ago

Average Market Rates for 1,000 Social Media Interactions by Platform

Methodology and sources

Pricing data were collected from SocialWick and BuzzVoice for five major social media platforms: Facebook, Instagram, TikTok, YouTube, and X (formerly Twitter). These two websites were selected because they publicly list prices for multiple types of artificial engagement across several major platforms, making them suitable for comparison. The study examined the advertised prices of artificial views, likes, shares, followers, and comments. To make the offers comparable, all prices were standardized to the cost per 1,000 interactions. When both websites offered the same interaction type, the prices were averaged and then compared across platforms. Where pricing was unavailable from one or both providers, conclusions were based only on the available data.

u/Surfshark_Privacy — 7 days ago

Nearly half of all deepfake fraud losses worldwide, $1.73 billion, originated from social media platforms.

Methodology and sources

This study used data from the AI Incident Database, Resemble.AI, and the OECD to create a combined dataset covering deepfake incidents from January 2020 to June 2026. Incidents were included if they involved the generation of synthetic videos, images, or audio; were verified by media reports; and had clearly documented financial losses.

Each deepfake incident was classified by target country and origin. These figures represent a conservative estimate based on publicly reported data, and the source databases included records of deepfake incidents across multiple languages.

If multiple countries were mentioned in an incident with a specific financial loss, that loss was divided equally among the countries involved.

To avoid double counting, each incident was assigned to one primary origin category based on the main channel, tactic, or entry point described in the source material. The categories were defined as follows:

  • Social media: cases originating on social media platforms;
  • Impersonation fraud: cases involving impersonation, synthetic facial verification videos, AI-generated face swaps, voice cloning, forged or altered IDs, fraudulent account openings, loan application fraud, or unauthorized access to wallets, bank accounts, or financial services;
  • Website: cases originating from fraudulent websites, including fake investment platforms, scam landing pages, or other web-based fraud schemes;
  • Fake job candidates: cases involving AI-generated resumes, face-swapping, deepfake video interviews, or other synthetic identity tactics used to infiltrate hiring processes;
  • Phone call: cases where deepfake-enabled voice cloning or impersonation was used during phone-based scams;
  • Video platform: cases originating on or using video platforms, including video conferencing tools or video-sharing platforms;
  • Messaging app: cases involving deepfake-enabled scams carried out through messaging applications;
  • Email: cases involving deepfake-enabled fraud delivered or initiated through email;
  • Other: cases that do not fit into the above categories, including novel schemes or unclassified methods.
u/Surfshark_Privacy — 27 days ago

Anthropic and Meta account for 81% of all AI-related fines and settlements so far — $2.9B between them

Methodology and sources

This study examined AI-related fines and settlements involving major technology companies between 2022 and 2026. We included cases where regulators or courts took formal action over the training, or marketing of AI systems. To qualify, each case had to involve a clearly identified company, a measurable penalty or settlement, and a direct link to AI-related conduct such as unlawful training on copyrighted or personal data, biometric data scraping, or misleading AI claims.

The final dataset contains 10 cases across 7 companies. For each case, we recorded the company, year, penalty amount, and stated reason for the action. We also calculated penalty amounts in both euros and the United States dollars, using a conversion rate of $1 = €0.86. Repeated penalties against the same company were counted separately when they came from different authorities. Annulled penalties were also included, but marked accordingly, to reflect the full enforcement landscape.

For the complete research material behind this study, click here.

u/Surfshark_Privacy — 1 month ago

We signed an open letter urging the UK Government to protect kids online without weakening online security for all

We’ve joined over 20 organizations in calling on the UK Government to protect children online without undermining the privacy and security tools millions of people rely on every day.

VPNs help people stay safer online — from protecting personal data on public Wi-Fi to enabling secure work, study, and access to information. Restricting them won’t solve the root causes of online harm, and it won’t meaningfully improve child safety either.

Children deserve an internet that is safe, private, and secure. Those goals should work together, not be treated as a trade-off.

Read the open letter here: https://vpntrust.net/wp-content/uploads/2026/07/VPN-Support-Open-Letter.docx.pdf

u/Surfshark_Privacy — 1 month ago

Surfshark 2025 Impact Report: what we did on emissions, digital rights, employee training, and yes, the security audits

We've had a busy year. New products, new people, new offices running on renewable energy, and a lot of behind-the-scenes work that doesn't usually make it into a product post. The Impact Report is where it’s all laid out, environmental footprint, employee wellbeing, digital rights work, and how we govern ourselves as a company.

Our 2025 Impact Report is out, and here are some of the highlights:

  • Both offices (Vilnius and Kaunas) now run on 100% renewable energy, with BREEAM "Excellent" certifications;
  • Greenhouse gas emissions measured across all three scopes, with reduction steps detailed;
  • Emergency VPN access provided to 2,500+ journalists, activists, and NGO representatives in restricted regions;
  • Every employee completed annual training on infosec, privacy, anti-bribery, anti-corruption, and workplace safety;
  • Full GDPR, UK DPA, and CCPA compliance;
  • Ongoing digital rights work with Access Now, Global Encryption Coalition, and the International Press Institute.

On the technical side, the report also covers this year's third-party audits: Deloitte re-verified the no-logs policy, Cure53 and SecuRing did assurance assessments on infrastructure and applications, the Android app passed MASA, and the network is 100% RAM-only.

Happy to answer any questions or elaborate on anything that you’ll find interesting in the report.

Full report: surfshark.com/blog/surfshark-published-impact-report-2025

u/Surfshark_Privacy — 1 month ago

Google and Apple app stores removed 2.2 million apps in 2025

New transparency reports show that Google and Apple cleared over 2.2 million apps from their stores in 2025. While Google's removals dropped to 2 million, Apple's app deletions more than doubled to nearly 167,000 as both platforms ramped up efforts against fraud and privacy violations.

Methodology and sources

This study is based on information provided in the Google Play and App Store transparency reports and supplemental data files. While the main focus is on 2025, the analysis also includes historical data going back to 2024. The exploration covers various aspects, such as the number of apps removed, the reasons for their removal, the rates of app submissions and rejections before release on the platforms, and the number of terminated developer accounts.

For the complete research material behind this study, click here.

u/Surfshark_Privacy — 2 months ago

Meet HeyPolo, a family safety app built by Surfshark. Members of this community get 30 days free

We've got something new to share. We invite you to check out HeyPolo, a privacy-first family safety app built by the team behind Surfshark.

Why was HeyPolo built?

Parents want to know their teens got home safe. Families want to stay connected. None of that requires handing your data over to advertisers.

HeyPolo helps families stay close in a way that's safe, private, and built on trust. Your location data stays yours — Heypolo will never sell it, full stop.

What you can do with HeyPolo

  • Get notified the moment your family arrives safely — no more waiting by the phone
  • Emergency SOS so your family can alert you instantly when they need help
  • Speed monitoring so you know your teenager is traveling safely
  • Low battery alerts so you're never left wondering why someone's gone quiet
  • Share an exact location, a general area, or go fully private — everyone stays in control
  • Create unlimited groups for family, friends, and whoever matters most
  • Invite anyone by link — everyone you invite to your group joins free

How HeyPolo keeps your data safe

  • SSL/TLS encryption during data transfer, AES-256 encryption at rest
  • Active firewalls and regular penetration testing
  • Your location data is never sold or shared with third parties

HeyPolo is available on iOS and Android.

HeyPolo was built by the team behind Surfshark but operates independently.

As a thank you to the Surfshark community, we're giving every one of you 30 days free. No payment details required — just enter the code and you’re in. 

Use code REDDITPOLO at checkout https://heypolo.com/checkout 

It’s still early days for HeyPolo and your feedback would mean a lot. If you try it out and want to share your thoughts and suggestions, drop HeyPolo a note at feedback@heypolo.com

reddit.com
u/Surfshark_Privacy — 2 months ago

Surfshark received PCMag's Editor's Choice badge. Here's what they said.

Hey everyone!

PCMag just published their review of Surfshark and awarded us their Editor's Choice badge. Here's what they highlighted:

  • Server network: 4,500+ servers across 100 countries
  • Dausos protocol: our proprietary protocol with quantum-resistant AEGIS-256X2 encryption got a specific callout
  • Audits: independent security audits by Cure53, Deloitte, and SecuRing
  • Privacy tools beyond the VPN: antivirus, ad blocker, data leak alerts, private search, data masking

Your feedback drives what we build. Thanks for being part of it. Full review: https://www.pcmag.com/reviews/surfshark-vpn

u/Surfshark_Privacy — 2 months ago

How to set up Surfshark with OpenVPN manual connection on Android TV/Android Box

Hey everyone! Here's a quick guide on setting up a manual OpenVPN connection on your Android TV or Android Box. This can be handy if a manual connection works better for your setup, or if you want to use Dedicated IP on Android TV before it gets added to the official Surfshark app.

You'll need your Android TV and a secondary device (phone or computer) to get started.

Part 1: Download your configuration file

  1. On your phone or computer, open the manual VPN configuration page.
  2. Go to the Locations tab and pick the server location you want to connect to.
  3. Click the download arrow next to your chosen location.
  4. Choose your protocol: UDP or TCP. We recommend UDP since it's generally faster, but you can read more about the differences here and decide what works best for you.

Part 2: Transfer the file to your TV

  1. Download the LocalSend app on both your TV and your phone/computer (available on the Play Store for Android).
  2. Open LocalSend on both devices.
  3. On your phone/computer, tap Send > File, then locate and tap the configuration file you downloaded previously.

Part 3: Connect

  1. Download the OpenVPN Connect app from the Google Play Store on your TV.
  2. Open OpenVPN Connect and tap the (+) icon in the top right corner.
  3. Tap Import and find the configuration file (it should be in your Downloads folder).
  4. Tap the imported profile, enter your credentials (you can find them here), and hit Connect. If you see any prompts, accept them.

That's it, you're connected!

If you run into any issues, drop a comment below and we'll do our best to help you out!

reddit.com
u/Surfshark_Privacy — 2 months ago

How to exclude websites from your Surfshark VPN connection on Linux

Hey everyone! If you need certain websites to work outside your VPN connection on Linux, here’s a step by step guide on how to do it.

What you'll need:

  • Terminal access on your Linux device
  • sudo or root privileges
  • The address of the website you want to exclude

Step 1: Find the website's IP address

Open your Terminal and enter:

ping -c1 <Website-Address>

Example: ping -c1 www.surfshark.com

Copy the IP address from the results (e.g. 104.18.121.34).

Step 2: Find your default gateway

Enter: netstat -rn

Look for the gateway IP at the top of the routing table. It usually starts with 192.168.x.x (e.g. 172.26.208.1).

Step 3: Create the bypass route

Enter: sudo ip route add <TheWebsiteIP> via <TheGatewayIP>

Example: sudo ip route add 104.18.121.34 via 172.26.208.1

Type your Linux password when prompted. Then visit the website and check if it shows your real IP. If it does, you're good to go.

Step 4: Remove the bypass when you don't need it anymore

Enter: sudo ip route delete <TheWebsiteIP>

Example: sudo ip route delete 104.18.121.34

Good to know:

  • You don't need to keep Terminal open. Once the route is added, it stays active.
  • The route goes away after a reboot.
  • Some websites use multiple IPs. If it's not working, try pinging the site again and adding any new IPs you get.

Hope this helps!

u/Surfshark_Privacy — 3 months ago

More than half of popular mobile browsers collect your location data.

We looked at 15 popular mobile browsers and their location data practices.

8 collect location data, 4 of those collect your precise location, and 2 (Edge and Aloha) share it with third parties.

  • Yandex (collects precise location data)
  • Chrome
  • Firefox
  • Phoenix (collects precise location data)
  • Edge (collects precise location data)
  • Aloha (collects precise location data)
  • Safari
  • Opera

Meanwhile, 7 browsers collect no location data at all, proving browsers don't need it to work:

  • Samsung Internet
  • DuckDuckGo
  • UC Browser
  • Ecosia
  • Brave
  • Mi Browser
  • Tor

Methodology and sources

For this study, we selected 15 popular mobile browsers identified in our previous research and analyzed their privacy disclosures on the Google Play Store. We examined whether each browser collects location data, whether the collected data is approximate or precise, and for what purposes mobile browsers collect this data. Data for Safari was collected from the Apple App Store and cross-referenced against Google Play Store entries, since Safari is not available on the Play Store.

The Play Store definitions of location that apply to all apps except Safari are as follows:

  • Approximate location: Yours or your device's physical location to an area greater than or equal to 3 square kilometers, such as the city you are in.
  • Precise location: Yours or your device's physical location within an area less than 3 square kilometers.

The App Store definitions of location that apply to Safari are as follows:

  • Approximate location: Information that describes your location with lower resolution than a latitude and longitude with three or more decimal places, such as from Approximate Location Services.
  • Precise location: Information that describes your location with the same or greater resolution as a latitude and longitude with three or more decimal places.

For the complete research material behind this study, click here.

u/Surfshark_Privacy — 3 months ago

Surfshark partners with Amnesty International to help detect spyware and protect human rights

We've got some news we're genuinely excited about. Surfshark is now a supporting partner of Amnesty International's Digital Forensics Fellowship (DFF).

What does the DFF do?

This program trains human rights defenders, activists, and journalists to analyze mobile devices, detect spyware, and investigate surveillance. The program launched after the Pegasus Project exposed how widely spyware was being used against civil society, and demand for this kind of training has only grown since.

Fellows learn real, hands-on forensics (Android, iOS, malware traffic analysis) and then bring that knowledge back to their communities. The 2026 edition is adding training on running secure helplines so organizations can receive and triage cases safely.

You might wonder: Surfshark doesn't offer digital forensics tools, so why support this fellowship?

The answer is simple. Our goal has always been bigger than any single product. We want people to be secure in their digital lives, and that doesn't stop at what we build.

The DFF addresses something we can't do ourselves: training the people who investigate and respond when digital rights get violated. Better protection for the most at-risk users raises the bar for everyone. Research from civil society groups on surveillance campaigns creates awareness, drives policy changes, and pushes the whole industry forward.

Privacy isn't just a product category. It's a cause, and it takes more than one organization to protect it.

You can read more about the partnership here: https://surfshark.com/blog/surfshark-partners-with-amnesty-international

u/Surfshark_Privacy — 3 months ago

TikTok makes opting out of AI training the most difficult for users

Methodology and sources

This study analyzed the 10 most popular social media platforms, ranked by Cloudflare's data on web traffic and user engagement. The focus was to determine whether users can opt out of AI training, what the default settings are, and whether opt-out options are available across regions. We downloaded the mobile applications for all platforms, with the exception of Kwai, which was not available in our region for analysis. For each accessible app, we assessed the default settings for AI training consent. Additionally, we attempted to opt out of the AI training process and quantified the difficulty by counting the number of actions required. An "action" was defined as a click, entering personal information, or toggling off consent buttons.

For Discord, Reddit, and Kwai, opt-out options were not readily identifiable within the apps, so we conducted a review of their official privacy policy pages to understand the companies' stated positions on AI model training. In the case of Reddit, we also noted publicly available information regarding partnerships with AI companies for data usage.

For the complete research material behind this study, click here.

u/Surfshark_Privacy — 3 months ago