A major SplitVPN data breach has exposed the personal records of roughly 865,000 unique users, raising fresh concerns about privacy promises made by VPN providers. SplitVPN, formerly known as NotVPN, is now facing scrutiny because the leaked data suggests it retained far more information than its public “no-logs” claims implied.
The breach matters because VPN users trust these services with highly sensitive metadata, often to avoid tracking, censorship, or surveillance.
Key Details
According to Have I Been Pwned, the incident occurred on July 21, 2026 and was added to its database on August 1, 2026, confirming 865,336 affected accounts. The wider breach reportedly came from a 17 GB SQL database that a threat actor began distributing on the cybercrime forum Altenen.
Researchers from Mysterium later obtained and verified the dump, confirming it contained:
- About 23.4 million user records.
- About 13.6 million device records.
- About 2.6 million payment records.
- Nearly 58 million connection logs.
Beyond the email count, the exposed dataset included:
- IP addresses.
- Country of residence.
- Partial payment card data.
- Device identifiers.
- Approximate geographic locations.
- Subscription status.
- Recurring-billing tokens.
Full card numbers were not exposed, but the retained metadata is still highly sensitive.
Technical Analysis
What makes this breach especially damaging is the gap between marketing and reality. SplitVPN, under its NotVPN branding, advertised a “No logs or history” policy with “100% privacy guaranteed.” Yet the leaked database reportedly contained a table tracking device-to-server connections.
Those logs covered nearly 58 million entries from June 2025 through July 21, 2026, the same day the breach dump was dated. While the logs did not record browsing destinations or visited websites, they did link specific devices and accounts to specific VPN servers at exact timestamps.
That is enough to undermine the anonymity users expected. If an attacker can connect a device, account, and location to a server at a particular moment, the privacy value of the service drops sharply.
Why It Matters
The exposure is particularly serious for users in countries where VPNs are often used to bypass censorship or surveillance. The affected user base reportedly includes people in Russia, Iran, India, and Myanmar.
That geographic concentration increases the stakes because connection metadata could potentially reveal who was using the service, when, and from where. Even if browsing content was not exposed, the metadata alone could put users at risk of profiling or targeting.
The breach also damages trust in “no-logs” marketing across the VPN industry. If a provider says it keeps no history but retains large-scale connection logs, users have little way to assess the real privacy risk.
Expert Recommendations
Anyone who used NotVPN or SplitVPN should assume that their associated email address and IP address may be compromised. The most important next steps are basic but urgent.
Recommended actions:
- Change reused passwords immediately.
- Enable two-factor authentication wherever possible.
- Review payment statements for unfamiliar charges.
- Watch for phishing emails referencing VPN usage.
- Check breach status through Have I Been Pwned.
- Assume connection metadata may be linkable to your identity.
- Move sensitive activity to a more trustworthy provider if you still need VPN access.
Security-conscious users should also avoid reusing the same email address across privacy services, financial accounts, and personal logins.
Industry Context
This breach is a reminder that privacy tools are only as trustworthy as the data practices behind them. VPN services often promise anonymity, but if they store connection metadata, billing tokens, or device identifiers at scale, a breach can expose the very users who relied on them for protection.
It also shows why transparency matters. Users do not just need encryption; they need credible retention limits, independent audits, and clear disclosure about what is actually logged.
Conclusion
The SplitVPN breach is a significant privacy incident because it exposed both user records and large-scale connection logs, despite public no-logs claims. For affected users, the safest response is to treat their email and IP data as compromised and tighten account security immediately.
FAQ SECTION
What was exposed in the SplitVPN breach?
The breach exposed user records, device data, payment information, and nearly 58 million connection logs.
How many users were affected?
Have I Been Pwned says 865,336 accounts were affected.
Why is the breach especially concerning?
Because SplitVPN marketed a no-logs policy, yet the leaked database appears to contain extensive connection metadata.
Did the breach expose browsing history?
No browsing destinations were reported in the logs, but devices and VPN servers were linked by timestamp.
What should users do now?
Change reused passwords, enable MFA, monitor payments, and check exposure through breach-notification services.