Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > 865,000 ‘No-Logs’ VPN Users Exposed After SplitVPN Breach Reveals Hidden Connection Records
865,000 ‘No-Logs’ VPN Users Exposed After SplitVPN Breach Reveals Hidden Connection Records
Read Time:3 Minute, 33 Second

A VPN provider that built its brand on privacy is now facing hard questions after a breach exposed the very connection records it swore it never kept. SplitVPN, a Russian service that previously operated as NotVPN, has confirmed that roughly 865,000 unique user accounts were compromised in an incident that took place in July 2026 — and the leaked data suggests the company was logging far more than its marketing ever admitted.

How the Breach Came to Light

According to breach-notification service Have I Been Pwned, the underlying compromise occurred on July 21, 2026, with the stolen dataset added to its tracking database on August 1. HIBP confirmed 865,336 affected email addresses tied to the service. The breach reportedly traces back to a 17GB SQL database that began circulating on the cybercrime forum Altenen, with a threat actor claiming it was pulled directly from SplitVPN’s own infrastructure.

Independent researchers at Mysterium later obtained and verified the leaked dump. Their analysis found it contained approximately 23.4 million user records, 13.6 million device records, 2.6 million payment-related entries, and close to 58 million individual connection logs — a scale that goes well beyond what a typical “no-logs” VPN provider should ever store.

What Was Actually Exposed

Beyond email addresses, the leaked dataset reportedly includes user IP addresses, country of residence, and partial card data limited to the first six and last four digits along with expiry dates. Full card numbers do not appear to have been exposed, since payment fields were masked to the bank identification number and last four digits only. Other fields found in the wider database include:

  • Device identifiers and approximate geographic locations
  • Subscription status and recurring-billing tokens
  • A connection-log table spanning June 2025 through July 21, 2026

That connection-log table is the most damaging element of the leak. It reportedly links specific devices and accounts to particular VPN servers at exact timestamps, and its entries run continuously right up to the day of the breach — strongly suggesting the logging was active and ongoing, not a legacy artifact.

A Direct Contradiction of the “No Logs” Promise

SplitVPN, under its earlier NotVPN branding, explicitly marketed a “no logs or history” policy with a “100% privacy guaranteed” pledge. The presence of nearly 58 million timestamped connection records undercuts that claim directly. While the logs reportedly do not capture browsing destinations or the websites users visited, tying an account and device to a specific server at a specific time is often enough to undermine the anonymity a VPN is supposed to provide.

The stakes are higher than usual here because of who the affected users appear to be. The impacted user base is reportedly concentrated in Russia, Iran, India, and Myanmar — countries where VPN usage is frequently driven by a need to bypass state internet censorship or surveillance. For users in these regions, exposed connection metadata is not just an inconvenience; it could plausibly expose individuals to real-world consequences from state actors monitoring circumvention tools.

What Affected Users Should Do

Anyone who has used NotVPN or SplitVPN should assume their associated email address and IP address are compromised. Security researchers recommend the following immediate steps:

  • Change any password reused across the VPN account and other services
  • Enable two-factor authentication wherever it is supported
  • Monitor payment statements closely for unfamiliar or recurring charges
  • Watch for phishing attempts that reference VPN usage, since attackers can use the leaked account data to craft convincing, targeted lures

Users can check their own exposure through breach-notification services such as Have I Been Pwned. More broadly, the incident is a reminder that “no-logs” claims from privacy services are marketing statements, not audited guarantees — and that the only way to verify them is through independent security audits, not trust alone.

The Bigger Picture

This breach adds to a growing list of incidents where VPN providers marketed strict privacy policies that did not hold up under scrutiny. For a product category whose entire value proposition rests on trust, a breach of this scale and sensitivity is likely to renew calls for mandatory, independent no-logs audits across the VPN industry — particularly for providers serving users in high-risk, censorship-heavy regions.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on 865,000 ‘No-Logs’ VPN Users Exposed After SplitVPN Breach Reveals Hidden Connection Records, use the discussion on Forum.

>> forum community

Comments

Leave a Reply