SplitVPN Data Breach Exposes 865k Users’ Personal Records

SplitVPN, a Russian VPN service previously known as NotVPN, has experienced a significant data breach, compromising the personal information of approximately 865,000 users. This incident, which occurred in July 2026, casts doubt on the company’s prior assurances of maintaining a strict no-logs policy.

The breach came to light when a threat actor began distributing a 17 GB SQL database on the cybercrime forum Altenen, claiming it was sourced directly from SplitVPN’s infrastructure. Security researchers from Mysterium analyzed the data and confirmed it contained around 23.4 million user records, 13.6 million device records, 2.6 million payment records, and nearly 58 million connection logs. Notably, the dataset included 865,336 unique email addresses, as verified by the breach-tracking service Have I Been Pwned.

Among the exposed information were users’ IP addresses, country of residence, and partial payment card details—specifically, the first six and last four digits, along with the card’s expiry date. Additional data fields reportedly included device identifiers, approximate geographic locations, subscription statuses, and recurring-billing tokens. Importantly, full credit card numbers were not disclosed; the payment data was masked to reveal only the bank identification number and the last four digits.

This breach is particularly concerning given SplitVPN’s previous claims under its NotVPN branding, where it advertised a “No logs or history” policy with a “100% privacy guaranteed” promise. Contrary to these assertions, the leaked database reportedly contained a table tracking device-to-server connections, logging almost 58 million entries from June 2025 through July 21, 2026—the date the breach data was dated. While these logs did not capture specific browsing activities, they did link devices and accounts to particular VPN servers at exact timestamps, undermining the anonymity users expected. The continuous nature of these timestamps suggests that the service was actively recording connection logs up until the breach occurred.

The majority of affected users are reportedly located in countries such as Russia, Iran, India, and Myanmar—regions where VPN usage is often employed to circumvent state-imposed internet censorship. This geographic concentration heightens the potential risks, as the exposed connection metadata could reveal individuals who relied on the service to evade government surveillance or restrictions.

Users of NotVPN or SplitVPN are advised to consider their associated email addresses and IP addresses as compromised. Security experts recommend changing any reused passwords immediately, enabling two-factor authentication where possible, and closely monitoring payment statements for unauthorized charges. Additionally, users should be vigilant against phishing attempts that reference their VPN usage, as attackers could exploit the leaked account data to craft convincing, targeted social engineering messages.

Given the breach’s scale and the sensitive nature of VPN usage data, affected individuals should check their exposure status through breach-notification services like Have I Been Pwned.

This incident underscores the critical importance of transparency and adherence to privacy commitments by VPN providers. Users entrust these services with safeguarding their online anonymity and data security. When such trust is violated, it not only compromises individual privacy but also erodes confidence in the broader VPN industry. Moving forward, VPN providers must prioritize robust security measures and clear communication to maintain user trust and ensure the protection of sensitive information.