A major security incident has affected SplitVPN, a Russian VPN service formerly branded as NotVPN, compromising the personal details of approximately 865,000 users.
This breach, which took place in July 2026, has sparked renewed debate over the trustworthiness of VPN providers’ no-logs policies. Despite assurances of minimal data retention, the incident has shown otherwise, revealing a discrepancy between public claims and actual practices.
Details of the Incident
SplitVPN’s security compromise was first detected on July 21, 2026, as reported by Have I Been Pwned, a breach-tracking platform. The breached data was added to their database by August 1, 2026, confirming the exposure of 865,336 user accounts.
The breach originated from a 17 GB SQL database, which began circulating on the cybercrime forum Altenen. This database was alleged to have been directly extracted from SplitVPN’s servers, containing millions of user-related records.
Scope of the Breach
According to investigations by Mysterium, the leaked data included approximately 23.4 million user records, 13.6 million device records, and 2.6 million payment records. Additionally, nearly 58 million connection logs were part of the data dump.
Beyond email addresses, the exposed information included users’ IP addresses, countries of residence, and partial payment card details. While full credit card numbers were not leaked, basic details such as bank identification numbers were revealed.
Implications for Privacy
The breach is particularly troubling given SplitVPN’s previous claims under the NotVPN name, which promised a strict no-logs policy. However, the leaked data showed detailed logs of device-to-server connections, with timestamps that challenge the anonymity users were assured.
The affected users primarily reside in countries like Russia, Iran, India, and Myanmar, where VPNs are often used to bypass governmental internet controls. The exposure of connection metadata in these regions could potentially put users at risk.
Users of NotVPN or SplitVPN are advised to consider their email and IP addresses compromised. It is crucial to change passwords, enable two-factor authentication, and monitor financial statements for any unauthorized transactions.
Additionally, users should be vigilant against phishing attempts that may exploit this leaked information, as attackers can craft targeted scams using the compromised data.
To assess their risk, affected individuals are encouraged to use services like Have I Been Pwned to check their exposure and take appropriate security measures.
