SplitVPN breach
Your VPN Lied: SplitVPN Kept 58 Million Logs Despite Its 'No-Logs' Promise

Key Takeaway

  • 🚨 The Lie: The SplitVPN breach exposed 58 million connection logs spanning June 2025 to July 21, 2026 — the exact day the data was stolen — directly contradicting the VPN provider’s “No logs or history: 100% privacy guaranteed” promise.
  • 📊 The Scale: The SplitVPN breach affected 865,336 unique user accounts, 23.4 million user records, 13.6 million device records, and 2.6 million payment records, including masked card numbers and recurring billing tokens.
  • 🌍 The Users: The user base was concentrated in Russia, Iran, India, and Myanmar — countries where people use VPNs specifically to evade state censorship. A leaked email-plus-IP-plus-timestamp record is not an abstract privacy nuisance; it ties a real person to the act of evading state controls.
  • 🔑 The Lesson: A “no-logs” policy is worth exactly as much as the provider’s willingness to enforce it and the user’s ability to independently verify it — which, in a centralized VPN architecture, is zero.
  • ⚡ What to Do: Audit your current VPN provider’s transparency reports, demand independent audits, and switch to providers with verified no-logs policies. Your VPN privacy is only as strong as its proof.

The most damaging promise a privacy service can break is the one that defines it. The SplitVPN breach did exactly that. A 17 GB SQL database, stolen from the Russian VPN provider formerly known as NotVPN and distributed on the Altenen cybercrime forum on July 21, 2026, contained nearly 58 million connection logs — records of which device connected to which server and exactly when — running continuously from June 2025 to the very day the data dump was dated. This was not a cache of stale test records. The service was still writing connection logs as it was being breached.

The SplitVPN breach is not simply another data leak in a year already saturated with them. It is a case study in the fundamental vulnerability of any privacy service built on unverifiable trust. When a VPN promises “100% privacy guaranteed” and then keeps tens of millions of logs that can be used to reconstruct who connected, from where, to which server, and when, the promise is not just broken — it was never enforceable in the first place. And for the users in Russia, Iran, India, and Myanmar who relied on SplitVPN to read independent news, use blocked messaging apps, and speak freely, the consequences of that broken promise are not abstract. They are dangerous.

What the SplitVPN Breach Actually Exposed

Mysterium VPN’s research team obtained a copy of the stolen database, verified it against the raw dump, and confirmed the numbers. The SplitVPN breach contained roughly 23.4 million user records, 13.6 million device records, 2.6 million payment records, and 58 million connection logs. The exposed data includes email addresses, IP addresses, device identifiers, approximate geographic locations, subscription details, and recurring payment tokens from the Tinkoff payment gateway. Full credit card numbers were not present — card data was masked to BIN plus last four digits — but the linkage between a person’s email, their payment history, and a recurring billing token is enough to cause serious harm.

The deviceProxy table, which is the core of the SplitVPN breach, has a simple structure: which device, which server, what time. That is a connection log by any definition. Cross-referenced with the users table — which holds account emails and last-seen IP addresses — and the device table — which holds hardware identifiers — those 58 million rows are enough to reconstruct who connected, from where, to which server, and when, for tens of millions of people. “A VPN’s single most important promise is that it doesn’t keep the records that would let anyone reconstruct your activity,” Mysterium’s research team stated. “NotVPN kept them by the tens of millions.”

To be precise, the logs record server connections, not destination websites visited. This is metadata, not full browsing history. But metadata is exactly what “we never store your connection logs” promises not to keep. The distinction between connection metadata and browsing history is a legal technicality — for a user in Iran or Myanmar, a record proving they connected to a VPN server at a specific time is already enough to invite questioning.

Why the No-Logs Promise Is Unverifiable — and Therefore Meaningless

Here is the structural problem the SplitVPN breach exposes. A “no-logs” policy is a promise made by a company that controls the servers, the databases, and the infrastructure. There is no external auditor verifying in real time that logs are not being written. There is no cryptographic proof that a VPN provider is not recording connection metadata. The user’s only evidence that a no-logs policy is being honored is the provider’s word — and the provider’s word is only tested when a breach happens, at which point it is too late.

SplitVPN, under its earlier NotVPN branding, explicitly advertised a “No logs or history” policy with a “100% privacy guaranteed” promise on its website. The leaked database contradicts that promise completely. The deviceProxy table contained 58 million entries — not a handful of debug records, not a temporary logging spike, but a continuous stream of connection data spanning 13 months. The service was logging as actively as any conventional VPN provider, while telling its users the opposite.

This is not a problem unique to SplitVPN. Any centralized VPN service — one where the provider operates the servers and controls the infrastructure — faces the same verification gap. The user cannot inspect the server. The user cannot audit the database. The user cannot verify that the “no-logs” claim is anything more than a marketing line on a website. The SplitVPN breach is the proof that this gap is not theoretical — it has been exploited, and the users who trusted the promise are now exposed.

The Human Stakes: When a Breach Is Not Just About Privacy

The seller on the Altenen forum listed the SplitVPN breach user base as concentrated in Russia, Iran, India, and Myanmar. That is not an arbitrary demographic detail. These are countries where people reach for a VPN specifically to get around state censorship — to read independent news, to use blocked messaging apps, to speak freely without government surveillance. For those users, a leaked email-plus-IP-plus-timestamp record is not an abstract privacy nuisance, as Mysterium’s report noted. “It’s a document that ties a real person to the act of evading state controls, sitting in a file now circulating on a criminal forum.”

The admin table in the SplitVPN breach exposed five operator accounts — pavel, valerii, maria, andrei, vladislav — with bcrypt password hashes, roles, and a complete admin action log. Account creation dates run from January to June 2026. The database also contains tables pointing to back-office infrastructure for provisioning App Store accounts — the plumbing behind distributing a VPN that Russia has been actively removing from app stores. The breach, in other words, does not just expose users. It exposes the operational infrastructure of a censorship-evasion service, now sitting on a cybercrime forum accessible to anyone — including state actors who would want to identify and target those users.

For Filipino professionals who use VPNs for work, privacy, or to access geo-restricted content, the SplitVPN breach carries a different but equally important lesson. If you are using a VPN to protect your browsing history, your financial transactions, or your business communications, the question is not whether the VPN provider promises not to log your data. The question is whether you can verify that promise. And the answer, in almost every case, is no. This is why securing your broader digital identity — through strong passwords, encrypted communication, and breach response readiness — matters as much as your choice of VPN. Our guides on password manager setup and data breach response planning cover those foundations.

SplitVPN’s Response and the Credibility Gap

SplitVPN told TechRadar that while the leaked subscription metadata — including email addresses, users’ countries of origin, subscription status, masked credit card information, and device names — is authentic, the deviceProxy table is “entirely fabricated.” A company spokesperson claimed that “the third-party listing claims 58 million connection logs, but this is a fabrication added to inflate the price.” SplitVPN maintains that it does not retain such data in accordance with its no-logs policy.

The credibility of this denial is thin. Mysterium’s research team verified the database against the raw dump and confirmed the deviceProxy table structure and record count. Bitdefender, Security Affairs, and SC Media all independently reported the 58 million log figure based on their analysis of the data. The claim that a threat actor would fabricate 58 million realistic-looking connection log entries to “inflate the price” of a stolen database strains credulity — particularly when the timestamps run continuously and logically from June 2025 to the day of the breach.

This is the standard playbook for a VPN provider caught in a breach. Deny the most damaging element, admit the less damaging elements, and frame the critical findings as fabrications. It is the same pattern seen in other privacy service breaches where the provider’s business model depends on user trust — admitting that logs were kept would destroy the brand overnight. But the SplitVPN breach data is on the Altenen forum, verifiable by any security researcher who obtains a copy, and the numbers have been corroborated by multiple independent analyses.

How to Choose a VPN You Can Actually Trust

The SplitVPN breach does not mean VPNs are useless. It means the trust model for centralized VPN services is fundamentally broken, and users need to demand more than marketing promises. Here is what to look for:

1. Independent, repeated audits. The only VPN providers whose no-logs claims carry any weight are those that have been independently audited by reputable security firms — and have repeated those audits annually. A single audit from 2023 is not sufficient. Ask: when was the last audit, who performed it, and is the full report publicly available?

2. Transparency reports. A VPN provider that genuinely does not keep logs should be able to publish regular transparency reports showing how many government data requests they received and how many they could respond to. If the provider received a data request and produced records, that means logs were kept — regardless of the no-logs claim.

3. Court-tested no-logs claims. The strongest evidence a no-logs policy is real is when a VPN provider has been served with a court order, investigated by law enforcement, and produced no user data because none existed. Several providers have passed this test. SplitVPN, NotVPN, and similar services have not.

4. Open-source clients and infrastructure. If the VPN client is open-source, security researchers can inspect the code for hidden logging. If the server infrastructure is documented and auditable, the trust gap narrows. Centralized VPN services that keep their server code proprietary are asking users to trust a black box — the exact failure mode the SplitVPN breach exposed.

5. Diskless infrastructure. The most reputable VPN providers now run diskless servers — RAM-only infrastructure where all data is wiped on reboot. If the server has no disk, it cannot store logs even temporarily. This is a hardware-level guarantee that no marketing promise can match.

What to Do If You Used SplitVPN or NotVPN

If you have ever used SplitVPN or its predecessor NotVPN, take these steps immediately:

Assume your data is compromised. Your email address, IP address, device identifiers, subscription details, and masked payment card information may be in the SplitVPN breach database circulating on cybercrime forums. Treat your SplitVPN-registered email as exposed — do not use it for sensitive accounts.

Change passwords on all accounts. If you used the same email and password combination for SplitVPN and other services, change those passwords now. Use a password manager to generate unique passwords for every account. HaveIBeenPwned, which has indexed the SplitVPN breach, can tell you if your email appears in the dump.

Monitor payment card activity. While full card numbers were not exposed, masked card details, expiration dates, and recurring billing tokens were. Contact your card issuer and request a replacement card if you used a credit or debit card with SplitVPN. This invalidates the stolen billing tokens.

Switch to an audited VPN provider. If you still need a VPN, switch to a provider with independent audits, transparency reports, and diskless infrastructure. Do not accept a “no-logs” claim at face value — the SplitVPN breach proved that the claim alone is meaningless without proof. Also consider whether you need a VPN at all. For many users, securing your home WiFi and using encrypted messaging apps provides sufficient privacy without the trust risk of a centralized VPN.

Check your exposure in other breaches. The SplitVPN breach is one of many data leaks in 2026. The ITRC’s H1 2026 Data Breach Report counted 1,803 compromises in six months and 471.2 million victim notices — already more than all of 2025. Check your email against HaveIBeenPwned regularly, and have a data breach response plan ready for when — not if — your data appears in a leak.

Cybersecurity Disclaimer: This article is for informational and educational purposes only and does not constitute legal, security, or professional advice. The SplitVPN breach details are based on publicly available security research as of August 2026. Readers should verify all breach information against primary sources, including Security Affairs, Mysterium VPN, and HaveIBeenPwned, before taking action. Mention of specific VPN providers does not constitute endorsement or recommendation.

Frequently Asked Questions About SplitVPN Breach

What is the SplitVPN breach?

The SplitVPN breach is a data leak that exposed a 17 GB SQL database stolen from SplitVPN (formerly NotVPN), a Russian VPN provider, on July 21, 2026. The database contained approximately 23.4 million user records, 13.6 million device records, 2.6 million payment records, and 58 million connection logs — directly contradicting the provider’s “no-logs” privacy promise.

How many users were affected by the SplitVPN breach?

The SplitVPN breach affected 865,336 unique user accounts, according to ReconShield’s analysis. The exposed data includes email addresses, IP addresses, device identifiers, approximate locations, subscription details, and masked payment card information. The user base was concentrated in Russia, Iran, India, and Myanmar.

Did SplitVPN actually keep logs despite promising not to?

Yes. The SplitVPN breach database contained a deviceProxy table with nearly 58 million connection log entries spanning from June 2025 to July 21, 2026 — the day of the breach. SplitVPN denied the logs were real, claiming the table was “fabricated” to inflate the price, but Mysterium VPN’s research team and multiple security publications independently verified the data.

What data was exposed in the SplitVPN breach?

The SplitVPN breach exposed email addresses, IP addresses, device identifiers, approximate geographic locations, subscription status, masked credit card numbers (BIN plus last four digits), expiration dates, and recurring billing tokens. Full credit card numbers were not exposed. The 58 million connection logs recorded which device connected to which server and when — enough to reconstruct user activity patterns.

Was my data in the SplitVPN breach?

If you used SplitVPN or NotVPN at any point between June 2025 and July 2026, your data may be in the breach database. Check your email address on HaveIBeenPwned, which has indexed the SplitVPN breach. If your email appears, change passwords on all accounts associated with that email and contact your card issuer for a replacement card.

Are VPNs still safe to use after the SplitVPN breach?

VPNs are still useful privacy tools, but the SplitVPN breach proves that a “no-logs” promise alone is not sufficient. Choose VPN providers with independent audits, court-tested no-logs claims, transparency reports, and diskless RAM-only servers. Do not trust a VPN’s marketing claims without verifiable evidence — the SplitVPN breach is proof that unverified promises can be lies.

Editorial Transparency Note:This article was researched and drafted with AI assistance, then reviewed, verified, and approved by Edmon Agron. All sources have been cross-checked against original publications as of the date of publication.

Leave a Reply