Privacy VPN SplitVPN Breached, Exposing User Connection Logs

What happened

According to public breach records, the SplitVPN data breach on July 21, 2026 is reported to have exposed the personal information of approximately 865,336 user accounts, along with 58 million connection logs.

In July 2026, the Russian VPN service SplitVPN—formerly known as NotVPN—suffered a massive data breach that completely contradicted its core privacy promise. A threat actor on the Altenen cybercrime forum distributed a 17 GB SQL database stolen from the service, containing roughly 23.4 million user records, 13.6 million device records, 2.6 million payment records, and critically, 58 million connection logs.

The breach is particularly damning because SplitVPN marketed itself with explicit "no-logs" guarantees. Their marketing promised: "No logs or history: We never store your activity or connection logs. 100% privacy guaranteed." The database told a different story.

The connection logs—58 million of them—recorded which device connected to which server and exactly when, stretching continuously from June 2025 to July 21, 2026, the day of the dump. These weren't stale test records; the service was actively writing connection logs as it was being breached.

The user base was concentrated in Russia, Iran, India, and Myanmar—countries where people use VPNs specifically to evade state censorship. For these users, the leaked records aren't just a privacy nuisance; they're documents that tie real people to the act of evading state controls, now circulating on criminal forums.

  • If you used SplitVPN or NotVPN, treat your email address and IP as compromised.
  • Change passwords everywhere that email was reused.
  • Enable two-factor authentication on all accounts using that email.
  • Factor into your threat model that connection metadata records now exist outside the operator's control.
  • Consider using a decentralized VPN or Tor for high-risk privacy needs.

What data was exposed

The following types of personal data were compromised:

  • Email addresses
  • IP addresses
  • Device information (hardware identifiers)
  • Geographic locations (approximate)
  • Partial credit card data (BIN + last 4 digits, expiry dates)
  • Payment history
  • Recurring billing tokens
  • Connection logs (58 million records showing device, server, and timestamp)
  • Admin account credentials (operator accounts with bcrypt hashes)

Breach details

Detail Value
Breach name SplitVPN (formerly NotVPN)
Date July 21, 2026
Disclosed July 29, 2026 (analysis), August 1, 2026 (HIBP)
Accounts affected 865,336+
Connection logs 58 million
Database size 17 GB
Domain splitvpn.io (formerly notvpn.io)

This summary is compiled from public breach-notification data and known leak databases. Figures reflect what those sources report and may be revised as more is learned. If something here looks wrong or you think your information is involved, contact our support team.

We report breaches as a factual record to help people check their exposure. Inclusion here is not an allegation of wrongdoing or negligence by SplitVPN; it reflects a publicly reported security incident.


What to do now

Based on the data exposed in this breach, here are the steps you should take:

  • If you used SplitVPN or NotVPN, treat your email address and associated IP addresses as compromised.
  • Change passwords immediately on any accounts that share the email address used for SplitVPN.
  • Enable two-factor authentication on all accounts using that compromised email.
  • Factor into your threat model that connection metadata records—contradicting the "no-logs" promise—now exist outside the operator's control and could potentially be used to reconstruct your VPN usage patterns.
  • Consider migrating to a decentralized VPN solution or Tor for high-risk privacy requirements, particularly if you relied on this VPN for circumvention of state censorship.
  • Monitor for phishing attempts, as your email, location data, and payment information are now in circulation on criminal forums.

Check your exposure

Data breaches are one of the ways your personal information ends up on data broker sites. Run a free scan to see which sites are exposing your personal data — and take action to remove it.

Sources

Find out what data brokers know about you

Run a free scan to see which sites are exposing your personal information — name, phone, address, email, and more.

Start your free scan