SplitVPN Data Breach Exposes 865k Users' Personal Records, Undermining 'No-Logs' Policy
Russian VPN provider SplitVPN has suffered a major data breach, exposing personal records of 865,300 users and contradicting its own 'no-logs' policy.

Russian VPN provider SplitVPN, formerly known as NotVPN, has been hit by a significant data breach that exposed the personal records of approximately 865,300 unique users. The incident, which occurred on July 21, 2026, has cast a shadow over the company's long-standing "no-logs" policy, revealing a far greater retention of user data than publicly claimed.
The compromised dataset, obtained by security researchers and verified, includes 865,336 affected accounts, with the broader breach reportedly stemming from a 17 GB SQL database. This database contained millions of user records, device records, and payment records, alongside nearly 58 million connection logs. While full credit card numbers were not exposed, the data did include users' email addresses, IP addresses, country of residence, and partial payment card information such as the first six and last four digits of the card, along with its expiry date.
What makes this breach particularly concerning is SplitVPN's explicit "No logs or history" and "100% privacy guaranteed" policy, advertised under its previous NotVPN branding. However, the leaked database contained a table logging device-to-server connections, with almost 58 million entries dating from June 2025 up to the day of the breach. These logs, while not capturing browsing destinations, did link specific devices and accounts to VPN servers at precise timestamps, directly undermining the anonymity users expected from the service.
The threat actor began distributing the stolen data on the cybercrime forum Altenen, with security researchers from Mysterium later confirming the dump's authenticity. The affected user base is reportedly concentrated in regions like Russia, Iran, India, and Myanmar, where VPN usage is often critical for circumventing strict internet censorship and government surveillance.
This geographic concentration significantly raises the stakes for affected individuals. The exposed connection metadata could potentially identify users who relied on the VPN to bypass state-imposed restrictions or avoid government monitoring. The continuous nature of the timestamps in the logs suggests the service was actively recording this sensitive information right up until the breach occurred.
Users who have utilized NotVPN or SplitVPN are strongly advised to consider their associated email and IP addresses compromised. Security experts recommend immediate password changes for any reused credentials, enabling two-factor authentication wherever possible, and vigilant monitoring of financial statements for any unauthorized charges. Furthermore, users should be wary of potential phishing attempts that leverage this leaked data to craft convincing, targeted social engineering attacks.
Given the scale of the breach and the sensitive nature of VPN usage data, especially in regions with heavy internet censorship, affected users are urged to check their exposure status through reputable breach notification services like Have I Been Pwned. The incident serves as a stark reminder of the importance of scrutinizing VPN providers' privacy claims and the potential consequences when these promises are broken.