SplitVPN Data Breach Exposes 865,000 Users, Raising Questions Over VPN No-Logs Claims
SplitVPN has suffered a data breach affecting more than 865,000 users. Researchers say the leaked database included customer records and VPN connection metadata, raising fresh questions about the provider's advertised no-logs privacy policy.
Xcademia Team
Xcademia Research Team

Introduction
A major data breach involving Russian VPN provider SplitVPN has exposed the personal records of more than 865,000 users, according to breach notification service Have I Been Pwned (HIBP). The incident has drawn widespread attention because researchers claim the leaked database contains connection metadata that appears inconsistent with the provider's previously advertised "no-logs" policy.
The breach reportedly occurred in July 2026, while HIBP added the incident to its public breach database on 1 August 2026, allowing affected users to verify whether their email addresses were compromised. According to HIBP, approximately 865,336 unique accounts were affected.
Although data breaches involving VPN providers remain relatively uncommon compared with other online services, they are particularly significant because users often rely on VPNs to protect their identity, conceal their IP addresses, and enhance online privacy. Any evidence suggesting the retention of connection metadata can therefore have implications extending beyond a conventional customer information breach.
The incident also highlights a broader challenge facing the VPN industry: balancing operational requirements with increasingly strict privacy promises marketed to security-conscious consumers.
Key Developments
According to publicly available reporting, the leaked database was allegedly distributed on the cybercrime forum Altenen after a threat actor claimed to have stolen it from SplitVPN's infrastructure.
Security researchers from Mysterium reportedly analysed the leaked SQL database and stated that it contained:
Approximately 23.4 million user records
Around 13.6 million device records
Roughly 2.6 million payment records
Nearly 58 million VPN connection logs
These figures originate from researchers' analysis of the leaked dataset and have not been independently confirmed by SplitVPN through a public statement at the time of writing.
According to HIBP, the verified breach affects 865,336 unique email addresses, making it one of the larger VPN-related exposure events publicly documented this year.
Among the information reportedly exposed were:
Email addresses
IP addresses
Country information
Device identifiers
Subscription status
Partial payment card information (first six and last four digits)
Card expiry dates
Billing tokens
VPN connection metadata
Researchers noted that full payment card numbers were not included in the leaked database.
One of the most notable findings involves the reported presence of VPN connection logs spanning from June 2025 until 21 July 2026. According to the analysis, these records linked user accounts and devices with specific VPN servers and timestamps but did not include browsing history or destination websites.

Technical Breakdown
Based on the available research, the leaked dataset appears to extend beyond standard customer account information and includes operational records associated with SplitVPN's service infrastructure. While the company has not publicly released technical details about the incident, the reported contents provide insight into the types of information that may have been stored.
Researchers from Mysterium reported that the leaked SQL database contained multiple tables covering users, devices, payments, subscriptions, and VPN connection events. Together, these datasets allegedly represented millions of records collected across different components of the provider's backend systems. These findings are based on the researchers' examination of the leaked database and have not been independently confirmed by SplitVPN.
What Was Reportedly Exposed?
According to the published analysis, the compromised database included several categories of information:
1. User Account Information
Email addresses
Account identifiers
Subscription details
Country information
2. Device Metadata
Device identifiers
Device-to-account relationships
Registered VPN clients
3. Payment Information
Masked payment card numbers
Card expiry dates
Recurring payment tokens
Importantly, researchers stated that complete payment card numbers were not present in the leaked data. Instead, payment records contained only the Bank Identification Number (BIN), the last four digits of payment cards, and expiry dates.
Although this significantly reduces the immediate risk of direct card fraud, the exposed information could still be valuable for phishing campaigns or account verification attacks.
Connection Logs Draw the Most Attention
The most controversial aspect of the incident concerns the reported VPN connection logs.
SplitVPN, previously operating under the NotVPN brand, had promoted a "No logs or history" policy alongside marketing statements promising complete privacy.
However, researchers claim the leaked database contained approximately 58 million connection records documenting:
Device identifiers
Account associations
VPN server identifiers
Connection timestamps
Session-related metadata
According to the analysis, these records did not include:
Websites visited
DNS queries
Browsing history
Online activity after the VPN connection was established
This distinction is important.
The reported logs do not indicate that users' browsing behaviour was recorded. Instead, they appear to document connection metadata, identifying which account connected to which VPN server and when.
From a privacy perspective, however, metadata can still be highly sensitive. While it may not reveal the content of internet activity, it can establish patterns of usage, device activity, and account behaviour over time.
Why Metadata Matters
Privacy experts have long argued that metadata can sometimes reveal nearly as much as content itself.
Connection timestamps can help establish:
When users were online
Which VPN locations they selected
How frequently accounts were used
Whether multiple devices belonged to the same individual
For users relying on VPNs for anonymity, especially in regions with internet restrictions, this type of information may carry significant privacy implications even without browsing histories.
The reported timestamps also suggest that the connection records were continuously updated until 21 July 2026, the same date associated with the leaked database.
If accurate, this finding raises questions about how SplitVPN interpreted its "no-logs" policy and whether the retained operational metadata aligned with users' expectations.
Infrastructure Questions Remain
At the time of writing, several important technical questions remain unanswered.
SplitVPN has not publicly disclosed:
How attackers gained access to its systems.
Whether the database was exposed through a server misconfiguration, credential compromise, or another attack vector.
Whether encryption protected stored records.
How long the attackers maintained access.
Whether additional internal systems were affected.
Without an official incident report, the precise root cause remains unknown.
This lack of transparency makes it difficult for independent researchers and affected users to fully assess the incident's scope and the effectiveness of the provider's security controls.
Source Facts vs Editorial Analysis
1. Source Facts
The available reporting confirms:
Have I Been Pwned lists 865,336 affected accounts.
Researchers report analysing a leaked SQL database allegedly originating from SplitVPN.
The reported database included user, payment, device, and connection-related information.
SplitVPN previously advertised a "No logs or history" policy.
Researchers claim the leaked dataset contained VPN connection metadata.
2. Editorial Analysis
The reported presence of connection metadata is likely to become the most closely examined aspect of this breach.
Many VPN providers distinguish between activity logs and operational logs, retaining limited connection information for service reliability, abuse prevention, or billing while avoiding storage of browsing histories.
The challenge is that users often interpret "no logs" as meaning no identifiable records whatsoever. When marketing language lacks clear explanations of what metadata is retained, breaches like this can undermine customer trust even if browsing activity itself was never recorded.
For enterprises and privacy-focused users, this incident reinforces the importance of evaluating a VPN provider's independently audited privacy practices rather than relying solely on marketing claims.

Industry Impact
The SplitVPN breach extends beyond a single service provider. It highlights broader questions about how VPN companies implement privacy commitments, secure customer data, and communicate their logging practices.
For many users, a VPN is purchased with the expectation that it will minimise the amount of identifiable information retained. While providers often require some operational data to deliver and maintain their services, the incident demonstrates how retained metadata can become valuable if an attacker gains access to internal systems.
1. Impact on Individual Users
According to the reported analysis, the exposed information includes email addresses, IP addresses, device information, subscription details, and masked payment data. Although full payment card numbers were reportedly not included, the combination of exposed fields could increase the risk of:
Targeted phishing campaigns
Credential-stuffing attacks against accounts using reused passwords
Social engineering based on knowledge of VPN usage
Account takeover attempts using exposed email addresses
Security experts recommend that affected users:
Change passwords that were reused across multiple services.
Enable multi-factor authentication (MFA) wherever available.
Monitor financial statements for suspicious activity.
Be cautious of unsolicited emails referencing VPN subscriptions or account verification.
Check whether their email address appears in breach-notification services such as Have I Been Pwned.
2. Challenges for VPN Providers
The incident is also likely to increase scrutiny of the VPN industry's privacy practices.
Many providers advertise "no-logs" policies, but the term is not always used consistently across the industry. Some vendors define it as not storing browsing history, while others extend it to include connection metadata or IP address records. Without clear technical explanations or independent audits, customers may struggle to understand what information is actually retained.
This breach reinforces the importance of:
Transparent privacy documentation
Independent security and privacy audits
Strong encryption of stored customer data
Data minimisation practices
Secure infrastructure monitoring and access controls
Providers that can demonstrate independently verified logging practices may be better positioned to maintain user trust following incidents of this nature.
3. Implications for Enterprises
Although SplitVPN primarily serves individual users, the incident offers valuable lessons for organisations evaluating VPN services for employees or contractors.
Enterprise procurement teams increasingly assess vendors not only on features and performance but also on:
Security architecture
Data retention policies
Incident response capabilities
Compliance certifications
Independent audit reports
A provider's published privacy policy should align with its technical implementation. Organisations may also consider requesting documentation that explains what operational data is retained and for how long.
Why This Matters
1. Source Facts
The confirmed facts indicate that:
More than 865,000 user accounts were affected, according to Have I Been Pwned.
Researchers reported that the leaked database contained user, device, payment, and connection-related records.
SplitVPN had previously promoted a "No logs or history" policy.
The company had not publicly disclosed detailed technical information about the breach at the time of writing.
2. Editorial Analysis
The incident reflects a broader trend in cybersecurity: privacy commitments are increasingly expected to be supported by technical evidence rather than marketing language alone.
In recent years, many VPN providers have invested in:
Independent no-logs audits
RAM-only server architectures
Transparency reports
Bug bounty programmes
External security assessments
These measures are intended to demonstrate that privacy claims can be independently verified rather than simply asserted.
For users, the SplitVPN incident serves as a reminder that trust in a privacy service depends not only on encryption technology but also on governance, infrastructure security, and clear disclosure of data retention practices.

Challenges and Considerations
The SplitVPN incident underscores several challenges facing VPN providers and the broader privacy industry:
Balancing functionality and privacy: Some operational data may be necessary for service delivery, but providers should clearly explain what is collected and why.
Infrastructure security: Even limited metadata can become sensitive if backend systems are compromised.
Transparency: Marketing claims should accurately reflect technical implementation and be supported by independent verification where possible.
Regulatory expectations: As privacy regulations evolve, organisations may face greater scrutiny regarding data retention, security controls, and breach disclosure.
Without an official post-incident report from SplitVPN, important questions about the attack vector, security controls, and remediation efforts remain unanswered.
Future Outlook
The SplitVPN breach is likely to encourage both users and organisations to take a closer look at how VPN providers substantiate their privacy claims.
The incident reflects a growing industry shift toward independently audited privacy practices and greater transparency around data retention. Future adoption decisions may increasingly depend on whether providers can demonstrate that their operational practices align with their published policies.
For VPN vendors, the breach serves as a reminder that protecting user trust requires more than strong encryption. It also depends on secure infrastructure, clear communication, and responsible handling of customer data.
Conclusion
The reported breach affecting SplitVPN has exposed the personal information of more than 865,000 users, according to Have I Been Pwned, while researchers claim a broader leaked database contained millions of user, device, payment, and VPN connection records.
Although the reported connection logs did not include browsing histories, their alleged existence has raised important questions about how "no-logs" policies are defined and implemented. At the time of writing, SplitVPN has not publicly released a detailed technical explanation of the incident.
For individuals, the breach reinforces the need to use unique passwords, enable multi-factor authentication, and remain vigilant against phishing attempts. For VPN providers and enterprise buyers, it highlights the growing importance of independently verified privacy practices, transparent data retention policies, and robust infrastructure security.
As privacy expectations continue to rise, organisations offering security and anonymity services will face increasing pressure to ensure that their technical practices match the promises they make to users.
Source: haveibeenpwned
About the Author