LEGAL DISCLAIMER: This platform is for authorized security research and educational purposes only. Scanning assets without permission is illegal.
HOMEBLOGSplitVPN Hacked: Data Breach Exposes 865,000 User Records and 58 Million Hidden Connection Logs (July 2026)
SplitVPN Hacked: Data Breach Exposes 865,000 User Records and 58 Million Hidden Connection Logs (July 2026)
Threat Intelligence

SplitVPN Hacked: Data Breach Exposes 865,000 User Records and 58 Million Hidden Connection Logs (July 2026)

SR
Surendra Reddy ↗ View profile
LAST UPDATED: AUG 3, 2026
13 MIN READ
492 VIEWS

You trusted a VPN to keep your activity private — but SplitVPN was secretly logging every connection you made. A 17 GB database stolen from SplitVPN's infrastructure and distributed on a cybercrime forum has confirmed what no-logs providers never want you to discover: the logs existed all along. In this briefing, you'll find every verified detail about what was exposed, who is at risk, and the exact steps to protect yourself right now.

Key Takeaways

  • SplitVPN (formerly known as NotVPN), a Russian VPN provider, suffered a confirmed data breach on July 21, 2026, affecting 865,336 unique user accounts.
  • Exposed data includes email addresses, IP addresses, geographic locations, device identifiers, partial payment card data, and subscription details.
  • 58 million connection logs — spanning June 2025 through the day of the breach — were found in the stolen database, directly contradicting SplitVPN's advertised "no-logs" privacy policy.
  • The stolen 17 GB SQL database was distributed on the Altenen cybercrime forum and independently verified by Mysterium's research team against the raw dump.
  • Users in Russia, Iran, India, and Myanmar face elevated risk because VPN usage in those regions is often tied to circumventing government censorship — making connection metadata particularly sensitive.
  • Partial payment card data was exposed, including masked card numbers, expiration dates, and recurring billing tokens — full card numbers were not included.
  • Immediate action is required: check your exposure on Have I Been Pwned, change passwords on any account that shared the email address, and enable two-factor authentication everywhere.

What Is the SplitVPN Data Breach?

The SplitVPN data breach is a confirmed security incident in which a threat actor stole and publicly distributed a 17 GB SQL database containing millions of customer records from the Russian VPN provider SplitVPN, formerly branded as NotVPN. The breach occurred on July 21, 2026. The compromised dataset was added to breach-tracking service Have I Been Pwned on August 1, 2026, officially confirming 865,336 affected accounts.

The breach stemmed from a 17 GB SQL database that a threat actor began distributing on the cybercrime forum Altenen, claiming it was stolen directly from SplitVPN's infrastructure. The database was independently examined and verified by Mysterium's research team, who confirmed that the numbers broadly matched the seller's description: roughly 23.4 million user records, 13.6 million device records, 2.6 million payment records, and 58 million connection logs. Have I Been PwnedSC Media

SplitVPN had not publicly confirmed the incident at the time of writing. This breach is now tracked in the ReconShield Vulnerability Database as part of our continuous threat intelligence monitoring. If you want to investigate SplitVPN's current domain registration and infrastructure, our WHOIS Lookup Tool returns full registrar and nameserver data in seconds.

What Data Was Exposed in the SplitVPN Breach?

The SplitVPN breach exposed a wide range of personal, financial, and behavioral data across multiple database tables, making it significantly more damaging than a typical email-and-password credential dump.

The incident exposed millions of customer records, including 865k unique email addresses. Other impacted data included IP addresses, the user's country, and partial payment card data — specifically the first 6 and last 4 digits plus expiry date. HookPhish

Beyond the surface-level personal records, the exposed information reportedly includes email addresses, recent IP addresses, device identifiers, approximate locations, subscription details, and recurring-payment tokens. Full payment-card numbers were not included, although masked card details, expiration dates, and transaction records were present. Security Affairs

Most critically, the leaked database also revealed administrative accounts with password hashes, logs of operator actions, and infrastructure details for provisioning App Store accounts. The exposure of admin-level credentials and operational infrastructure suggests the breach may extend beyond user data to the internal mechanics of how SplitVPN provisioned and managed its service — a finding with serious implications for any remaining users.

Use the ReconShield Email Security Checker to verify your domain's current authentication posture if your organization's email domain was among the exposed addresses. You can also cross-reference exposed IP addresses in our IP Intelligence Hub to understand what location and network data may be associated with your exposed records.

The "No-Logs" Lie: 58 Million Connection Records Tell a Different Story

The most damaging revelation from the SplitVPN breach is not the email addresses or partial payment data — it is the existence of 58 million device-to-server connection logs that prove the company was actively logging user activity while publicly claiming it kept no records.

SplitVPN, under its earlier NotVPN branding, explicitly advertised a "No logs or history" policy with a "100% privacy guaranteed" promise. Yet the leaked database reportedly contained a table tracking device-to-server connections, logging almost 58 million entries spanning from June 2025 through July 21, 2026 — the very day the breach dump was dated. Have I Been Pwned

The timestamps run continuously from June 2025 to July 21, 2026, the day of the dump. These aren't stale test records. The service was still writing connection logs as it was being breached. The deviceProxy table structure is simple: which device, which server, what time. Cross-referenced with the users table — which holds account emails and last-seen IP addresses — and the device table — which holds hardware identifiers — those 58 million rows are enough to reconstruct who connected, from where, to which server, and when, for tens of millions of people. SC Media

These entries do not reveal browsing destinations, but they can associate a device and account with a particular VPN server at a specific time. For users in countries where VPN usage itself is a political or legal liability, that association is not a minor inconvenience — it is a direct personal safety risk. Security Affairs

Mysterium frames the structural lesson clearly: a conventional VPN is a centralized intermediary where the provider, not the user, decides what gets logged. "No-logs" is an unauditable marketing claim backed by nothing the user can verify. When the provider logs anyway — for billing, anti-fraud, capacity planning, or less benign reasons — the user has no way to know until a 17 GB file with their email shows up on a forum. SC Media

This is precisely why independent, verifiable security assessments matter. Our guide to OSINT Fundamentals explains how researchers and threat analysts use open-source intelligence to investigate claims like "no-logs" — and how the same methods reveal when those claims cannot withstand scrutiny.

Who Is at Risk from the SplitVPN Breach?

Any individual who created an account with SplitVPN or its predecessor NotVPN between January and June 2026 should treat their associated email address, IP address, and payment details as compromised.

The affected user base is reportedly concentrated in countries including Russia, Iran, India, and Myanmar — regions where VPN usage is often tied to circumventing state censorship. For users in these jurisdictions, the risk profile extends beyond conventional identity theft. Connection logs that associate a user's identity with specific VPN servers at specific times could potentially be used to identify individuals who accessed restricted content or communicated through channels their governments monitor. Have I Been Pwned

The database also revealed administrative accounts with password hashes and logs of operator actions, as well as infrastructure details for provisioning App Store accounts — the plumbing behind distributing a VPN that Russia has been actively removing from app stores. This suggests that SplitVPN was operating in a legally complicated environment, adding another layer of uncertainty about how the stolen data may be used by the threat actor who obtained it.

For organizations whose employees may have used SplitVPN on corporate devices or networks, the exposed IP addresses and device identifiers represent a potential lateral threat surface. Run a comprehensive exposure check using the ReconShield Website Security Scanner to assess your organization's current internet-facing risk posture.

How Did This Breach Happen? The Attack Vector

The SplitVPN breach followed a pattern common to centralized service providers: a single database containing years of operational data was exfiltrated and distributed publicly before the vendor detected or disclosed the incident. While SplitVPN has not confirmed the specific attack vector, the characteristics of the dump are consistent with either a direct database compromise through a misconfigured or vulnerable endpoint, or insider exfiltration.

The 17 GB database size and its structured SQL format suggest the attacker had direct access to the backend database layer — not just an API or front-end application. The inclusion of administrative password hashes and operator action logs points to either elevated access privileges or a misconfiguration that exposed management-level database tables without additional access controls.

Understanding how attackers discover and exploit exposed database infrastructure is foundational to the attack surface management discipline. Databases exposed through misconfigured security groups, open ports, or unauthenticated API endpoints are discovered by automated scanners within minutes of exposure — a reality that applies equally to VPN providers and any other internet-facing service. Audit your own exposed services with the ReconShield Port Scanner and Vulnerability Scanner to see what an attacker would find if they targeted your infrastructure today.

Immediate Steps If You Were a SplitVPN or NotVPN User

If you used SplitVPN or its predecessor NotVPN at any point, treat your account credentials and associated email address as fully compromised and act immediately.

First, check whether your email address appears in the breach by visiting Have I Been Pwned at haveibeenpwned.com and entering the email address you used to register. The SplitVPN breach was added to the HIBP database on August 1, 2026, so results will reflect confirmed exposure.

Second, change the password on every online account that uses the same email address or password combination you used with SplitVPN. Credential reuse across services is the primary way a single breach multiplies into multiple account takeovers. Prioritize accounts with financial, healthcare, or workplace access first.

Third, enable two-factor authentication on every account where it is available — particularly email, banking, and any service that shares your SplitVPN email address. If you used NotVPN or SplitVPN, treat the associated email address and IP as compromised, change passwords everywhere that email was reused, and enable two-factor authentication. SC Media

Fourth, monitor your payment cards for unauthorized transactions. While full card numbers were not exposed, masked card details, expiration dates, and recurring billing tokens were included in the breach. Contact your card issuer if you notice any suspicious charges. Verify your domain's email authentication records — SPF, DKIM, and DMARC — are correctly configured to prevent phishing campaigns that will use this breach's email list as a targeting set. Our email spoofing prevention guide and SPF Record Complete Guide walk through exactly how to lock these controls down. You can validate your current email authentication status with the ReconShield Email Security Checker.

Fifth, if you were using SplitVPN for activities that require genuine privacy — particularly if you are in Russia, Iran, India, or Myanmar — factor into your current threat model that connection metadata records now exist outside the operator's control and may be accessible to threat actors, data brokers, or state-level entities.

What This Breach Means for the VPN Industry

The SplitVPN breach is a case study in the fundamental vulnerability of any privacy service built on unverifiable trust claims. A "no-logs" policy is worth exactly as much as the provider's willingness to enforce it and the user's ability to independently verify it — which, in a centralized VPN architecture, is zero.

The breach also illustrates the aggregation risk of centralized services. Each individual data point in the database — an email address, a device identifier, an IP address, a timestamp — may seem relatively harmless in isolation. Combined across 58 million connection log entries and cross-referenced with personal account records, they create a detailed behavioral profile for tens of millions of people. This is the core privacy risk that the VPN industry rarely discusses transparently.

For security teams evaluating VPN solutions for enterprise use, this incident reinforces the importance of requiring independently audited no-logs certifications from reputable third-party firms — not self-attested claims. It also underscores the value of monitoring your organization's DNS exposure and external attack surface continuously. Review your DNS record health with the ReconShield DNS Lookup Tool and understand your full domain footprint through the DNS Records Analysis Hub. For terminology around VPN security, zero-trust networking, and data breach classifications, the ReconShield Cyber Glossary provides concise, practitioner-oriented definitions.

What's Next: How to Evaluate a VPN Provider's Security Claims

Evaluating a VPN provider's security claims requires applying the same skepticism you would to any unaudited privacy assertion — because "no-logs" without independent verification is marketing, not a security control.

Before trusting a VPN with sensitive traffic, verify the following. Check whether the provider has undergone a third-party independent security audit within the last 12 months, and confirm the audit was conducted by a reputable firm whose report is publicly available. Verify that the audit specifically covered logging infrastructure and data retention practices — not just application-layer security. Investigate the provider's legal jurisdiction and understand what data retention obligations may apply under local law, regardless of the provider's stated policy. Research the provider's ownership history — SplitVPN's transition from NotVPN is a reminder that rebrandings can obscure prior incidents and regulatory actions.

Use OSINT tools to investigate the provider's infrastructure before committing. The ReconShield WHOIS Lookup, Subdomain Finder, and SSL Checker give you immediate visibility into a provider's registered infrastructure, certificate history, and technical configuration — the same data a security researcher would use to assess trustworthiness.

Conclusion

The SplitVPN breach is not primarily a story about a hack — it is a story about a broken promise. Eight hundred and sixty-five thousand users trusted SplitVPN with their privacy, and the company responded by secretly logging 58 million connection records that a threat actor now controls. The breach has confirmed the most important lesson in VPN security: you cannot verify what you cannot audit, and you cannot audit what a centralized provider controls entirely.

If your email address appears in this breach, act now — change your passwords, enable MFA, and monitor your payment accounts. If you are a security professional responsible for organizational VPN policy, treat this incident as the prompt for a formal provider review. And if you are building or operating any internet-facing service that makes privacy claims, understand that those claims will eventually be tested — either by an auditor you chose, or by a threat actor who did not ask permission.

Start your own infrastructure security assessment today with ReconShield's free Vulnerability Scanner, Port Scanner, Email Security Checker, and full website security scanner — no registration required.

Written by
Surendra Reddy
Cybersecurity Researcher & Founder, ReconShield
Surendra is an information security engineer specializing in OSINT methodology, internet telemetry mapping, and cryptographic domain security. He designed ReconShield to help teams manage their attack surface exposure.

Reviewed by
ReconShield Editorial Board
Verified against Have I Been Pwned breach records, Bitdefender threat analysis, Security Affairs reporting, Mysterium research findings, and SC Media briefings as of August 3, 2026.

Disclaimer: This article was initially drafted using AI assistance. However, the content has undergone thorough revisions, editing, and fact-checking by human editors and subject matter experts to ensure accuracy. All breach details have been verified against publicly confirmed sources including Have I Been Pwned, Bitdefender, Security Affairs, and Mysterium's independent database analysis.

## Analyst Commentary & Implementation Blueprint

Security advisory

Continuous security exposure assessment is critical to identifying public vulnerabilities before they are exploited. Organizations should maintain a passive inventory of all web servers, TLS configs, and open ports, ensuring that default configurations are eliminated and security advisories are actively implemented.

Hardened Security Configuration Blueprint

# General Security Hardening Directive
ServerTokens ProductOnly
ServerSignature Off
FileETag None

Actionable Mitigation Checklist

  • Perform passive asset inventories weekly.
  • Restrict administrative ports using local firewall controls.
  • Monitor active CVE alerts for exposed software.

Common Inquiries & FAQs

Why is passive scanning preferred for continuous auditing?

Passive audits do not cause operational impact or trigger firewall blocks, making them ideal for constant surveillance of internet-facing assets.

What should I do if a vulnerability is flagged?

Apply the latest vendor patches, restrict access to the resource via firewalls, or verify configuration flags to mitigate risks.

SR

Surendra Reddy

Surendra Reddy is a cybersecurity researcher and founder of ReconShield, specializing in OSINT and defensive infrastructure analysis.

Connect on LinkedIn ↗
#THREAT INTELLIGENCE

// AUDIT BRIEFING DISCUSSION (2 COMMENTS)

agent_x9 // Verified Analyst2 HOURS AGO

Great breakdown of the passive infrastructure vectors. We recently audited our external DNS zones and found multiple dangling staging environments. Implementing wildcard certificates reduced our CT log leaks significantly.

sec_analyst_015 HOURS AGO

Is there any automated tooling you recommend for daily crt.sh scraping? Manually checking CT logs is becoming unsustainable for our domain portfolio.

// POST RESPONSE BRIEFING
* Encrypted transmission via Secure Socket LayerSUBMIT BRIEFING