SplitVPN Data Breach Exposes 865k User Records
Key Takeaways Russian VPN provider SplitVPN (formerly NotVPN) suffered a significant data breach in July 2026. The incident exposed records for approximately 865,000 unique users, including email...
Key Takeaways
- Russian VPN provider SplitVPN (formerly NotVPN) suffered a significant data breach in July 2026.
- The incident exposed records for approximately 865,000 unique users, including email addresses, IP addresses, country of residence, and partial payment details.
- The breach severely undermines SplitVPN’s “no-logs” policy, as the leaked database contained nearly 58 million connection logs.
- Users in Russia, Iran, India, and Myanmar are disproportionately affected, raising concerns about potential exposure of individuals circumventing censorship.
A substantial data breach has impacted SplitVPN, a Russian-based virtual private network (VPN) provider previously known as NotVPN, leading to the exposure of personal information for an estimated 865,000 unique users. The incident, which took place in July 2026, casts a shadow over the “no-logs” assurances frequently made by privacy-focused services, as the compromised data indicates a far greater level of data retention than the company publicly advertised.
Table Of Content
The breach in July 2026 resulted in the compromise of millions of customer records, including 865,300 distinct email addresses. According to breach-tracking service Have I Been Pwned, the security incident occurred on July 21, 2026, with the compromised dataset being integrated into its database on August 1, 2026, confirming 865,336 affected accounts.
Reports indicate that the broader breach originated from a 17 GB SQL database. A threat actor began distributing this database on the cybercrime forum Altenen, asserting it was directly exfiltrated from SplitVPN’s infrastructure. Security researchers from Mysterium subsequently acquired and validated the data dump. Their analysis confirmed it contained approximately 23.4 million user records, 13.6 million device records, and 2.6 million payment records, alongside nearly 58 million connection logs.
SplitVPN Data Breach Details
Beyond the reported email addresses, the exposed dataset includes users’ IP addresses, their country of residence, and partial payment card information. This payment data is limited to the first six and last four digits of the card, along with its expiry date. Full credit card numbers were not exposed, as the payment information within the database was masked to only show the bank identification number and the last four digits.
Additional fields reportedly present in the extensive leaked database include device identifiers, approximate geographic locations, subscription statuses, and recurring-billing tokens. The presence of these details further illustrates the extent of data collected and stored by the service.
The severity of this breach is compounded by SplitVPN’s prior marketing under the NotVPN brand, which explicitly promised a “No logs or history” policy and “100% privacy guaranteed.” Despite these assurances, the leaked database reportedly contained a table meticulously tracking device-to-server connections. This table logged almost 58 million entries, spanning from June 2025 through July 21, 2026 – the exact date attributed to the breach dump.
While these logs did not capture specific browsing destinations or visited websites, they did link individual devices and user accounts to particular VPN servers at precise timestamps. This directly undermines the anonymity users expected from the service. The continuous nature of these timestamps suggests that the service was actively recording these connection logs right up until the point of the breach.
The user base most significantly affected by this breach is reportedly concentrated in countries such as Russia, Iran, India, and Myanmar. In these regions, VPN usage is frequently employed to circumvent state-imposed internet censorship and surveillance. This geographic concentration elevates the stakes considerably, as the exposed connection metadata could potentially identify and compromise individuals who relied on SplitVPN to bypass government restrictions or surveillance.
What You Should Do
- Change Passwords: Immediately update any passwords associated with your SplitVPN or NotVPN account, especially if they have been reused on other services.
- Enable Two-Factor Authentication (2FA): Activate 2FA on all online accounts where it is available to add an extra layer of security.
- Monitor Financial Statements: Closely review bank and credit card statements for any unauthorized or unfamiliar charges.
- Beware of Phishing: Be highly vigilant for phishing attempts. Attackers could leverage the leaked account data to craft convincing, targeted social engineering messages related to your VPN usage.
- Check Exposure Status: Utilize breach-notification services, such as Have I Been Pwned, to confirm if your email address or other personal information was compromised in this incident.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.