Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
SplitVPN Data Breach Exposes 865k User Records
August 2, 2026
Cisco ASA, FTD Critical Zero-Day Vulnerability Exploited in Attacks
August 2, 2026
Brinks Home Confirms Data Breach After ShinyHunters Claim
August 1, 2026
Home/CyberSecurity News/SplitVPN Data Breach Exposes 865k User Records
CyberSecurity News

SplitVPN Data Breach Exposes 865k User Records

Key Takeaways Russian VPN provider SplitVPN (formerly NotVPN) suffered a significant data breach in July 2026. The incident exposed records for approximately 865,000 unique users, including email...

Marcus Rodriguez
Marcus Rodriguez
August 2, 2026 3 Min Read
3 0

Key Takeaways

  • Russian VPN provider SplitVPN (formerly NotVPN) suffered a significant data breach in July 2026.
  • The incident exposed records for approximately 865,000 unique users, including email addresses, IP addresses, country of residence, and partial payment details.
  • The breach severely undermines SplitVPN’s “no-logs” policy, as the leaked database contained nearly 58 million connection logs.
  • Users in Russia, Iran, India, and Myanmar are disproportionately affected, raising concerns about potential exposure of individuals circumventing censorship.

A substantial data breach has impacted SplitVPN, a Russian-based virtual private network (VPN) provider previously known as NotVPN, leading to the exposure of personal information for an estimated 865,000 unique users. The incident, which took place in July 2026, casts a shadow over the “no-logs” assurances frequently made by privacy-focused services, as the compromised data indicates a far greater level of data retention than the company publicly advertised.

Table Of Content

  • Key Takeaways
  • SplitVPN Data Breach Details
  • What You Should Do

The breach in July 2026 resulted in the compromise of millions of customer records, including 865,300 distinct email addresses. According to breach-tracking service Have I Been Pwned, the security incident occurred on July 21, 2026, with the compromised dataset being integrated into its database on August 1, 2026, confirming 865,336 affected accounts.

Reports indicate that the broader breach originated from a 17 GB SQL database. A threat actor began distributing this database on the cybercrime forum Altenen, asserting it was directly exfiltrated from SplitVPN’s infrastructure. Security researchers from Mysterium subsequently acquired and validated the data dump. Their analysis confirmed it contained approximately 23.4 million user records, 13.6 million device records, and 2.6 million payment records, alongside nearly 58 million connection logs.

SplitVPN Data Breach Details

Beyond the reported email addresses, the exposed dataset includes users’ IP addresses, their country of residence, and partial payment card information. This payment data is limited to the first six and last four digits of the card, along with its expiry date. Full credit card numbers were not exposed, as the payment information within the database was masked to only show the bank identification number and the last four digits.

Additional fields reportedly present in the extensive leaked database include device identifiers, approximate geographic locations, subscription statuses, and recurring-billing tokens. The presence of these details further illustrates the extent of data collected and stored by the service.

The severity of this breach is compounded by SplitVPN’s prior marketing under the NotVPN brand, which explicitly promised a “No logs or history” policy and “100% privacy guaranteed.” Despite these assurances, the leaked database reportedly contained a table meticulously tracking device-to-server connections. This table logged almost 58 million entries, spanning from June 2025 through July 21, 2026 – the exact date attributed to the breach dump.

While these logs did not capture specific browsing destinations or visited websites, they did link individual devices and user accounts to particular VPN servers at precise timestamps. This directly undermines the anonymity users expected from the service. The continuous nature of these timestamps suggests that the service was actively recording these connection logs right up until the point of the breach.

The user base most significantly affected by this breach is reportedly concentrated in countries such as Russia, Iran, India, and Myanmar. In these regions, VPN usage is frequently employed to circumvent state-imposed internet censorship and surveillance. This geographic concentration elevates the stakes considerably, as the exposed connection metadata could potentially identify and compromise individuals who relied on SplitVPN to bypass government restrictions or surveillance.

What You Should Do

  • Change Passwords: Immediately update any passwords associated with your SplitVPN or NotVPN account, especially if they have been reused on other services.
  • Enable Two-Factor Authentication (2FA): Activate 2FA on all online accounts where it is available to add an extra layer of security.
  • Monitor Financial Statements: Closely review bank and credit card statements for any unauthorized or unfamiliar charges.
  • Beware of Phishing: Be highly vigilant for phishing attempts. Attackers could leverage the leaked account data to craft convincing, targeted social engineering messages related to your VPN usage.
  • Check Exposure Status: Utilize breach-notification services, such as Have I Been Pwned, to confirm if your email address or other personal information was compromised in this incident.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachExploitphishingSecurityThreat

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Cisco ASA, FTD Critical Zero-Day Vulnerability Exploited in Attacks

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Best Cloud Firewall Solutions: Top 10 for 2026
August 1, 2026
HackerOne Mandates ID Verification for Bug Bounty Submissions
August 1, 2026
Arch Linux Disables AUR Package Takeovers After Malicious Commits
August 1, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us