
A leaked database attributed to SplitVPN, formerly NotVPN, allegedly exposed user, device, payment and VPN connection metadata despite the service’s no-logs promise.
A threat actor is distributing a database alleged to come from SplitVPN, the service previously known as NotVPN. Researchers said they examined the raw file and found the record counts broadly matched the seller’s description. SplitVPN had not publicly confirmed the incident at the time of writing.
The exposed information reportedly includes email addresses, recent IP addresses, device identifiers, approximate locations, subscription details and recurring-payment tokens. Full payment-card numbers were not included, although masked card details, expiration dates and transaction records were present.
The most damaging finding is a table containing nearly 58 million device-to-server connections dated from June 2025 through July 21, 2026. These entries do not reveal browsing destinations, but they can associate a device and account with a particular VPN server at a specific time.
That distinction may offer little comfort to users in Russia, Iran, India and Myanmar, where the service was reportedly popular for bypassing internet restrictions. The incident also reinforces a broader privacy lesson: a “no-logs” promise is more credible when supported by transparent policies, data-minimization and frequent independent audits.
Former NotVPN or SplitVPN users should change reused passwords, enable two-factor authentication and monitor payment statements for unfamiliar charges. They should also distrust emails or messages that mention their VPN use, as leaked account data could make phishing and extortion attempts look convincing.
When choosing a trustworthy VPN service, consumers should examine what data it collects and whether its claims have been independently tested. Bitdefender VPN’s no-log infrastructure underwent an independent audit in 2025. Bitdefender Digital Identity Protection can also monitor exposed personal information and provide breach alerts and remediation guidance.
tags
Vlad's love for technology and writing created rich soil for his interest in cybersecurity to sprout into a full-on passion. Before becoming a Security Analyst, he covered tech and security topics.
View all posts