SplitVPN breach reveals 58 million hidden connection logs

Vlad CONSTANTINESCU

July 30, 2026

SplitVPN breach reveals 58 million hidden connection logs

A leaked database attributed to SplitVPN, formerly NotVPN, allegedly exposed user, device, payment and VPN connection metadata despite the service’s no-logs promise.

Key takeaways

  • Researchers analyzed a 17 GB SQL database allegedly stolen from SplitVPN.
  • The dump reportedly contains 23.4 million user records, 13.6 million device records and 2.6 million payment records.
  • Nearly 58 million entries record when specific devices connected to VPN servers, but not the websites users visited.
  • Former users should secure their accounts, watch for targeted phishing and reconsider which VPN providers they trust.

SplitVPN data leak puts millions at risk

A threat actor is distributing a database alleged to come from SplitVPN, the service previously known as NotVPN. Researchers said they examined the raw file and found the record counts broadly matched the seller’s description. SplitVPN had not publicly confirmed the incident at the time of writing.

The exposed information reportedly includes email addresses, recent IP addresses, device identifiers, approximate locations, subscription details and recurring-payment tokens. Full payment-card numbers were not included, although masked card details, expiration dates and transaction records were present.

Why the no-logs contradiction matters

The most damaging finding is a table containing nearly 58 million device-to-server connections dated from June 2025 through July 21, 2026. These entries do not reveal browsing destinations, but they can associate a device and account with a particular VPN server at a specific time.

That distinction may offer little comfort to users in Russia, Iran, India and Myanmar, where the service was reportedly popular for bypassing internet restrictions. The incident also reinforces a broader privacy lesson: a “no-logs” promise is more credible when supported by transparent policies, data-minimization and frequent independent audits.

What affected users should do now

Former NotVPN or SplitVPN users should change reused passwords, enable two-factor authentication and monitor payment statements for unfamiliar charges. They should also distrust emails or messages that mention their VPN use, as leaked account data could make phishing and extortion attempts look convincing.

When choosing a trustworthy VPN service, consumers should examine what data it collects and whether its claims have been independently tested. Bitdefender VPN’s no-log infrastructure underwent an independent audit in 2025. Bitdefender Digital Identity Protection can also monitor exposed personal information and provide breach alerts and remediation guidance.

tags


Author


Vlad CONSTANTINESCU

Vlad's love for technology and writing created rich soil for his interest in cybersecurity to sprout into a full-on passion. Before becoming a Security Analyst, he covered tech and security topics.

View all posts

You might also like

Bookmarks


loader