bytevyte
bytevyte
Language
quick-beats

SplitVPN Data Breach: 58M Logs Belie Its No-Logs Promise

SplitVPN data breach

Few incidents show the distance between VPN marketing and reality as plainly as the SplitVPN data breach. It leaked roughly 865,000 user accounts and nearly 58 million connection records, data the provider said it never kept. Researchers at Mysterium confirmed the authenticity of the 17 GB SQL database after a threat actor distributed it on the Altenen cybercrime forum in late July 2026. Have I Been Pwned added the incident to its breach records on August 1.

The service is a Russian VPN that previously operated as NotVPN. It is marketed as a tool for bypassing internet censorship and advertises a "no-logs" policy, saying it records neither activity nor connection data. The core of the SplitVPN data breach is a database that contradicts that claim at scale: 865,336 unique accounts, 23.4 million user entries, 13.6 million device entries, and 2.6 million payment entries.

What the SplitVPN Data Breach Leaked

Leaked fields include email addresses, IP addresses, approximate location data, device fingerprints, subscription status, and recurring-billing tokens. For payment cards, the dump held only the BIN and last four digits; full card numbers did not appear.

The most damaging piece is the deviceProxy table, which records which device connected to which server and when. It holds nearly 58 million entries spanning June 2025 through July 21, 2026, the day of the breach. Entries were added right up to that date, so logging looks routine instead of a one-time misconfiguration. The table does not capture the websites users visited, but it pairs email addresses with device identifiers, connection times, and server routes.

Why the No-Logs Claim Falls Apart

Most users sit in Russia, Iran, India, and Myanmar, where the risks extend past identity theft. Connection metadata that ties a person to circumvention tools can carry serious safety implications in countries that restrict such software. The SplitVPN data breach puts that evidence in the open alongside payment details.

The incident also shows why a no-logs claim cannot be verified before purchase. Buyers have no way to inspect a provider's infrastructure, and marketing copy is no substitute for an audit. Published third-party audits, explicit data-collection policies, and a provider's legal jurisdiction are the practical safeguards. None of them protected SplitVPN's customers.

What Affected Users Should Do

Anyone caught up in the SplitVPN data breach should treat their email address and IP address as public and tied to the service. Because recurring-billing tokens were in the leak, payment credentials attached to old subscriptions deserve review. Users can check their email against Have I Been Pwned, and any password reused across services should be changed immediately.

Why this matters

The SplitVPN data breach is the clearest recent proof that a no-logs promise is only as solid as the infrastructure behind it, and consumers cannot audit that infrastructure before paying. For privacy-conscious VPN shoppers, the practical lesson is to choose providers with published third-party audits and minimal data collection. Advertising alone carried no weight here.

✔Human Verified


Researched and cross-referenced against primary sources by the Bytevyte editorial team. This article was generated with the assistance of artificial intelligence and reviewed by the Bytevyte editorial team.