Menu
CYBERSECURITY NEWS

SplitVPN Data Breach Exposes 865,000 Users and 58 Million Connection Logs

Uday Patil Aug 2, 2026 5 min read 7 views
SplitVPN Data Breach Exposes 865,000 Users and 58 Million Connection Logs

Emergency Threat Alert: A catastrophic data compromise has afflicted SplitVPN (formerly branded as NotVPN), exposing approximately 865,336 unique user email addresses within a 17 GB stolen SQL database. Most damaging to consumer trust, forensic audits of the leaked repository reveal nearly 58 million secret connection logs linking specific user account identities to device IP addresses and timestamps, directly contradicting the vendor’s public guarantees of zero connection archiving.

Virtual private networks represent the fundamental operational guardrail for individuals seeking digital anonymity and enterprise employees attempting to shield critical data across unsecured Wi-Fi networks. When a privacy-focused network vendor suffers an infrastructure breach, the resulting fallout compromises user anonymity across high-risk global regions.

In this urgent diagnostic report, we break down the verified scope of the SplitVPN infrastructure intrusion, analyze the severity of exposed metadata across 23 million internal records, and outline essential mitigation protocols for impacted subscribers and corporate IT directors.


Verified Scope of the 17GB SQL Database Dump

According to verified threat intelligence tracking service Have I Been Pwned and security analysts at Mysterium who examined the leaked archive, the infrastructure intrusion occurred on July 21, 2026. A cybercrime operator subsequently initiated commercial distribution of the 17 GB database across the darknet extortion forum Altenen.

Data Record CategoryVerified VolumeExposed Technical Metadata Fields
User Account Identities23.4 Million Records865,336 unique email addresses, hashed passwords, and subscription status
Connection Activity Logs57.9 Million EntriesSource device IP, target VPN server IP, connection timestamps, and geographic country
Device Hardware Profiles13.6 Million RecordsDevice telemetry identifiers, approximate operating system, and regional routing targets
Payment Billing Tokens2.6 Million RecordsMasked credit card numbers (first 6 and last 4 digits) plus expiration dates

To study how international data compromises evolve into large-scale corporate enterprise attacks across the 2026 threat landscape, inspect our comprehensive global breach index: 2026 Major Data Breaches & Cyber Hacks Master Timeline.

The No-Logs Guarantee Fallacy: 58 Million Secret Entries

The most alarming discovery emerging from this incident involves the absolute contradiction between SplitVPN’s commercial marketing and its backend database architecture. Operating originally under the brand name NotVPN, the vendor marketed a strict “No logs or history” policy alongside a “100% privacy guaranteed” consumer pledge.

Despite these explicit commercial assurances, the stolen SQL repository contained an active connection-tracking table that systematically documented 57.9 million device-to-server connection events between June 2025 and July 21, 2026. While these logs reportedly avoided capturing direct destination browsing URLs, they definitively connected individual subscriber email identities and hardware device identifiers to precise VPN servers at exact second-by-second timestamps.

Because the affected subscriber demographic is heavily concentrated across regions including Russia, Iran, India, and Myanmar, the exposed connection metadata presents severe operational safety concerns for individuals utilizing the utility to bypass regional internet surveillance.

For verified technical protocols governing secure enterprise connectivity and defending mobile hardware from unverified data interception, read our operational guide: Device Security Audit 2026: Zero-Click Exploits & Best Defense Guide.

Actionable Safeguards for Impacted Subscribers

Any individual or organization utilizing SplitVPN or NotVPN infrastructure must proceed under the immediate assumption that associated email passwords and source IP addresses are completely compromised:

1. Immediate Password Reset Across All Shared Platforms

Subscribers must immediately alter any login credentials that mirror passwords associated with their SplitVPN accounts. Cyber syndicates routinely feed breached credential combinations into automated brute-force scripts to unlock banking profiles and corporate cloud workspaces.


2. Enforce Hardware Multi-Factor Authentication (MFA)

Activate multi-factor security barriers across primary email registries, financial management applications, and enterprise VPN gateways to block unauthorized logins even if password hashes are successfully cracked.


3. Audit Credit Card Statements and Enable Fraud Alerts

Although payment numbers were partially masked to the bank identification digits and final four numbers, threat actors frequently leverage partial credit card data to execute convincing social engineering attacks or unauthorized billing queries.

To learn how small business owners and mobile consumers can deploy zero-trust internet routing techniques without falling victim to insecure third-party software applications, study our consumer safety report: Public Wi-Fi & VPN Security: Complete 2026 Defense Guide.

Frequently Asked Questions: SplitVPN Breach

What information was exposed in the SplitVPN data breach?

The 17 GB database leak exposed 865,336 unique user email addresses, hashed account passwords, device operating telemetry, regional IP locations, partial credit card billing numbers, and nearly 58 million device connection timestamp logs.

Did the SplitVPN breach reveal internet browsing history?

The leaked database entries did not capture direct destination website URLs or individual browser searches, but they did link specific subscriber accounts and device IP addresses to dedicated VPN servers at exact connection timestamps.

How can users confirm if their SplitVPN profile was compromised?

Impacted subscribers can verify their account exposure status by submitting their associated email address into verified cybersecurity tracking portals such as Have I Been Pwned, which imported the verified dataset on August 1, 2026.


Reported by CyberUpdates365 Threat Intelligence Center

Providing continuous real-time forensic coverage of enterprise data breaches, privacy network leaks, and zero-trust corporate security protocols. All technical safeguards align strictly with NIST and CISA threat mitigation mandates. (Updated August 2, 2026)

Author

  • Uday Patil

    Cybersecurity Expert | DevOps Engineer
    Founder and lead author at CyberUpdates365. Specializing in DevSecOps, cloud security, and threat intelligence. My mission is to make cybersecurity knowledge accessible through practical, easy-to-implement guidance. Strong believer in continuous learning and community-driven security awareness.

Share Article: