SplitVPN Breach Exposes 865,000 Emails as 58 Million Log Claim Challenges No-Logs Promise

Abeerah Hashim  - Security Expert
Last updated: September 7, 2026
Share
  • Have I Been Pwned’s log shows 865,336 email addresses leaked in the SplitVPN breach.
  • Researchers say one leaked database contains almost 58 million VPN connection records, but SplitVPN says those records are fake.
  • The confirmed leak includes emails, IP addresses, device data, locations, and partial payment card data.

The Russian VPN service, SplitVPN, is under scrutiny again regarding its privacy claims after a huge database turned up at a cybercrime forum. SplitVPN, formerly NotVPN, experienced a data breach in July 2026.

A leaked database tied to the service is about 17GB in size. It holds millions of user, device, and payment records, according to researchers. The most serious claim involves almost 58 million connection records.

Mysterium’s research team says the records show which device used which VPN server and when. If true, that would conflict with SplitVPN’s no-logs promise. But SplitVPN rejects that claim. The company says some leaked account data is real. It says the 58 million connection records did not come from its systems.

The breach exposed more than emails

Have I Been Pwned lists SplitVPN as a confirmed breach. Its entry says 865,336 unique email addresses leaked. It also lists IP addresses, user countries, device data, and partial payment card data.

That figure is much smaller than the number of user records reported by Mysterium. The two figures measure different things. Mysterium says the leaked database contains about 23.4 million user records. It also found 13.6 million device records and 2.6 million payment records.

Mysterium also found a table called deviceProxy. The research team says it holds nearly 58 million records. Every record basically links a device to a VPN server and has a timestamp too.  All these records cover June 2025 through July 21, 2026—which, interestingly, is when the breach happened.

SplitVPN says the 58 million logs are fake

SplitVPN has challenged the main finding. The company told TechRadar that parts of the leaked subscription data are genuine. That includes emails, countries, subscription status, device names, and masked payment data. But the company says the deviceProxy table is not real.

SplitVPN says those who listed the 58 million records did so deliberately to make the stolen database look more valuable. It also says its systems do not create or keep records that link a device, VPN server, and time.

The company says it took action after the breach. It changed server IP addresses and rotated key login and security data. It also closed the flaw and hired outside security experts to review its systems.

So, two facts should stay separate. The SplitVPN breach is real. But the claim about 58 million connection logs hasn’t been validated yet. That distinction matters because the 58 million figure has spread widely as a confirmed fact.

SplitVPN still makes a no-logs promise

SplitVPN’s website says it does not keep activity or connection logs. The service also uses the phrases “No logs and history” and “100% privacy guaranteed.”

A VPN connection log does not show every website a person visited. It’s not the same as a full browsing history. It may still provide valuable information. For instance, the record would state that one device had connected to the VPN server at a particular time. If other data links that device to an account, the record becomes more revealing.

Moreover, the leak may contain information on the account emails, IP addresses, device details, as well as geolocation information. If the records prove to be true, such information will allow an attacker to create a history of the user’s activity via the VPN.

Why the leak could hurt users

The reported database includes users from Russia, India, Iran, and Myanmar, according to the leak analysis. Those markets matter. People mostly use VPNs in places where you can’t access certain sites or say whatever you want online because of government blocks and restrictions.

Email leaks can lead to spam and phishing. An email linked to an IP address, device, location, and payment record can reveal much more. It gives an attacker several pieces of the same person’s digital trail.

The risk would rise again if the disputed connection records prove real. Such records would not show the exact pages a person viewed. They could still show when a device used a VPN and which VPN server it reached.

The case shows the limits of “no logs”

A similar data exposure involving Russian ticketing platform Kassy.ru highlights how personal data from Russian services can be weaponized. In April 2023, pro-Ukrainian hacker groups C.A.S. and UHG leaked nearly 14 million records from the platform, including full names, email addresses, phone numbers, and hashed passwords.

The SplitVPN case also raises a wider issue. A VPN provider controls its own servers and databases. Users usually cannot see what those systems record. That means a no-logs claim often starts with trust.

An outside audit can provide more proof. It can check whether a provider’s systems match its privacy claims at the time of the audit. It cannot promise that a company will never change those systems later.

The confirmed breach already shows that SplitVPN held sensitive customer data. If the disputed connection records are genuine, they could turn a serious database breach into a much deeper privacy failure.

What SplitVPN users should do now

Anyone who used SplitVPN or NotVPN should treat the exposed account data as at risk.

First, check the email address used with the VPN against Have I Been Pwned. Its SplitVPN listing covers 865,336 addresses.

Make sure to change any passwords you reused on the VPN and other sites and turn on 2FA for your important accounts.

Users who paid for SplitVPN should also watch their payment accounts. According to data from Have I Been Pwned, the breach exposed partial card data, which includes both the first six and last four digits as well as card expiry date.

Be careful with emails that mention the breach. Attackers may use the incident to send fake warnings or password reset links.

Most of all, do not treat a “no-logs” label as proof by itself. The SplitVPN incident does not prove that the company secretly stored 58 million connection logs. SplitVPN says those records are fake. But the confirmed breach is still a major privacy event.

For a service built around privacy, losing sensitive customer data is a serious warning.

Share this article

About the Author

Abeerah Hashim

Abeerah Hashim

Security Expert

Abeerah is a passionate technology blogger and cybersecurity enthusiast. She yearns to know everything about the latest technology developments. Specifically, she’s crazy about the three C’s; computing, cybersecurity, and communication. When she is not writing, she’s reading about the tech world.

More from Abeerah Hashim

Comments

No comments.