In short: On July 21, 2026, hackers published a 17 GB database dump from SplitVPN, exposing 865,336 user accounts and 57.8 million connection log entries that the service explicitly promised never to keep. The breach directly contradicts SplitVPN's core marketing claim: "No logs or history — 100% privacy guaranteed."
What happened
The database dump, attributed to a breach of SplitVPN (formerly NotVPN), appeared on the Altenen cybercrime forum on July 21, 2026. Researchers at Mysterium Network downloaded the archive, cross-referenced it against live accounts, and independently confirmed the data was authentic.
The 17 GB archive contained 23.4 million user records, 13.6 million device records, 2.6 million payment records — and a deviceProxy table with 57.8 million rows logging which device connected to which VPN server at what time, continuously from June 2025 through the day of the breach.
For context on why no-logs is the cornerstone of VPN privacy, read our explainer What "No-Logs" Really Means.
The exact promise — and what the data showed
SplitVPN's privacy policy stated verbatim: "No logs or history: We never store your activity or connection logs. 100% privacy guaranteed."
The deviceProxy table in the leaked database is precisely the connection log the company said it never kept: timestamped records linking each device identifier to the VPN server endpoints it accessed. Mysterium researchers independently verified every figure against the raw SQL dump.
We have covered similar cases before — earlier this year free VPN apps were exposed for leaking user data. What makes the SplitVPN incident more significant is that this was a paid commercial product with active marketing, not a no-cost service with an obvious monetisation motive.
What was exposed
According to Mysterium Network and Security Affairs analysis, the leaked database contains:
- 23.4 million user records — email addresses, hashed passwords, registration IP addresses, approximate geolocation;
- 57.8 million connection log entries — device, destination server, timestamps (June 2025 – July 21, 2026);
- 13.6 million device records — including Apple push notification tokens (APNS);
- 2.6 million payment records — card BIN plus last four digits, expiry date, recurring billing tokens;
- 5 admin operator accounts with bcrypt password hashes and complete admin action logs.
The combination allows an adversary to reconstruct a user's internet activity timeline: which device, at what time, connecting through which VPN server — and therefore where that person was physically located at the time.
Steps to take if you used SplitVPN
Mysterium Network researchers recommend:
- Terminate all active sessions in the SplitVPN application immediately.
- Change your password everywhere you reused it — email, banking apps, and other sensitive accounts. A unique password limits the blast radius significantly.
- Review your payment history for unexpected charges; leaked billing tokens can enable recurring payment fraud.
- Watch for phishing emails: the database contains the email addresses of all users, making impersonation attacks from fake "SplitVPN Support" senders highly likely.
- Treat your data as compromised regardless of any official statement — or silence — from SplitVPN.
When choosing a replacement, prioritise services with independently audited no-logs policies over marketing claims. Learn how LiMP VPN handles your data on our features page or in our cybersecurity blog.
