High cybersecurity update: SplitVPN Data Breach Exposes 865k Users’ Personal Records. NetworkFix reviewed the available source material to summarize the security issue, its potential impact and the defensive actions administrators should prioritize.
What Happened
A significant data breach has hit SplitVPN, a Russian VPN provider formerly known as NotVPN, exposing the personal records of roughly 865,000 unique users. The incident, which occurred in July 2026, has raised fresh concerns about the reliability of “no-logs” promises made by privacy-focused services, since the exposed data reveals far more retention than the […] The post SplitVPN Data Breach Exposes 865k Users’ Personal Records appeared first on Cyber Security News . SplitVPN Data Breach Exposes 865k Users' Personal Records A significant data breach has hit SplitVPN, a Russian VPN provider formerly known as NotVPN, exposing the personal records of roughly 865,000 unique users. The incident, which occurred in July 2026, has raised fresh concerns about the reliability of “no-logs” promises made by privacy-focused services, since the exposed data reveals far more retention than the company publicly claimed. In July 2026, SplitVPN suffered a breach that led to the exposure of millions of customer records, including 865,300 unique email addresses. According to breach-tracking service Have I Been Pwned , the incident occurred on July 21, 2026, and the compromised dataset was added to its database on August 1, 2026, confirming 865,336 affected accounts. The wider breach reportedly stemmed from a 17 GB SQL database that a threat actor began distributing on the cybercrime forum Altenen, claiming it was stolen directly from SplitVPN’s infrastructure. Security researchers from Mysterium later obtained and verified the dump, confirming it contained approximately 23.4 million user records, 13.6 million device records, and 2.6 million payment records, alongside nearly 58 million connection logs.
Technical Details
Beyond the headline email figure, the exposed dataset includes users’ IP addresses, their country of residence, and partial payment card information limited to the first six and last four digits, along with the card’s expiry date. Additional fields reportedly present in the broader leaked database include device identifiers, approximate geographic locations, subscription status, and recurring-billing tokens. Notably, full credit card numbers were not exposed, since payment data in the database was masked down to the bank identification number and last four digits. What makes this breach particularly damaging is that SplitVPN, under its earlier NotVPN branding, explicitly advertised a “No logs or history” policy with a “100% privacy guaranteed” promise. Yet the leaked database reportedly contained a table tracking device-to-server connections, logging almost 58 million entries spanning from June 2025 through July 21, 2026, the very day the breach dump was dated. These logs did not capture browsing destinations or visited websites, but they did link specific devices and accounts to particular VPN servers at exact timestamps, undermining the anonymity users expected. The continuous nature of the timestamps suggests the service was actively writing these connection logs right up until the breach occurred. The affected user base is reportedly concentrated in countries including Russia, Iran, India, and Myanmar, regions where VPN usage is often tied to circumventing state internet censorship. This geographic concentration raises the stakes considerably, as exposed connection metadata could potentially expose individuals who relied on the service to bypass government surveillance or restrictions.
Security Impact
Organizations using the affected technology should treat the report according to its high severity classification. Anyone who used NotVPN or SplitVPN should treat their associated email address and IP address as compromised. Security experts recommend changing any reused passwords immediately, enabling two-factor authentication wherever possible, and closely monitoring payment statements for unfamiliar charges. Users should also remain cautious of phishing attempts that reference their VPN usage, since attackers could exploit the leaked account data to craft convincing, targeted social engineering messages. Given the breach’s scale and the sensitive nature of VPN usage data, affected users should check their exposure status through breach-notification services like Have I Been Pwned . Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments. Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026) An SOC Story of Why Fast Answers Beat Perfect Answers in Cyber Incident Response How DCSync Attack Helps Hackers Steal Password Hashes Silently from Active Directory Top 10 Malware Used by Hackers Between July 20-26, 2026, to Launch Cyberattacks Ransomware Gangs Attack Palo Alto, Fortinet, Citrix, and Check Point VPNs to Target Corporate Networks Hackers Turned a Trusted Advertising Platform Into a Crypto-Stealer Delivery Network Arch Linux Disables AUR Package Takeovers as Attackers Push Malicious Commits HackerOne Mandates ID Verification for Bug Bounty Submissions CMMC Phase II Is Paused, But Contractors’ Data-Security Obligations Are Not Security in the AI Era Starts with First Principles Planning Your AI Security – How will You Manage All Your Resources?
Recommended Actions
- Identify whether the affected product, service or software is present in the environment.
- Review the original vendor or research advisory and verify affected versions before making configuration changes.
- Apply vendor-provided security updates or mitigations as soon as operationally practical.
- Review relevant security logs and monitoring alerts for signs of suspicious activity associated with the reported issue.
- Use the CVE identifiers, where available, to validate exposure through vulnerability-management and asset-inventory tools.
Security Details
- Severity: High
- Original source: Cybersecurity News
Why This Matters
Cybersecurity teams should use reports like this as an input to risk-based vulnerability and threat management rather than relying on headline severity alone. Exposure depends on whether the affected technology is deployed, reachable by an attacker and protected by compensating controls. Confirming asset ownership, affected versions and available vendor fixes helps teams prioritize remediation while avoiding unnecessary emergency changes.
Original Report
NetworkFix recommends reviewing the complete original report from Cybersecurity News for the authoritative technical context, affected versions, indicators and vendor-specific remediation details: Read the original report.