SplitVPN leak exposes 58 million connection logs contradicting 'no logs' policy
This digest was compiled by AI from multiple sources — links to the originals are below.

A data breach at SplitVPN has exposed 58 million connection logs and millions of user records, directly contradicting the VPN's 'no logs' privacy claim. The 17 GB database, distributed on a cybercrime forum, contained 23.4 million user records and 2.6 million payment records, posing risks to users in Russia, Iran, India, and Myanmar. The leak reveals administrative accounts and operator action logs even as SplitVPN marketed itself for bypassing censorship.
Data Exposed
The stolen 17 GB SQL database, distributed via the Altenen forum and analyzed by Mysterium, includes 23.4 million user records, 13.6 million device records, and 2.6 million payment records. Nearly 58 million connection logs detail device connections to specific servers with timestamps up to the breach day. Exposed payment data contains masked card numbers, expiration dates, and recurring billing tokens, though full credit card numbers were not compromised. User emails, IP addresses, device identifiers, and approximate locations were also included.
False Privacy Promise
SplitVPN, formerly NotVPN, explicitly advertised a 'no logs' policy. The leak's connection logs directly refute this, capturing metadata that could link users to their online activity. The user base is concentrated in Russia, Iran, India, and Myanmar, where VPNs are often used to evade state censorship. Security Affairs warns the exposure may endanger dissidents and others relying on the service for anonymity, as the logs could be used by governments to identify individuals.
Administrative Exposure
Beyond user data, the database contained administrative accounts with password hashes and logs of operator actions. Infrastructure details for provisioning app store accounts were also revealed. This administrative access could allow attackers to compromise the VPN's backend systems, potentially intercepting future traffic or modifying the service. The breach highlights systemic failures in securing sensitive operational data.
What's Next
The incident may prompt regulatory scrutiny of VPN providers that claim no-logging practices. It remains unclear whether SplitVPN will notify affected users or if the data will be exploited for surveillance in high-risk regions.
1 source
SplitVPN leak exposes 58 million connection logs contradicting 'no logs' policy



