SplitVPN, formerly known as NotVPN, was reportedly breached, exposing a 17 GB SQL database containing nearly 58 million connection logs and millions of related records, undermining the provider’s public "no-logs" claims. Analysis cited by Mysterium found roughly 23.4 million user records, 13.6 million device records, and 2.6 million payment records, with connection metadata spanning from June 2025 to July 21, 2026. The leaked database was reportedly circulated on the Altenen cybercrime forum.
The exposed information allegedly includes email addresses, IP addresses, device identifiers, approximate location data, subscription status, masked payment card details, expiration dates, recurring billing tokens, and records showing which users connected to which VPN servers and when. Reports also said the dump contained five administrative accounts with bcrypt password hashes, operator action logs, and references to back-office infrastructure used for App Store account provisioning. The breach is particularly serious because SplitVPN is marketed as a censorship-circumvention service, with many users reportedly located in Russia, Iran, India, and Myanmar, raising privacy and personal safety risks for people relying on the VPN for anonymity.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
Have I Been Pwned added the SplitVPN breach to its database and reported 865,336 affected accounts tied to the incident. The reference says HIBP listed the incident as having occurred on July 21, 2026.
The exposed SplitVPN SQL database reportedly contained connection-log metadata covering activity from June 2025 through July 21, 2026, along with user, device, and payment records. The presence of these logs directly contradicted the service's public no-logs claims.
Mysterium's research team reportedly verified and analyzed the leaked SplitVPN database, identifying about 23.4 million user records, 13.6 million device records, 2.6 million payment records, and nearly 58 million connection logs. The analysis also found admin account password hashes, operator action logs, and infrastructure details.
A 17 GB SQL database allegedly stolen from SplitVPN was reportedly distributed on the Altenen cybercrime forum. The leaked data included tens of millions of user, device, payment, and connection-log records.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
7 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcemalware.news
Open sourcecyberaccord.com
Open sourcecybersecuritynews.com
Open sourcehaveibeenpwned.com
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.