In July 2026, SplitVPN, a Russian VPN provider previously known as NotVPN, experienced a significant data breach that exposed personal records of about 865,000 users. This breach has brought into question the reliability of the company's 'no-logs' privacy claims. The incident came to light when the breached data, consisting of 865,336 affected accounts, was identified by breach-tracking service Have I Been Pwned on July 21, 2026, and subsequently added to its database on August 1, 2026.

The breach involved a 17 GB SQL database, reportedly stolen from SplitVPN's infrastructure and distributed by a threat actor on the cybercrime forum Altenen. Security researchers from Mysterium authenticated the database, which contained over 23.4 million user records, 13.6 million device records, and 2.6 million payment records, along with nearly 58 million connection logs. The data included email addresses, IP addresses, country of residence, and partial payment card information. Notably, full credit card details were not exposed due to masking.

Despite SplitVPN's previous assurances of '100% privacy guaranteed' and 'No logs or history', the leaked data showed extensive connection logs linking devices to specific VPN servers at exact timestamps. This revelation undermines the anonymity promised to users. The breach is particularly concerning in regions like Russia, Iran, India, and Myanmar, where VPNs are often used to bypass government censorship, potentially exposing users to surveillance risks.

Users of NotVPN or SplitVPN should consider their email and IP addresses compromised. Security experts advise changing any reused passwords, enabling two-factor authentication, and watching for unfamiliar charges on payment statements. Additionally, users should be wary of phishing attempts leveraging their VPN usage data. The scale of this breach highlights the importance of verifying one's exposure through breach-notification services such as Have I Been Pwned.