SplitVPN Breach: Why ‘No Logs’ Needs Evidence, Not Just Marketing
Have I Been Pwned says SplitVPN exposed 865,000 unique email addresses, while security reporting says leaked records allegedly included device, payment and VPN connection metadata.
Quick takeaways
- Have I Been Pwned lists the SplitVPN breach as affecting 865,300 unique email addresses and says exposed data included device information, geographic locations, IP addresses and partial card data.
- Bitdefender reports that a leaked database allegedly included nearly 58 million VPN device-to-server connection records, despite no-logs messaging around the service.
- If you used SplitVPN or NotVPN, change reused passwords, enable MFA, monitor payment activity and treat messages referencing your VPN use as high-risk phishing.
What happened?
Have I Been Pwned added a SplitVPN breach entry on 1 August 2026. HIBP says the Russian VPN service, previously known as NotVPN, suffered a July 2026 breach that exposed 865,300 unique email addresses. The exposed data listed by HIBP includes device information, email addresses, geographic locations, IP addresses and partial payment-card data.
Bitdefender's HotForSecurity report says a 17 GB SQL database allegedly attributed to SplitVPN was being distributed and that researchers who reviewed the raw file found the contents broadly matched the seller's claims. Bitdefender reports the alleged leak included user, device, payment and VPN connection metadata, including nearly 58 million device-to-server connection entries. SplitVPN had not publicly confirmed the incident in that reporting.
Why it matters for VPN users
The most important lesson is not just that a VPN company can be breached. It is that VPN privacy claims need evidence. A provider can advertise a no-logs posture, but users need to know what the service actually stores, for how long, who has access to it, and whether those claims have been independently tested.
Connection metadata is not the same as browsing history, and the reported records do not mean websites visited were exposed. But metadata can still be sensitive. An email address, device identifier, IP address, location and server-connection timestamp may connect a real person to VPN use at a specific time. For users in restrictive environments, that can be far more serious than a routine marketing database leak.
What affected users should do now
If you used SplitVPN or NotVPN, first check whether your email appears in Have I Been Pwned and change any password reused on that account. Prioritise your email account, banking, social media, work accounts and any account where a password manager shows the same or similar password was used.
Enable two-factor authentication where available, monitor payment statements for unfamiliar charges, and be sceptical of messages that mention SplitVPN, NotVPN, your VPN use, payment details or account status. Breach data can make phishing and extortion attempts sound convincing even when the attacker has no further access.
How to judge no-logs claims more carefully
A good no-logs claim should be specific. Look for clear statements about connection timestamps, source IP addresses, assigned VPN IPs, DNS requests, bandwidth totals, device identifiers, analytics, crash logs, payment records and account emails. Vague lines about military-grade privacy are not enough.
Stronger evidence can include recent independent audits, court-tested or incident-tested claims, RAM-only or diskless server design, transparent warrant-canary or transparency reports, open-source apps, signed releases, and a privacy policy that explains what is collected rather than hiding behind broad categories. None of those guarantees perfection, but they are better than trusting a slogan.
Where a VPN helps — and where it does not
A trustworthy VPN can hide your browsing from a local network and reduce ISP-level visibility. It can be useful on public Wi-Fi, while travelling, or when you want to route traffic through a provider you deliberately chose rather than the network you happen to be on.
A VPN does not protect you from the VPN provider itself storing too much data, suffering a breach, or operating with weak internal controls. That is why provider selection is a security decision, not just a price or speed decision.
VPN Rocks view
The SplitVPN story is exactly why VPN Rocks treats no-logs claims as a question to investigate, not a badge to repeat. Privacy tools deserve scrutiny because users route sensitive traffic through them and often use them in moments where exposure matters.
If you are choosing a VPN today, prefer providers that explain their logging limits plainly, publish credible audits, keep apps updated, minimise account data and avoid pretending a VPN solves every privacy problem. Trust comes from evidence, not just a brand name or a low monthly price.
Sources and further reading
VPN Rocks adds plain-English analysis and practical advice. Source links are included so readers can check the underlying guidance directly.