
SplitVPN No-Logs Breach Claims: What VPN Users Should Check
TechRadar reports that SplitVPN denies allegations that leaked data included 58 million connection logs, but confirms some account and subscription metadata was exposed.
The short version
What you need to know
- TechRadar reports that a leaked database was advertised as containing SplitVPN user records, payment data, devices and alleged connection logs.
- SplitVPN told TechRadar that basic account and subscription metadata was authentic, but denied that alleged device-server-timestamp connection logs came from its infrastructure.
- The practical lesson is that a no-logs claim is stronger when it is backed by independent audits, technical controls and a clear breach response.
What happened?
TechRadar reported on 7 August that SplitVPN, formerly NotVPN, had been accused of breaching its no-log policy after a database was shared on a cybercrime forum. The article says the listing claimed to include user records, payment-related data, devices and around 58 million alleged connection logs.
SplitVPN disputed the logging allegation. According to TechRadar, the provider said exposed subscription metadata such as email addresses, countries of origin, subscription status, masked card information and device names was authentic, but that the alleged device-server-timestamp records were fabricated and not from its infrastructure.
Why it matters for VPN buyers
No-log policies are central to VPN trust because users cannot easily inspect what a provider records behind the scenes. Even if browsing histories are not exposed, connection metadata can still matter when it links an account, device, server and time window.
This is especially sensitive for people using VPNs in places where censorship or legal risk is real. Conflicting claims after a breach leave ordinary users in a difficult position: they may have to make safety decisions before an independent investigation or audit is public.
What you can do now
If you use SplitVPN, follow the provider's official security guidance, change the account password, rotate any reused passwords elsewhere, and review payment and email-account activity. Treat unexpected VPN support emails, renewal links or refund messages as phishing until verified through the official site.
When choosing any VPN, look for recent independent no-log audits, RAM-only or similarly constrained server designs, clear ownership, signed apps, transparent incident updates and a policy that explains exactly which account, payment and diagnostic metadata is still retained.
Where a VPN helps — and where it does not
A trustworthy VPN can reduce ISP-level tracking, encrypt traffic on local networks and make casual Wi-Fi snooping harder. Those benefits only apply when the VPN provider and app are themselves trustworthy.
A VPN cannot make its own provider's account systems invisible, cannot erase billing records, and cannot prove a no-log claim by marketing language alone. For privacy-critical use, technical architecture and independent verification matter as much as the slogan.
VPN Rocks view
The fair reading is cautious: SplitVPN denies the most serious logging allegation, but the confirmed exposure of some account metadata is still a reminder that VPN privacy is not all-or-nothing. Account systems, payments, app telemetry and support tooling are part of the privacy surface.
For most readers, this is a reason to prefer established VPNs with audit trails and transparent breach handling rather than whichever app is cheapest or loudest in search ads.
Primary reading
Sources and further reading
We add plain-English context and practical advice. These links let you inspect the underlying reporting, research and official guidance directly.
