SplitVPN (formerly NotVPN) Breach Exposes 58M Connection Logs, 23.4M User Records Despite 'No Logs' Claims — Threadlinqs Intelligence
As of 2026-08-02, SplitVPN (formerly NotVPN) Breach Exposes 58M Connection Logs, 23.4M User Records Despite 'No Logs' Claims is a high-severity data breach threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 26 indicators of compromise.
Threat ID: TL-2026-1815 · Severity: HIGH · Status: ACTIVE · Category: DATA_BREACH
Russian VPN provider SplitVPN (rebranded from NotVPN) suffered a breach exposing a 17GB SQL database with 23.4M user records, 13.6M device records, 2.6M Tinkoff payment records, and 58M
SplitVPN, a Russian VPN provider rebranded from NotVPN and marketed for bypassing internet censorship, suffered a breach of its backend SQL database. A forum actor using the handle 'vhacker51' advertised and distributed the archive -- allegedly exfiltrated on July 21, 2026 -- on the Altenen cybercrime forum as a ~5GB compressed (17GB raw) SQL dump with a public download link, listing approximately 23.4 million user records, 13.6 million device records, 23.9 million authorization records, 2.6 million Tinkoff payment records, and roughly 58 million proxy/device connection log entries. Mysterium's research team obtained a copy of the dump and verified the record counts against the raw database, confirming the seller's claims were substantially accurate, with one notable discrepancy: vhacker51 claimed six exposed admin accounts, while Mysterium's investigators confirmed only five.
The most consequential finding is a table (referred to in reporting as 'deviceProxy') recording exactly which device connected to which VPN server and precisely when -- nearly 58 million such entries spanning June 2025 through July 21, 2026, the apparent breach date. This directly contradicts SplitVPN's advertised claim: 'We never store your activity or connection logs. 100% privacy guaranteed.' While the exposed logs do not include full browsing destinations or complete payment card numbers, they are sufficient to reconstruct which user, from which IP address and device, connected to which server and at what time -- effectively de-anonymizing VPN sessions the service promised never to record.
Beyond the 'deviceProxy' connection-log table, the dump comprised at least a 'users' table (account emails, most-recent IP addresses, country/geolocation, subscription status), a 'device' table (hardware identifiers, device fingerprints, and operating-system values), an 'authorization' table (~23.9 million session/authorization-token records), and an 'admin' table exposing named operator accounts. Exposed fields also included recurring billing tokens and masked card data (BIN + last four digits, expiry, authorization codes for recurring charges) tied to the Tinkoff payment gateway, authentication tokens, WireGuard peer configurations, Telegram account linkages, Apple ID references, server metrics, and internal infrastructure details including App Store account-provisioning data. The 'admin' table exposed five named SplitVPN operator/admin accounts (pavel, valerii, maria, andrei, vladislav) with bcrypt-hashed passwords, assigned roles, and a complete admin action log; account creation timestamps for these five accounts run from January through June 2026.
No public reporting identifies the specific technical vulnerability or misconfiguration (e.g., exposed database, compromised credentials, insider access) that led to the initial exfiltration -- the incident is documented purely as a leaked/stolen database now circulating for free download on a cybercrime forum, with no CVE assigned and no vendor confirmation. The exposure is disproportionately dangerous for SplitVPN's core user base, concentrated in Russia, Iran, India, and Myanmar, where VPN usage is frequently used to evade state censorship and where connection metadata linking a real identity, device, and timestamp to VPN usage could expose activists, journalists, or ordinary citizens to state surveillance or persecution. Have I Been Pwned added the breach on August 1, 2026, loading 865,300 unique compromised email addresses for public search and notification. As of this writing, SplitVPN has issued no public confirmation or remediation statement.
Target sectors: consumer, civil society, news - media, government administration
Target regions: russia, iran, india, myanmar
Related threats
- SplitVPN (formerly NotVPN) "No-Logs" VPN Breach Exposes 58 Million Connection Logs, 23.4M User Records
- Alleged Revolut Data Breach — Unverified Threat-Actor Claim of 75M-User Financial Dataset for Sale ($500, Sample Data Disputed as Fabricated)
- Threat Actor 'TheHatman' Claims Theft of 3.6M+ Azure/Entra Tenant Employee Records from McDonald's, Gap, Vodafone, TCS, and Six Others via Password Spray/MFA Fatigue; TCS and Gap Dispute the Claims
- Sextortion Scammers Impersonate ShinyHunters, Exploit Leaked Breach Data for Bitcoin Extortion
- Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Data
- Alleged Żabka Polska Breach: 541K Jira Issues, 230K IT Tickets, 89 GitLab Repos, and Cloudflare/MongoDB/Broker Credentials Offered for €5,000
Detections & IOCs
As of 2026-08-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 26 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
DATA_BREACH, HIGH, threat intelligence, cybersecurity, T1589, T1590, T1596, T1650, T1586, T1552, T1110, T1078, T1566, T1087