SplitVPN (formerly NotVPN) "No-Logs" VPN Breach Exposes 58 Million Connection Logs, 23.4M User Records — Threadlinqs Intelligence
As of 2026-08-02, SplitVPN (formerly NotVPN) "No-Logs" VPN Breach Exposes 58 Million Connection Logs, 23.4M User Records is a high-severity data breach threat attributed to vhacker51, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-1823 · Severity: HIGH · Status: ACTIVE · Category: DATA_BREACH
Attribution: vhacker51 · FINANCIAL
A threat actor using the handle "vhacker51" listed a 17 GB SQL database (compressed ~5 GB) allegedly stolen from SplitVPN, a Russian VPN service formerly branded NotVPN, on the Altenen cybercrime
SplitVPN, a Russian VPN service marketed for bypassing internet censorship and rebranded from its earlier NotVPN identity (Android package names com.notvpn and com.notvpn2 still reference the legacy brand), advertises a strict "No logs or history: We never store your activity or connection logs" policy. On July 21, 2026, a forum actor operating under the handle "vhacker51" began distributing a 17 GB SQL database (approximately 5 GB compressed, with a public download link) on the Altenen cybercrime/carding forum, claiming the data was stolen directly from SplitVPN's backend infrastructure.
The listing advertised roughly 23.4 million user records, 13.6 million device records, 23.9 million authorization records, 2.6 million Tinkoff payment records, and nearly 58 million device-to-server connection log entries. Security researchers at Mysterium Network obtained a copy of the dump and verified it against the raw data, confirming the counts. The exposed dataset spans email addresses, last-seen IP addresses, countries of residence, approximate geographic locations, device identifiers/hardware IDs, subscription status, recurring-billing tokens issued via the Tinkoff payment gateway, masked card data (BIN plus last four digits and expiry date, not full PANs), transaction amounts and timestamps, authentication tokens, proxy targets, WireGuard peer data, linked Telegram account identifiers, linked Apple ID identifiers, server metrics, internal back-office/App Store provisioning infrastructure tables, and administrator records.
The most damaging element is the `deviceProxy` table: nearly 58 million rows recording which device connected to which VPN server and exactly when, with timestamps running from June 2025 through July 21, 2026 (the apparent breach cutoff date). This table does not record destination websites visited, but device-to-server connection metadata at this granularity is precisely the category of record SplitVPN's marketing promised never to retain, and it is sufficient to support timing-correlation and de-anonymization analysis against a censorship-circumvention user base concentrated in Russia, Iran, India, and Myanmar -- jurisdictions where VPN use itself can carry legal or personal-safety risk.
The `admin` table exposed five named operator accounts (pavel, valerii, maria, andrei, vladislav) with bcrypt password hashes, assigned roles, and action logs; these accounts were created between January and June 2026, suggesting relatively recent administrative infrastructure. Have I Been Pwned ingested the breach on August 1, 2026 and confirmed 865,336 unique email addresses in its consumer-facing notification dataset -- a smaller figure than the seller's full 23.4 million user-record claim, consistent with HIBP typically indexing only the unique-email subset of a larger raw dump. As of the initial reporting, SplitVPN had not publicly confirmed the incident.
Weaknesses (CWE)
CWE-532, CWE-200
Target sectors: consumer, telecoms, civil society, news - media
Target regions: russia, iran, india, myanmar
Detections & IOCs
As of 2026-08-25, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
DATA_BREACH, HIGH, threat intelligence, cybersecurity, T1589, T1590, T1591, T1588, T1585, T1586, T1552, T1110, T1213, T1005