A significant data breach involving SplitVPN, formerly known as NotVPN, has exposed 58 million connection logs and a multitude of user records, countering its 'no-logs' claims. A 17 GB SQL database was released by a threat actor on a cybercrime forum, verified by Mysterium's research team. The database includes approximately 23.4 million user records, 13.6 million device records, and 2.6 million payment records, with metadata revealing users' connection histories from June 2025 to July 2026.
Though not capturing specific website visits, the logs entail sensitive information, making its exposure particularly dangerous for users in regions with stringent censorship. The incident calls into question the reliability of 'no-logs' promises from VPN providers, highlighting the risks of centralized services that may log user activities for various reasons.