
SPLITVPN, formerly traded as NotVPN, has leaked a massive trove of connection logs and user data, according to MysteriumVPN’s research, shattering its promise of a no‑logs service.
The breach was first publicised by databreaches.net, which reported that a 17 GB SQL database appeared on a cybercrime forum. The database holds roughly 23.4 million user records, 13.6 million device identifiers and 58 million connection logs covering the period from June 2025 to July 2026.
Security Affairs also covered the incident, noting that the exposed records include email addresses, IP addresses and device metadata, alongside 2.6 million payment records that did not contain full card numbers (source). While the logs do not reveal specific website visits, they still provide a detailed picture of user behaviour.
The exposure undermines trust in VPN providers that advertise a strict no‑logs policy, particularly for individuals living under authoritarian regimes where connection histories could be used for reprisals. No specific threat actor has been attributed to the leak, but the data’s appearance on underground markets raises the risk of credential stuffing, targeted phishing and surveillance.
Evidence suggests the database is being offered for sale, increasing the likelihood that malicious actors will attempt to exploit the information. Although no ransomware or destructive payload has been linked to the breach, the aggregated data enables profiling and social engineering at scale.
Users of SplitVPN or NotVPN should treat their accounts as compromised, change passwords for any services where the same credentials were reused and enable multi‑factor authentication wherever possible. They should also monitor financial and online accounts for unusual activity and consider migrating to a VPN that has undergone independent audits of its logging claims.