SplitVPN Data Leak Validates Severe Privacy Violations
The veracity of a Virtual Private Network’s (VPN) promotional promises can only be authenticated through its internal telemetry. Consequently, rigorous analysis of the recent SplitVPN data leak corroborated a foundational suspicion. The service provider aggressively archived tens of millions of connection logs, directly contradicting its emphatic zero-log public declarations.
Validating the 17-Gigabyte Compromise
Just last week, intelligence emerged regarding the illicit sale of a 17-gigabyte database allegedly belonging to SplitVPN (formerly operating as NotVPN). The illicit vendor boldly asserted that the archive contained sensitive intelligence spanning 23.4 million discrete users. Initially, the authenticity of this massive dump remained unverified. However, the Mysterium team recently acquired a comprehensive copy of the database and meticulously examined its table architecture, counters, and sampled records.
Their forensic audit, detailed in a report regarding the NotVPN and SplitVPN breach, definitively substantiated the primary claims. The database legitimately harbors approximately 23.4 million user profiles, 13.6 million unique device identifiers, and 2.6 million payment transactions. Crucially, it contains nearly 58 million discrete rows within the deviceProxy table.
Each row systematically correlates a specific device to a designated VPN server alongside precise connection timestamps. Startlingly, the platform continuously amassed these granular logs from June 2025 until July 21, 2026, the exact date attackers exfiltrated the database.
The Scope of the Compromised Telemetry
This subsequent analysis also definitively clarified the exact contents of the hemorrhage. The logs thankfully did not contain comprehensive browsing histories or specific URLs of visited websites. Nevertheless, when combined with exposed email addresses, originating IP addresses, and hardware identifiers, these records meticulously establish which specific device connected from a particular geographic origin to a designated VPN node at an exact time.
This extensive data collection protocol flagrantly violates SplitVPN publicized guarantees regarding the absolute absence of activity and connection logging.
Payment Data and Administrative Credentials
Fortunately, the payment tables did not surrender complete primary account numbers (PAN). Instead, the database archived the first six and last four digits of credit cards, expiration dates, transaction amounts, operational identifiers, and recurring billing tokens. Alarmingly, the dump also exposed five administrative accounts featuring bcrypt-hashed passwords, role assignments, and comprehensive employee activity ledgers.
Geographic Impact and Critical Remediation
The vendor attributes the service’s primary demographic base to users residing in Russia, Iran, India, and Myanmar. For individuals relying upon this VPN specifically to circumvent stringent state censorship, the toxic combination of exposed email addresses, originating IPs, and precise connection timestamps irrevocably unmasks their utilization of the service, even devoid of specific traffic payloads.
Security experts strongly advise all NotVPN and SplitVPN patrons to immediately assume that their associated email addresses and IP addresses are thoroughly compromised. Users must expeditiously change any reused passwords, aggressively enable two-factor authentication, remain exceptionally vigilant against targeted phishing campaigns, and meticulously monitor financial statements. Unfortunately, the connection metadata has irrevocably slipped beyond the service provider’s control.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.