A VPN that promised “no logs or history: we never store your activity or connection logs” turns out to have stored tens of millions of them. A threat actor is currently distributing a 17GB SQL database on the Altenen cybercrime forum, claimed to be stolen from SplitVPN, a Russian VPN service formerly known as NotVPN and marketed for bypassing internet censorship.
The breach was reported on July 29, 2026, and the database itself contains records running right up to the day it was taken, which means whoever pulled it had access to a live, actively used system rather than an old backup.
What was exposed
According to a report from Security Affairs, based on research from Mysterium’s research team, who obtained a copy of the database and verified it against the raw dump, the numbers break down as roughly 23.4 million user records, 13.6 million device records, 2.6 million payment records, and 58 million connection logs.
The connection logs sit in a table called deviceProxy, which records which device connected to which server, and exactly when, nearly 58 million times, with timestamps running continuously from June 2025 up to July 21, 2026, the day of the dump. That means the service was still actively logging connections as the breach occurred, not exposing old, discontinued records.
Cross-referenced with the users table (account emails, last-seen IP addresses) and the device table (hardware identifiers), those records are detailed enough to reconstruct who connected, from where, to which server, and when, for tens of millions of people. Payment records include masked card numbers, expiry dates, and recurring billing tokens tied to the Tinkoff payment gateway. No full card numbers were exposed, but the combination of email, payment history, and a recurring billing token is still enough to cause real problems for affected users.
Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.
To be clear about what wasn’t exposed
It’s worth being precise here, since breach headlines tend to blur into “everything was leaked.” The deviceProxy table records server connections, not destination websites visited. This is metadata, connection logs in the strict sense, not a full browsing history of every site each user loaded. That distinction matters, but it doesn’t make the exposure minor. Knowing which server a specific email address connected to and exactly when is still enough, especially combined with account and payment data, to build a detailed picture of a person’s VPN usage over more than a year.
Full payment card numbers also weren’t exposed; the database stores masked card numbers (BIN plus last four digits) rather than complete numbers. The risk there sits more in the recurring billing tokens and the linkage between an email, a payment history, and a real person, than in direct card fraud.
Why the user base makes this worse
The seller lists SplitVPN’s user base as concentrated in Russia, Iran, India, and Myanmar, countries where people commonly turn to a VPN specifically to get around state censorship, access blocked messaging apps, or read independent news. For that population, a leaked record linking an email address to an IP address and a timestamp isn’t an abstract privacy inconvenience. It’s a document tying a real person to the act of evading state internet controls, now circulating on a criminal forum.
The database also exposed an admin table with five operator accounts, bcrypt password hashes, roles, and a complete admin action log, along with tables pointing to back-office infrastructure used to provision App Store accounts, the plumbing behind distributing a VPN app that Russia has been actively removing from official app stores.
What this proves about “no-logs” marketing
SplitVPN’s situation is a clean example of the gap between a marketing claim and a verifiable one. A “no-logs” claim on a VPN’s website is not something a user can check. It’s the provider’s word, and nothing more, unless it’s backed by an independent audit that a security firm actually performs against the provider’s live infrastructure. SplitVPN made the strongest possible version of that claim and kept detailed connection logs anyway, apparently for as long as the service has existed.
This is exactly why we treat an independently audited no-logs policy as a distinct, heavily weighted category on our audited no-logs VPN comparisons, rather than taking any provider’s own claims at face value. If you want to understand what actually counts as proof of a no-logs policy, versus what’s just a line in a privacy policy, our guide on how to verify a VPN’s no-logs policy breaks down the difference between an audit, a court case, and an unverified claim.
SplitVPN and NotVPN do not appear anywhere on our comparison table. None of the providers we track made a “zero logs” claim this specific, or this thoroughly contradicted by a leaked database, which is itself worth noting: the VPNs that submit to repeat, named, independent audits (NordVPN’s sixth audit by Deloitte Lithuania, ProtonVPN’s fourth audit and SOC 2 certification, PIA’s third Deloitte Romania audit) are making a claim that a third party has actually gone and checked, not just a promise on a landing page.
How this fits the wider pattern
This isn’t an isolated incident in the VPN industry, it’s part of a recurring pattern where the providers most willing to make absolute, unverifiable privacy claims turn out to be the ones with the least to back them up. Our coverage of Operation Saffron, where Europol dismantled a VPN service used by ransomware gangs, and the ongoing questions around Kape Technologies’ ownership of several mainstream VPN brands both point to the same underlying lesson: a VPN’s trustworthiness is a function of what can actually be checked, not what’s written on its homepage.
The providers that repeatedly submit to named, dated, independently published audits, and that publish transparency reports detailing exactly how many law enforcement requests they received and how many they complied with, are making a falsifiable claim. ProtonVPN’s July 2026 transparency report, for instance, documented 458 requests and zero logs handed over, a claim anyone can scrutinize against ProtonVPN’s audit history. SplitVPN made a stronger claim (“we never store your activity or connection logs”) with nothing behind it at all, and the difference between those two situations is the entire point of paying attention to audits in the first place.
What to do if you used NotVPN or SplitVPN
If you or anyone you know used this service, treat the associated email address and IP as compromised. Change passwords anywhere that email was reused, enable two-factor authentication wherever it’s available, and be aware that connection metadata tying you to a specific server and timestamp now exists outside the provider’s control, on a criminal forum, not just in a breached database sitting unused.
This breach is a reminder that "no logs" is only as trustworthy as the verification behind it. A provider that keeps detailed connection logs while advertising "100% privacy guaranteed" isn't a rare bad actor, it's what happens by default when nobody checks. Stick to VPNs with a current, named, independent no-logs audit, and treat any provider that can't point to one as making a claim you have no way to verify.
Keep reading: NordVPN Passes Its Sixth No-Logs Audit and How to Verify a VPN’s No-Log Policy