Skip to content
Cyber Security Firms
ConfirmedTechnology

SplitVPN Data Breach (July 2026)

A 17 GB database taken from the Russian VPN service SplitVPN reached a cybercrime forum in July 2026, and Have I Been Pwned verified 865,336 email addresses alongside IP addresses, device details, user locations and masked card numbers.

Disclosed Updated
Organization
SplitVPN
Country
RU
Incident date
July 21, 2026
Disclosed
July 29, 2026
Records affected
865,000
Attack type
Undisclosed
Status
Confirmed
Data exposed
  • Device information
  • Email addresses
  • Geographic locations
  • IP addresses
  • Partial credit card data
Timeline
  1. A threat actor begins distributing a 17 GB SQL database on the Altenen cybercrime forum, per TechRadar. Have I Been Pwned records this as the breach date
  2. Security Affairs publishes the first account, after Mysterium VPN's research team checks the dump against the raw data
  3. Have I Been Pwned loads the data and verifies 865,336 unique email addresses
  4. SplitVPN tells TechRadar the subscription data is authentic and the connection log table is fabricated, and says it rotated credentials and closed the vulnerability

What Happened

SplitVPN is a Russian VPN service that traded as NotVPN before it rebranded, sold largely to people who use a VPN to get around national internet blocks. On July 21, 2026, a threat actor began distributing a 17 GB SQL database on the Altenen cybercrime forum and claimed it had been taken from SplitVPN's own infrastructure, according to TechRadar's account.

The research team at Mysterium VPN obtained a copy and checked it against the raw dump. Per Security Affairs, which published the first report on July 29, the database held roughly 23.4 million user rows, 13.6 million device rows and 2.6 million payment rows, plus a table called deviceproxy holding close to 58 million entries that each map a device to a VPN server with a timestamp, running from June 2025 to the day of the leak.

On August 1, Have I Been Pwned loaded the data and verified 865,336 unique email addresses. That is the number on the fact grid above. The larger counts are row totals from the dump as reported by Mysterium and relayed by Bitdefender's Vlad Constantinescu, not verified individuals.

SplitVPN has confirmed part of it. The company told TechRadar on August 7 that the leaked subscription metadata, including email addresses, countries, subscription status, masked card details and device names, is authentic, and that the connection log table is not. "The third-party listing claims 58 million connection logs, but this is a fabrication added to inflate the price," a company spokesperson said, adding that "the exposed data contains only basic account information, which fully aligns with our no-logs commitment." The company also said it changed every VPN server node IP, rotated access credentials and encryption keys, closed the vulnerability and hired outside specialists to audit its infrastructure. It has not described the vulnerability, so the attack type on this report stays undisclosed.

What Was Exposed

The verified classes are email addresses, IP addresses, device information, geographic locations and partial credit card data, which Have I Been Pwned records as the first six and last four digits of the card plus the expiry date.

Two things make this set worse than the same fields taken from a shop. The first is what the account itself says about you: the record proves that a named email address paid for a censorship circumvention tool, and it carries a recent IP address and country beside it. For a user in a country that polices that behavior, the link between the address and the network location is the exposure, not the card.

The second is the card fragment. A first six and last four with an expiry date cannot be used to make a charge. It is close to perfect material for a scam call, because reading your own card's opening and closing digits back to you is the trick that makes a stranger sound like your bank.

What to Do If You Are Affected

Phishing built on breach data reads nothing like the generic version, and the tells that still give it away are in how to spot a phishing email. The wider sequence, including which steps are worth doing in the first week, is in what to do after a data breach. The other technology breaches on record here show how often a subscription database is the thing that ends up on a forum.

What Is Not Known Yet

How the attacker got in. SplitVPN says it closed a vulnerability but has not said what it was, and no source has named an intrusion method, so the attack type is recorded as undisclosed.

Whether the connection logs are real. Mysterium says it verified the deviceproxy table against the raw dump; SplitVPN says the table was invented to raise the asking price. No independent party has settled it, and the honest position is that a user cannot tell which account it is.

How many people the 23.4 million user rows represent. Only the 865,336 verified email addresses are a count of anything checkable. We have also found no regulator filing or notification letter for this incident, which is the usual position for a service that sits outside US and EU notification rules.

Sources

  1. Have I Been Pwned: SplitVPN
  2. Security Affairs, VPN Breach Exposes 58 Million Connection Logs Despite No-Logs Claims, July 29, 2026
  3. TechRadar, This Russian VPN Has Been Accused of Breaching Its No-Log Policy, August 7, 2026
  4. Bitdefender HotForSecurity, SplitVPN Breach Reveals 58 Million Hidden Connection Logs
On this page
Reviewed by

Daniel Reyes

  • CISSP
  • 12 years in security operations
  • Austin, TX

Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.

Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.

Read the full bio and how we research →