← Blog

SplitVPN Breach: 865k Emails and 58M Logs

Share on X

BREAKING: On August 1, 2026, Have I Been Pwned loaded the SplitVPN (formerly NotVPN) breach: 865.3k unique email addresses, plus IP addresses, country/geo fields, device information, and partial payment-card data. Troy Hunt noted that about 37% of those emails were already in HIBP. Researchers separately verified a dump with roughly 58 million connection logs — despite “no logs” marketing.

Canonical record: SplitVPN HIBP breach.

What HIBP indexed

HIBP’s SplitVPN page says the July 2026 incident exposed millions of customer records including 865.3k unique emails. Compromised data categories listed: email addresses, IP addresses, geographic locations, device information, and partial credit card data. The breach was added to HIBP on 1 August 2026.

Partial cards typically mean BIN (first six) plus last four digits and expiry — enough for fraud targeting and social engineering, not enough for a full card clone by themselves. Combined with email and IP history, they still raise phishing quality dramatically.

What Mysterium found in the raw dump

SecurityAffairs and Mysterium’s research describe an Altenen forum listing by vhacker51 offering a ~17GB SQL dump dated about 21 July 2026: roughly 23.4 million user records, 13.6 million devices, 2.6 million payment records, and ~58 million connection logs. Mysterium says it verified the corpus against the raw dump.

The damning table is deviceProxy: which device connected to which VPN server and when — continuously from June 2025 through the dump day. That is connection metadata, not a full browsing history of destination websites. It is still exactly the kind of log a “we never store connection logs” pitch promises not to keep.

Cross-referenced with emails and last-seen IPs, those rows reconstruct who connected, from where, to which server, and when — especially sensitive for users in Russia, Iran, India, Myanmar, and other places where VPN use can be politically loaded.

Why unique emails and row counts both matter

HIBP’s 865.3k figure is the unique-email census useful for “was I pwned?” checks. The 23.4 million user-row figure can include duplicates, abandoned accounts, and non-email identifiers. BreachHistory indexes 865,300 as recordsAffected to match HIBP, and documents the larger researcher counts in the writeup.

The 37% overlap with prior HIBP breaches means many SplitVPN users already recycle compromised emails — credential stuffing risk is not theoretical.

Action items if you used SplitVPN / NotVPN

  1. Change the password on the email used to register, and anywhere that password was reused.
  2. Enable MFA on email and financial accounts.
  3. Watch bank/card statements for fraud citing BIN+last4 patterns.
  4. Assume last-seen IPs and connection times may be in third-party hands.
  5. Stop using SplitVPN/NotVPN; migrate to a provider with a credible no-logs audit story.
  6. Ignore “SplitVPN refund” phishing that quotes your old IP country.
  7. Check your email on Have I Been Pwned for the SplitVPN entry.
  8. If you used the VPN in a high-risk jurisdiction, factor metadata exposure into your threat model with local counsel if needed.

Canonical sources

Catalog: https://breachhistory.com/splitvpn/splitvpn-hibp2026. HIBP — SplitVPN. Mysterium analysis. SecurityAffairs.

Timeline

June 2025–21 July 2026: connection-log timestamps in the verified dump.

~21 July 2026: Altenen dump date cited by researchers.

Late July 2026: public research coverage of the 58M-log finding.

1 August 2026: HIBP loads 865.3k unique emails.

“No logs” as an unauditable marketing claim

Centralized VPNs ask users to trust an operator’s logging policy. When that trust fails, the user learns after the fact from a forum dump. SplitVPN’s breach is a case study in why independent audits, open-source clients, and minimized metadata matter more than slogan screenshots.

Payment tokens and subscription state in the dump also show how billing systems become privacy liabilities even when full PANs are masked.

Who is most at risk

Users who registered with a primary email reused across banks and social media.

Users in censored or hostile jurisdictions who assumed connection metadata did not exist.

Anyone who paid with a card still active — BIN+last4 plus email enables convincing bank-impersonation calls.

Extended FAQ

Is SplitVPN in Have I Been Pwned? Yes — 865.3k unique emails added 1 Aug 2026.

Were full credit cards leaked? HIBP/Mysterium describe partial card data (BIN + last 4 + expiry), not full PANs.

Did they keep connection logs? Researchers verified ~58M device↔server↔time rows despite no-logs marketing.

Why only 865k if there are 23M user rows? HIBP counts unique emails; row counts can exceed unique addresses.

Practical guidance for the next month

Expect phishing that names NotVPN and SplitVPN interchangeably. Scammers will claim your “58 million log entry” is proof and demand crypto to delete it — that is fraud.

Corporate security teams should hunt for SplitVPN usage in shadow-IT inventories; employees sometimes install censorship-bypass VPNs on work laptops.

Journalists should keep HIBP’s unique-email figure and the researcher log counts labeled separately so “58 million users” does not accidentally replace “58 million connection rows.”

Bottom line on the SplitVPN data breach

HIBP confirms 865.3k unique emails plus IPs, geo, devices, and partial cards. Independent research adds a verified picture of tens of millions of connection-log rows contradicting no-logs claims. Rotate credentials, assume metadata exposure, and treat countdown-clock “deletion” offers as scams.

If your email appears in the SplitVPN HIBP entry, prioritize email-account MFA today — that inbox is the recovery path for everything else the dump helps attackers target.

Privacy-conscious users should treat this SplitVPN data breach as a reminder that marketing slogans are not controls. Prefer providers that publish independent no-logs audits, minimize retained metadata by design, and separate billing systems from VPN session infrastructure so a single SQL dump cannot reconstruct both identity and connection timelines.

Parents and schools in countries where VPN use is common for streaming or research should warn teens not to reuse school emails on consumer VPN apps; those addresses are now enrichment fuel for phishing that quotes “your SplitVPN country.”

Security teams writing postmortems can use SplitVPN as a tabletop: what would we do if a contractor’s “no-logs” tool appeared in HIBP tomorrow with partial card data? The answer should already include forced password resets, card monitoring, and a ban on unapproved VPN clients.

Finally, bookmark the BreachHistory SplitVPN record so community forums can link a labeled summary instead of screenshot chains of Altenen posts.

Researchers handling samples should continue redacting emails and tokens; secondary redistribution is not required to prove the no-logs contradiction. Responsible disclosure of methodology beats dumping more victim rows into public Telegram channels.

For users who already rotated passwords after other 2026 VPN headlines, still check HIBP specifically for SplitVPN — the 37% overlap statistic means many people are in multiple breaches, but the new metadata exposure is unique to this corpus.

Payment processors and card issuers may see elevated fraud attempts that quote BIN ranges from the dump. Cardholders who used SplitVPN should enable transaction alerts even if only partial digits were published.

The SplitVPN / NotVPN incident will be cited for years whenever someone claims “no logs” without evidence. Keep the HIBP link and the Mysterium analysis side by side when explaining it.

Additional context for defenders and the public

Incident response teams reading this coverage should map the confirmed facts to their own ticketing language: what is attested by a primary source, what is still an open forensic question, and what attackers will invent in the next 72 hours of phishing. That discipline prevents help-desk improvisation from becoming a second breach vector.

Community moderators on forums and union channels can reduce harm by pinning official URLs and removing posts that demand victims paste NIRs or card digits “to check if they are in the dump.”

Lawmakers and auditors will ask why long-retention staff databases remain reachable with a single professional account. Those questions are fair; answering them with blame-only politics helps nobody who needs a password reset today.

Keep following primary sources linked above. When counts or data elements are revised, BreachHistory will update the canonical rows. Until then, prefer labeled caution over viral certainty.

Individuals should prefer official apps and bookmarked portals over search ads, refuse remote-support tools offered by cold callers, and record dates of suspicious contacts for reports if financial loss occurs.

Organizations should brief support staff on social-engineering scripts that cite these headlines and document decisions for auditors who will ask how the firm responded.

Field-level risk and secondary scams

Once a breach is public, the dump itself is only half the harm. The other half is opportunistic crime that uses the headline as bait. Attackers do not need every row to be accurate; they need enough plausible detail to open a conversation.

Victims should assume callers may quote an email domain, a city derived from IP geo, a teacher’s académie, or a partial card BIN. Knowledge of a detail from the news is not proof of legitimacy. Hang up and use a phone number from a letter you already trust or from an official website you typed yourself.

Support desks at banks, schools, and VPN providers will see a surge of “was I affected?” tickets. Give them a one-page fact sheet: what is confirmed, what is not, and which enrollment codes are valid only from mailed notices.

How to read competing numbers in the same news cycle

Modern breaches ship with multiple metrics: unique emails, raw table rows, terabytes, years of retention, state AG subsets. Honest coverage labels each metric’s source. Inflating one number into another is how 865k unique emails become “23 million victims” or how “agents since 2001” becomes “every teacher in France confirmed stolen.”

BreachHistory keeps separate catalog fields and dual rows when needed so searchers can see attested versus claimed figures. When you share links, prefer those labeled pages over screenshots of forum posts.

Sector lessons that travel beyond this incident

Long-retention databases are gravitational wells for attackers. Whether the system trains teachers or bills VPN subscribers, keeping decades of identifiers behind a single passwordable account is a design choice with predictable outcomes.

Phishing-resistant MFA, egress logging, and rapid account disablement beat post-breach apologies. Boards should ask for evidence of those controls before the next communiqué.

Regulators will keep asking whether “no logs” and “we take privacy seriously” statements were marketing or engineering. The market is learning to demand the latter.

Thirty-day checklist

Week one: rotate passwords on the email tied to the service, enable MFA, and monitor payment cards.

Week two: review account recovery questions and delete unused apps that shared that email.

Week three: watch for delayed phishing that references official notice language once letters mail.

Week four: reassess whether you still need the product that was breached; switching costs are often lower than a year of fraud cleanup.

Throughout: refuse remote-access tools from strangers and ignore gift-card “remediation” demands.

Closing

Stay aligned with primary sources linked in this article. Keep MFA on. Treat payment or identity requests that cite this news cycle as fraud until verified through channels you already trust. Bookmark the BreachHistory canonical record so internal tickets and community posts point to a stable summary.

Researchers and journalists can reduce harm by withholding raw PII samples, emphasizing verification status, and updating stories when company or regulator counts arrive. Clarity is a safety control.

If you help relatives navigate these headlines, send them the official notice page and the BreachHistory summary together — two links, clear labels, no screenshot chain.

Defenders should update threat briefings with the correct verification status and brief staff on social-engineering scripts before the Monday inbox flood.

Individuals should prefer bookmarked portals over search ads and record suspicious contacts if financial loss occurs. That paper trail matters for banks and police.

The next amendment to this story will likely be a count, a denial, or a deeper forensic note. Until then, act on what is confirmed and refuse what is merely loud.

Communications guidance when headlines outrun the census

Spokespeople face a trap when an incident is confirmed but the headcount is not. Ignoring the story looks evasive; inventing a number looks dishonest. The durable approach is to restate attested facts, point to the official notice page, explain why a census takes time, and tell people how to recognize phishing that cites the incident.

That approach respects victims without laundering unverified figures. It also gives journalists a clean quote that will not need a humiliating correction two days later.

Internally, write the FAQ before the press call. Include: what systems, what data categories, what is explicitly not in scope, how people will be notified, and which phone numbers are real. Print it for the help desk.

Externally, update the same FAQ when facts change instead of spawning contradictory PDFs. Version dates on the page prevent rumor that “the ministry deleted the truth.”

For global audiences reading translations, keep proper nouns stable — SplitVPN/NotVPN, Compas, académie, NIR — so searchers can match English and French coverage to the same BreachHistory rows.

If you only remember one habit from this playbook: never ask the public to email sensitive identifiers to prove they were affected. That request is how scammers finish the job the breach started.

Patience beats panic: freeze credit or watch statements where relevant, rotate reused passwords, and wait for official notices before uploading identity documents anywhere new. Premature uploads to fake portals create more harm than a short delay. When relatives forward alarmist videos, reply with the official link and the BreachHistory summary instead of arguing in screenshots.