A database allegedly stolen from VPN provider SplitVPN, formerly known as NotVPN, appears to expose tens of millions of user records, device records, payment records, and connection logs, raising questions about the company’s longstanding “no-logs” privacy claims.
Security researchers at Mysterium reported obtaining a copy of the alleged 17 GB SQL database circulating on a cybercrime forum and said they verified its contents against the raw dump. According to their analysis, the database contains approximately 23.4 million user records, 13.6 million device records, 2.6 million payment records, and roughly 58 million connection log entries.
Connection metadata reportedly retained
The most significant finding is a table that allegedly recorded connections between user devices and VPN servers. Researchers said the records include device identifiers, server associations, and timestamps spanning from June 2025 through July 21, 2026.
While the database does not reportedly contain users’ browsing history or destination websites, the connection metadata could still reveal when users connected, which VPN server they used, and the device associated with those sessions.
According to Mysterium, those records directly contradict SplitVPN’s public marketing, which stated that the service never stored activity or connection logs.
Millions of user and payment records
The researchers said the database also contains user email addresses, last known IP addresses, device identifiers, subscription information, recurring billing tokens, and masked payment card information. Full payment card numbers were reportedly not included.
The report notes that users were concentrated in countries including Russia, Iran, India, and Myanmar, where VPN services are commonly used to bypass internet censorship. For individuals in those regions, exposure of VPN connection metadata could present heightened privacy and security risks.
Administrative data also exposed
Researchers also identified administrator accounts, role assignments, password hashes, and audit logs within the database, along with infrastructure related to the service’s backend operations.
At the time of publication, SplitVPN had not issued any public statement addressing the alleged database leak or the reported discrepancy between its “no-logs” policy and the data researchers say was retained.
The SplitVPN breach has been added to Have I Been Pwned, allowing users to check whether their email address appears in the exposed dataset.












