Full Report
In July 2026, the Russian VPN service SplitVPN (previously known as NotVPN) suffered a data breach. The incident exposed millions of customer records, including 865k unique email addresses. Other impacted data included IP addresses, the user's country, and partial payment card data (first 6 and last 4 digits plus expiry date).
Analysis Summary
# Incident Report: SplitVPN Customer Data Breach
## Executive Summary
In July 2026, the Russian-based VPN provider SplitVPN (formerly NotVPN) experienced a significant data breach resulting in the exposure of millions of customer records. The compromise included 865,000 unique email addresses, connection logs, and partial payment information. The incident is particularly notable as it contradicts the service's "no-logs" claims by exposing 58 million connection logs.
## Incident Details
- **Discovery Date:** Approximately August 1, 2026 (Date added to HIBP)
- **Incident Date:** July 2026
- **Affected Organization:** SplitVPN (formerly NotVPN)
- **Sector:** Technology / Virtual Private Network (VPN) Services
- **Geography:** Russia / Global Customer Base
## Timeline of Events
### Initial Access
- **Date/Time:** July 2026
- **Vector:** Not explicitly disclosed (Likely misconfigured database or unauthorized administrative access)
- **Details:** Attackers gained access to the backend infrastructure housing customer databases and connection logs.
### Lateral Movement
- **Details:** Information not provided in the source; however, the scope suggests access to multiple database tables including user accounts, billing, and traffic logs.
### Data Exfiltration/Impact
- **Details:** Exfiltration of millions of records. The data set included 865,300 unique email addresses, IP addresses, geographic locations, and 58 million connection logs.
### Detection & Response
- **Discovery:** The breach was identified and publicized in late July/early August 2026, subsequently cataloged by "Have I Been Pwned" on August 1, 2026.
- **Response actions taken:** Users were advised to change passwords and enable Two-Factor Authentication (2FA).
## Attack Methodology
*Note: Specific technical methodology was not disclosed in the provided text.*
- **Initial Access:** Likely exploitation of exposed database or credential stuffing against administrative accounts.
- **Collection:** Automated harvesting of user tables and logging databases.
- **Exfiltration:** Transfer of large-scale CSV or JSON database dumps.
- **Impact:** Massive privacy breach and exposure of PII (Personally Identifiable Information).
## Impact Assessment
- **Financial:** Exposure of partial credit card data (First 6 and Last 4 digits + expiry). Increased risk of targeted phishing/fraud for affected users.
- **Data Breach:** High volume; 865k unique emails and 58 million connection logs.
- **Operational:** Potential loss of user trust due to the exposure of logs despite "no-log" marketing.
- **Reputational:** Significant damage to brand integrity following the rebranding from NotVPN to SplitVPN.
## Indicators of Compromise
- **Network indicators:** None provided in source (recommend monitoring for unauthorized access to port 443 or 1194).
- **File indicators:** Database dumps containing SplitVPN user schema.
- **Behavioral indicators:** Unusual outbound data spikes from database servers to external IP addresses.
## Response Actions
- **Containment:** Information regarding the closing of the vulnerability is not provided in the source.
- **Eradication:** Recommendation for users to rotate credentials.
- **Recovery:** Data was integrated into breach notification services to alert affected individuals.
## Lessons Learned
- **Key takeaways:** "No-log" claims are often marketing-driven and may not reflect actual technical configurations. Even partial payment data exposure increases the risk of sophisticated social engineering.
- **What could have been done better:** Implementation of a strict zero-logs policy at the kernel level and encryption of PII at rest would have mitigated the impact.
## Recommendations
- **For the Provider:** Conduct a third-party security audit of "no-logs" infrastructure; implement hardware security modules (HSM) for payment data; enforce MFA for all administrative access.
- **For Users:**
- Change passwords immediately for SplitVPN and any service using the same credentials.
- Enable 2FA on all sensitive accounts.
- Monitor credit statements for suspicious activity related to the exposed partial card data.
- Utilize a password manager to ensure unique credential sets.