A major data leak has hit SplitVPN, formerly known as NotVPN, exposing personal information for around 865,000 unique users. In July 2026, SplitVPN experienced a breach that resulted in the exposure of millions of customer records, including 865,300 unique email addresses. The broader breach is believed to have originated from a 17 GB SQL database stolen directly from SplitVPN's infrastructure by a threat actor who began distributing it on the cybercrime forum Altenen.

Security researchers from Mysterium later obtained and verified the dump, confirming it contained approximately 23.4 million user records, 13.6 million device records, and 2.6 million payment records alongside nearly 58 million connection logs.

SplitVPN Data Breach Beyond the headline email figure, the exposed dataset includes users' IP addresses, their country of residence, and partial payment card information limited to the first six and last four digits, along with the card's expiry date. Additional fields reportedly present in the broader leaked database include device identifiers, approximate geographic locations, subscription status, and recurring-billing tokens. Yet a leaked database reportedly contained a table tracking device-to-server connections, logging nearly 58 million entries from June 2025 through July 21, 2026—the very day of the breach dump’s date.

These logs did not capture browsing destinations or visited websites but linked specific devices and accounts to particular VPN servers at precise timestamps, undermining users’ expected anonymity.