A 17 GB SQL database now circulating on the Altenen cybercrime forum has put a spotlight on one of the VPN industry's most repeated promises: the no-logs policy. The database, claimed to be stolen from SplitVPN (formerly known as NotVPN), a Russian VPN marketed specifically for bypassing internet censorship, reportedly contains around 23.4 million user records and roughly 58 million connection logs. That's a striking number for a service that built its marketing around the idea that it doesn't keep logs at all.

This isn't just a story about one VPN provider getting hacked. It's a reminder that a privacy policy is only as good as the practices behind it, and that the VPN no-logs claims breach at SplitVPN illustrates exactly why users need to look past marketing copy before trusting a provider with their traffic.

What Happened in the SplitVPN Breach

According to reporting from Security Affairs, a threat actor began distributing the database on a known cybercrime forum, and researchers at Mysterium obtained a copy and verified it against the raw dump. Their analysis confirmed the scale: millions of user accounts, device information, payment details, and connection metadata, all allegedly pulled from a service whose entire value proposition rested on not retaining exactly this kind of data.

We covered the technical breakdown of the exposed dataset in detail in our earlier piece on the SplitVPN breach exposing 58 million logs, including what categories of data were reportedly included and how the leak was verified. If you use or have used SplitVPN, that coverage is worth reading in full, since it lays out what information may have been exposed and what steps affected users should consider.

The core issue isn't just that a breach happened. Breaches happen to companies across every industry. The issue is the gap between what SplitVPN told users about its data practices and what the leaked database appears to show. If a VPN advertises itself as a censorship-bypassing tool with no logging, and a stolen database shows tens of millions of connection records, that's not a minor discrepancy. It's a direct contradiction of the product's core promise.

Why Connection Logs Undermine No-Logs Promises

Connection logs are not the same as browsing history, but they can still be deeply revealing. A connection log typically records when a user connected to a VPN server, which server they used, how long the session lasted, and sometimes the IP address they connected from. For a VPN marketed toward people trying to get around internet censorship, that kind of metadata can be sensitive on its own, since it can potentially be used to establish patterns of when and how someone accessed the internet, even without knowing exactly what they did once connected.

A genuine no-logs policy means a provider architects its systems so that this information simply isn't retained, whether through RAM-only servers, session data that's discarded immediately, or infrastructure that never writes connection metadata to disk in the first place. When a breach reveals millions of connection logs sitting in a database, it suggests the provider was collecting and storing exactly the kind of information its marketing said it wouldn't. That's the central problem the SplitVPN incident illustrates: the promise and the practice apparently didn't match.

How to Verify a VPN's No-Logs Claims Before Trusting It

Marketing pages are easy to write. Verifiable proof is harder to fake, and it's what separates a credible no-logs claim from an empty one. Before trusting a VPN with your traffic, look for a few concrete signals:

Independent audits matter more than self-reported policies. A reputable third-party security firm reviewing a provider's server configuration and confirming that no identifying logs are stored carries far more weight than a paragraph on a privacy policy page.

Court cases and law enforcement requests can serve as real-world tests. If a provider has previously been compelled to hand over user data and simply had none to give, that's a stronger signal than an unverified claim.

Transparency reports, jurisdiction, and ownership history all matter too. A provider based in a country with strong data protection laws, publishing regular transparency reports, and with a clear ownership structure is generally easier to hold accountable than one that obscures who runs it.

Checklist: Red Flags When Choosing a Privacy-Focused VPN

As you evaluate a VPN provider, watch for these warning signs: no independent audit has ever been published or the audit is years out of date; the company's ownership or jurisdiction is unclear or frequently changes; the privacy policy uses vague language about "anonymized" or "aggregated" data without explaining what's actually collected; there's no transparency report or history of responding to legal requests; and the service has previously rebranded (as SplitVPN did from NotVPN) without a clear explanation of what changed operationally.

What This Means For You

If you're currently using SplitVPN, treat this as a signal to review the coverage on the SplitVPN breach exposing 58 million logs and consider whether your account, device, or payment information may have been included in the exposed database. More broadly, this incident is a useful prompt to re-examine any VPN you rely on, not because every provider is lying about its logging practices, but because trust in this space should be earned through verification, not assumed from a marketing page.

The VPN no-logs claims breach at SplitVPN doesn't mean no-logs VPNs are a myth. It means the label alone isn't proof. Providers that can point to independent audits, consistent transparency reporting, and a track record of protecting user data under legal pressure have earned a different level of trust than those relying on marketing language alone.

Actionable Takeaways

Check whether your VPN provider has undergone a recent, publicly available independent audit of its no-logs claims. Look into the provider's jurisdiction and ownership history, since these affect what data can legally be compelled from them. Read transparency reports if the provider publishes them, and treat their absence as a gap worth questioning. If you were a SplitVPN user, review the details of the exposed dataset and consider changing any reused passwords or payment information tied to that account. And going forward, choose privacy tools based on verifiable evidence rather than promises alone.