A 'No-Logs' VPN's Database Surfaces Online
A stolen 17 GB SQL database allegedly belonging to SplitVPN, the VPN service previously known as NotVPN, has surfaced online, and the contents directly contradict the company's long-standing no-logs privacy promise. According to an analysis of the leaked data, the database contains roughly 23.4 million user records, 13.6 million device records, and 2.6 million payment records. That combination of personal, device, and financial data is precisely what a genuine no-logs VPN service should never be able to collect, let alone lose in a breach.
The leak reportedly began circulating on the Altenen cybercrime forum, a venue frequently used to distribute stolen databases before they get resold or picked apart by other threat actors. Once a dataset like this reaches that kind of forum, it tends to spread quickly across other criminal marketplaces, making containment nearly impossible. For a VPN provider, whose entire value proposition rests on the promise of not retaining user activity or identity data, this kind of exposure is about as damaging as it gets.
Why the 'No-Logs' Claim Is Now in Question
VPN providers market no-logs policies as a core selling point: the idea that even if a government or attacker demanded user data, there would be nothing to hand over. SplitVPN's situation shows why those claims deserve scrutiny rather than blind trust. A separate breakdown of the same incident found that the exposed data also included tens of millions of connection logs, as detailed in a related report on SplitVPN's exposure of 58 million logs despite its no-logs vow. Connection logs, device identifiers, and payment records are not the kind of information a provider can plausibly claim it never stored.
This gap between marketing language and actual data practices is not unique to SplitVPN, but the scale here makes it a notable case study. Millions of users chose the service specifically because it promised privacy, and many likely used it in regions where anonymity matters for personal safety, not just convenience. When a provider's internal practices don't match its public claims, the consequences extend beyond embarrassment. They can put real people at risk, particularly those relying on the service to mask their identity or location.
A closer look at the leaked database and its origins is worth reading in full, including how the no-logs claim came under fire in the first place. A deeper examination of that question is available in this analysis of why SplitVPN's no-logs claims need verification, which walks through the disconnect between the policy SplitVPN advertised and the data it apparently retained.
What This Means For You
If you have ever used SplitVPN or its predecessor, NotVPN, treat this as a signal to act, not just read about. The exposed dataset reportedly includes payment records, meaning financial details tied to your account could be part of the leak. Device records suggest that identifiers linked to your specific hardware may also be exposed, which can make it easier for bad actors to correlate your VPN usage with your real identity across other services.
More broadly, this breach is a reminder that a VPN's privacy policy is only as good as the company's actual infrastructure and security practices. A no-logs claim printed on a website is a marketing statement, not a technical guarantee. Providers that are serious about the promise typically undergo independent audits of their systems, and even then, breaches of billing systems or device metadata can still happen if a company collects more than it should for support or fraud-prevention purposes.
What SplitVPN Users Should Do Now
Start by assuming your email address, and possibly payment information, has been exposed. Change your SplitVPN account password immediately, and update the password anywhere else you may have reused it, since credential reuse is one of the most common ways a single breach turns into multiple account compromises. If you paid via credit card, monitor your statements closely for unauthorized charges and consider contacting your card issuer if anything looks unfamiliar.
It's also worth reviewing whether you still want to use the service at all. A breach of this scale, involving data a no-logs provider should not have retained in the first place, is a legitimate reason to look elsewhere. When evaluating any VPN going forward, look for providers that have published independent third-party audits of their no-logs claims, rather than relying on marketing copy alone.
The Bigger Picture on VPN Trust
The SplitVPN incident lands at a moment when VPN adoption continues to grow among people seeking basic privacy protections online. That growth makes incidents like this one more consequential, not less. A single breach affecting tens of millions of records erodes trust not just in one provider, but in the broader idea that a VPN subscription automatically means privacy. It doesn't. Privacy depends on what a company actually does behind the scenes, not what it claims on its homepage.
For now, affected users should focus on securing their accounts and finances, and everyone else should take this as a prompt to ask harder questions before trusting any provider with their data. Reading independent audits, checking a company's breach history, and understanding exactly what data a service collects are simple steps that go a long way toward avoiding the next headline like this one.




