What the SplitVPN Breach Exposed
A newly disclosed data breach has put SplitVPN, a virtual private network provider, at the center of an uncomfortable question that keeps resurfacing across the VPN industry: what happens when a company that promises not to log your activity turns out to have logged it anyway.
According to reporting on the incident, the breach exposed roughly 865,000 user records along with full payment-card numbers. That alone would be a serious incident for any online service. But the scope goes well beyond billing information. The exposed database reportedly included administrative accounts complete with password hashes, logs tracking the actions of SplitVPN's own operators, and infrastructure details tied to provisioning App Store accounts. Security researchers who reviewed the leak have noted that the presence of admin-level credentials and internal operational data suggests the breach may extend further than the user-facing records alone would indicate.
Perhaps the most consequential detail, however, is the discovery of 58 million hidden connection logs inside the same database. For a VPN provider, that single number does more damage to trust than the payment-card exposure or the admin credential leak combined.
Why 58 Million Logged Connections Contradict No-Logs Claims
The entire value proposition of a VPN rests on a simple promise: your provider routes your traffic, encrypts it, and does not keep a record of what you did or when you did it. Providers market this as a "no-logs policy," often the single most repeated phrase in VPN advertising. It is the reason privacy-conscious users pay for the service in the first place.
A database containing 58 million connection logs is not a hypothetical technicality. It is direct evidence that whatever policy SplitVPN advertised to its customers did not match what was actually happening on its servers. Connection logs of this kind typically capture information like timestamps, session duration, and originating or destination IP addresses, precisely the metadata that a genuine no-logs architecture is designed to avoid retaining. When that data ends up sitting in a breachable SQL database alongside payment information and admin credentials, it confirms the logs existed long enough, and in a retrievable enough format, to be stolen.
This is not the first time a VPN's no-logs marketing has been contradicted by a leak, and it will not be the last. But the scale here, tens of millions of individual connection records tied to hundreds of thousands of user accounts, makes SplitVPN a stark case study in the gap between what providers say and what they store. For a deeper breakdown of exactly what the leaked database contains and why the logging contradiction matters, our earlier coverage of the SplitVPN breach and its no-logs claims walks through the specifics in more detail.
How to Vet a VPN Provider's Security and Logging Practices
The SplitVPN incident is a useful reminder that a no-logs claim printed on a marketing page is not verification, it is a promise. Readers evaluating any VPN provider, whether they used SplitVPN or not, should look for a few concrete signs of accountability rather than taking policy language at face value.
Independent, third-party security audits are the closest thing to real verification currently available. A provider that has commissioned an outside firm to examine its server configurations and confirm logs are not retained gives users something more substantial than a written policy. It's also worth checking whether a provider has a documented history of transparency reports, disclosed breaches handled openly, and a clear data retention schedule for billing and account information, since payment data is often the part users overlook when focusing purely on browsing logs. The analysis of SplitVPN's no-logs contradiction covers additional questions worth asking before trusting any provider's privacy claims.
What This Means For You
If you are a current or former SplitVPN user, treat this as an active incident requiring action, not just a headline to skim past. The exposure of payment-card numbers means your financial information could be at risk of fraud. The exposure of connection logs means activity you believed was never recorded may now be tied to your account. And the exposure of admin credentials means the underlying platform itself may not be secure until SplitVPN confirms remediation.
Steps to Take If You Were a SplitVPN User
Cancel or replace the payment method linked to your SplitVPN account and monitor statements closely for unauthorized charges. Change your SplitVPN password immediately, and if you reused that password anywhere else, change it there too. Enable two-factor authentication on any account where it's available. Watch for phishing attempts that reference this breach, since attackers often use leaked data to craft convincing follow-up scams. Finally, if you are shopping for a new VPN, prioritize providers with independently audited no-logs claims rather than self-reported policies alone.
The SplitVPN data breach no-logs contradiction is a clear signal that privacy promises need proof, not just marketing copy. Users deserve providers that can demonstrate their claims, not just state them.




