A data breach tied to SplitVPN, a virtual private network provider formerly known as NotVPN, has exposed 865,336 users and roughly 58 million connection logs. The incident is drawing scrutiny because SplitVPN, like many VPN services, marketed itself on a promise of privacy: a strict no-logs policy that told users their online activity would never be recorded or stored. The breach suggests that promise did not hold up in practice.

For an industry built almost entirely on trust, this is the kind of story that reshapes how people evaluate a VPN provider's claims. Millions of people use VPNs specifically to avoid having their browsing habits tracked or retained anywhere. When a provider's own logging practices contradict its marketing, it raises hard questions not just for SplitVPN customers, but for anyone relying on a "no-logs" label as a reason to trust a service with their traffic.

What Happened in the SplitVPN Breach

According to the disclosure, the exposed data included 865,336 user records alongside approximately 58 million connection logs. That volume of connection data is significant because a genuine no-logs VPN should not be generating, let alone storing, records of user connections at that scale. The presence of tens of millions of connection logs directly undercuts the core privacy assurance that SplitVPN advertised to its user base.

SplitVPN previously operated under the name NotVPN before rebranding. The SplitVPN breach exposing 865K records and 58 million logs has already prompted broader conversation about how VPN companies verify and enforce their own privacy policies, especially smaller or lesser-known providers that may not undergo the same level of independent auditing as larger, established services.

Why the No-Logs Claim Matters So Much

The entire value proposition of a VPN rests on trust. Users route their traffic through a third-party server specifically so their internet service provider, network administrators, or other observers cannot see what they're doing online. In exchange, they place that same visibility in the hands of the VPN provider. A no-logs policy is the mechanism that is supposed to prevent the VPN company itself from becoming the point of exposure.

When a provider advertises no-logs but is later found to have been retaining connection metadata, and that metadata is then exposed in a breach, it defeats the purpose of using the service in the first place. Users didn't just have their data exposed by an outside attacker; they had their data exist in a form it was promised would never be created. This is why regulators, security researchers, and privacy advocates consistently push for independent audits of no-logs claims rather than accepting marketing language at face value.

What Data Was Exposed

The SplitVPN breach reportedly involved user account records and connection logs numbering in the tens of millions. Connection logs of this kind can potentially reveal patterns such as when a user connected, for how long, and other metadata associated with their VPN sessions. Even without full browsing history, this type of metadata can be used to infer behavior, timing, and habits that users believed were being kept private.

For affected individuals, the exposure means that information they assumed was never collected has now been tied to their accounts and potentially made accessible to unauthorized parties. That is a different and arguably more damaging scenario than a typical data breach, because it also destroys the trust basis the service was sold on.

What This Means For You

If you have ever used SplitVPN or NotVPN, it's worth treating this as a signal to review your account and change any credentials associated with the service, including reused passwords on other platforms. More broadly, this breach is a reminder that "no-logs" is a claim, not a guarantee, unless it has been independently verified. Before trusting any VPN provider with your traffic, look for evidence of third-party audits, transparency reports, or a documented history of standing behind privacy claims under scrutiny.

It's also a good moment to reassess what you expect from a VPN. A no-logs policy should mean there is nothing to leak in the first place. If a breach produces millions of connection logs from a provider that claimed not to keep them, that is a meaningful red flag about how the company actually operates behind the scenes, regardless of what its marketing states.

Actionable Takeaways

If you're a current or former SplitVPN or NotVPN user, change your account password immediately and update it anywhere else you may have reused it. Monitor your email and payment accounts for suspicious activity in the weeks following this disclosure. Going forward, choose VPN providers that publish independently audited no-logs reports rather than relying on unverified claims. And treat any privacy promise, from any provider, as something to verify rather than assume, since this incident shows how quickly a no-logs claim can be broken.