VPN Breach Exposes 58 Million Connection Logs Despite “No-Logs” Claims
A breached “no-logs” VPN exposed 58 million connection logs and millions of user, device, and payment records, contradicting its privacy claims. A threat actor on the Altenen cybercrime forum is distributing a 17 GB SQL database claimed to have been stolen from SplitVPN, formerly known as NotVPN, a Russian VPN marketed for bypassing internet censorship. […]

A threat actor on the Altenen cybercrime forum is distributing a 17 GB SQL database claimed to have been stolen from SplitVPN, formerly known as NotVPN, a Russian VPN marketed for bypassing internet censorship. Mysterium’s research team obtained a copy, verified it against the raw dump, and confirmed the numbers: roughly 23.4 million user records, 13.6 million device records, 2.6 million payment records, and 58 million connection logs. A VPN that promised zero logs kept tens of millions of them.
“NotVPN’s own marketing promises “No logs or history: We never store your activity or connection logs. 100% privacy guaranteed.” The database contains a table (deviceProxy) that records which device connected to which server, and exactly when — nearly 58 million times, right up to the day of the breach.” states Mysterium’s research team. “No full credit-card numbers were exposed (card data is masked to BIN + last four). But emails, IP addresses, device identifiers, approximate location, subscription status, and recurring-billing tokens were.”
Related breach coverage
- ShinyHunters Claims Ernst & Young Data Breach, Threatens to Leak Stolen Data2026-07-29
ShinyHunters claimed the Ernst & Young data breach, threatening to leak stolen tax records unless the firm contacts the group by July 31. The ShinyHunters cybercrime group has taken responsibility for the recently disclosed data breach involving professional services firm Ernst & Young (EY), adding the company to its Tor-based leak site and threatening to […]
- Australian energy provider Origin Energy disclosed a data breach impacting customer data2026-07-25
Origin Energy confirmed a data breach after a hacker claimed to have stolen data from 2 million customers and threatened to leak it. Origin Energy disclosed a cyberattack that exposed customer data after a hacker claimed to have stolen records belonging to 2 million customers and threatened to publish them. An alleged hacker calling themselves […]
- New Russian Campaign Uses Fake Webex and Zoom Installers to Deploy Starland RAT2026-07-17
Russian-speaking UAT-11795 spreads trojanized Zoom, Webex, and MobaXterm installers to deliver Starland RAT and the WLDR memory-only implant. Cisco Talos researchers published a detailed technical report on July 16 disclosing UAT-11795, a financially motivated, Russian-speaking threat actor that has been running a malware campaign against users in the United States and Europe since at least […]
- Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims2026-07-14
The D1R cybercrime group claimed to have stolen valuable data from Synopsys and Bosch, threatening to leak it unless a ransom is paid. The post Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims appeared first on SecurityWeek.
