CYBERSECURITYTRACKER
TRACKING6,767 stories in this site build1,408 vulnerability news stories in this site build
Permanent story citation

A “No-Logs” VPN That Kept 58 Million Connection Logs: Inside the NotVPN / SplitVPN Breach

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3693

As cited

Copy frozen at (site build).

breaches incidents

A “No-Logs” VPN That Kept 58 Million Connection Logs: Inside the NotVPN / SplitVPN Breach

A threat actor posted a 17 GB SQL database allegedly stolen from SplitVPN (formerly NotVPN), a Russian VPN service that claimed to maintain no logs. MysteriumVPN's research obtained and analyzed the data, which reportedly contains connection logs contradicting the service's privacy claims.

Why it matters: Users of SplitVPN and similar no-logs VPN services face credential exposure and connection history disclosure, forcing practitioners to assess whether their organization or users relied on this service for sensitive traffic and to verify actual privacy practices of their VPN vendors.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

breaches incidents

A “No-Logs” VPN That Kept 58 Million Connection Logs: Inside the NotVPN / SplitVPN Breach

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

breaches incidents

A “No-Logs” VPN That Kept 58 Million Connection Logs: Inside the NotVPN / SplitVPN Breach

A threat actor posted a 17 gigabyte database allegedly stolen from SplitVPN, a Russian virtual private network (VPN) service, on the Altenen cybercrime forum. The compromised database contains approximately 58 million connection logs despite the service's advertised no-logs policy. MysteriumVPN's research team obtained and analyzed the data.

Why it matters: Users of SplitVPN and similar services with no-logs claims face exposure of their connection history and IP addresses; practitioners should treat such privacy guarantees with skepticism and verify through technical audits.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary