[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1nt86mw66a3u6":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":29,"seoTitle":30,"seoTitleEn":31,"seoDescription":30,"seoDescriptionEn":32,"logoUrl":33,"isVerified":4,"isSensitive":34,"isSpamList":34,"isMalware":34,"company":35},"6a6f57b3fb664a09b21dc7a0","SplitVPN2026","SplitVPN 2026 Data Breach","splitvpn-2026","splitvpn.io","2026-07-21T00:00:00.000Z","2026-08-02T14:44:02.926Z","2026-08-02T14:51:28.514Z","Database leak","https:\u002F\u002Fwww.mysteriumvpn.com\u002Fblog\u002Fnews\u002Fnotvpn-splitvpn-breach-58-million-logs",[15,17],"https:\u002F\u002Fsecurityaffairs.com\u002F196197\u002Fsecurity\u002Fvpn-breach-exposes-58-million-connection-logs-despite-no-logs-claims.html",865336,"known",null,"accounts","High",[24,25,26,27,28],"Device information","Email addresses","Geographic locations","IP addresses","Partial credit card data","\u003Cp>\u003Cstrong>The SplitVPN 2026 data breach\u003C\u002Fstrong> came to light after a database copy dated July 21, 2026, allegedly taken from the VPN service previously known as NotVPN, was distributed on a cybercrime forum. A verified public breach catalog confirmed that the incident contained 865,336 unique email addresses.\u003C\u002Fp>\n\u003Cp>Technical analysis found email-linked IP addresses and device information across user, device, payment, and connection tables. The much larger table totals describe different measurements and must not be added together or presented as a count of affected people.\u003C\u002Fp>\n\u003Ch2>How Was the SplitVPN Breach Verified?\u003C\u002Fh2>\n\u003Cp>Mysterium’s research team examined a copy of the 17 GB SQL database offered on the forum. It compared table schemas, counters, and the structure of sampled records and reported that the data was genuine. The internal database name “notvpn” also connected SplitVPN to its former NotVPN identity.\u003C\u002Fp>\n\u003Cp>Security Affairs separately reported the technical findings and exposed-data scope on July 29, 2026. The independent breach catalog added the incident as a verified breach on August 1, listing 865,336 unique email addresses and device, location, IP, and partial payment-card data. No incident notice issued by SplitVPN was found in the sources reviewed.\u003C\u002Fp>\n\u003Ch2>What Happened on July 21, 2026?\u003C\u002Fh2>\n\u003Cp>A threat actor published an SQL database claimed to be from SplitVPN on the Altenen forum and dated the copy July 21. Researchers found that its structure broadly matched the advertised scope. The sources do not establish when the first unauthorized access occurred or how the database was obtained.\u003C\u002Fp>\n\u003Cp>Timestamps in the connection table ran from June 2025 through July 21, 2026. The entries showed when a device connected to a particular VPN server; they were not confirmed to contain the full browsing history or destination websites. Even so, combining email, IP, and time data can allow activity to be linked to an account.\u003C\u002Fp>\n\u003Ch2>What Information Was Exposed?\u003C\u002Fh2>\n\u003Cp>The confirmed data classes are email addresses, IP addresses, approximate geographic locations, device information, and partial payment-card data. Researchers also reported device identifiers, app and operating-system details, push-notification tokens, language, country, and subscription-status fields.\u003C\u002Fp>\n\u003Cp>Payment records reportedly contained the first six and last four card digits, expiration dates, payment identifiers, and recurring-billing tokens. Full card numbers were not confirmed as exposed. Password data does not appear among the user data classes confirmed by the public catalog.\u003C\u002Fp>\n\u003Ch2>How Many Accounts Were Affected?\u003C\u002Fh2>\n\u003Cp>The public catalog identified 865,336 unique email addresses in the dataset. The catalog’s affected-account figure follows that verified, deduplicated email measurement; it should not be interpreted as a definitive count of every person affected by the incident.\u003C\u002Fp>\n\u003Cp>The primary research reported approximately 23.4 million user records, 13.6 million device records, 2.6 million payment records, and 58 million connection records. These are row counts from different tables. One user may appear in several tables or multiple times in one table, so the figures cannot be summed into a people count.\u003C\u002Fp>\n\u003Ch2>Why Is This Incident High Risk?\u003C\u002Fh2>\n\u003Cp>In some countries, VPN use may be associated with access to news, messaging services, or blocked websites. When email, last-seen IP, approximate location, device, and connection time are combined, they may support sensitive inferences about when a particular account used a VPN.\u003C\u002Fp>\n\u003Cp>Partial card data is not enough by itself to complete an online purchase. Combined with an email address, payment history, and subscription context, however, it can make bank- or subscription-themed fraud more convincing. Messages offering breach support, refunds, or “account verification” should be checked independently.\u003C\u002Fp>\n\u003Ch2>What Should SplitVPN and NotVPN Users Do?\u003C\u002Fh2>\n\u003Cp>Enable multi-factor authentication on the associated email account, review active sessions, and change any password reused on other services. SplitVPN’s official site sends sign-in codes by email, making control of the mailbox especially important. Do not approve an unexpected sign-in code or reset message.\u003C\u002Fp>\n\u003Cp>Users who paid through Tinkoff or another provider should watch card and subscription activity for an unfamiliar charge and contact the bank through the official number on the card if one appears. A message that knows an email, IP address, or VPN context is not automatically legitimate; never disclose a one-time code, full card details, or identity document in response.\u003C\u002Fp>","","SplitVPN 2026 Data Breach (865.3 Thousand Accounts Affected)","The SplitVPN and former NotVPN breach exposed 865,336 email addresses alongside IP, device, location, and partial payment-card data.","https:\u002F\u002Fsplitvpn.io\u002Fbuild\u002Fassets\u002Flogo-CSu-pg8M.svg",false,{"name":36,"sector":37,"country":30,"website":10,"websiteArchiveUrl":30,"websiteStatus":38,"websiteCheckedAt":12},"SplitVPN Technologies LLC","Technology","active"]