01Summary
A threat actor posted a SQL dump dated 21 July 2026 on the Altenen forum, describing SplitVPN as a Russian VPN for bypassing blocks. Its users are in Russia, Iran, India and Myanmar. The dump holds about 58 million device-to-server connection records from June 2025 to July 2026, about 23.4 million user records (around 865,000 unique emails), 13.6 million device records and 2.6 million payment records. It also contains IP addresses, device IDs, approximate locations and recurring-billing tokens. The logs do not show browsing destinations, but they contradict the service's "100% privacy guaranteed" and no-logs promises.
02Key revelations
- 01A "no-logs" VPN was logging every connection.
03Victims and impact
Countries affected
- Russia
- Iran
- India
- Myanmar
04Data exposed
Data types
- VPN connection logs
- Email addresses
- IP addresses
- Device identifiers
- Approximate location
- Payment tokens
05Timeline
- 2026-07-21Database dump date.
- 2026-07-29Leak reported publicly.
06Significance and legacy
Significance
Puts VPN users in authoritarian states at risk of identification.
07Disclosure and media
Publishing organisations
- Security Affairs
- SC World
- Bitdefender
08Sources
References
- [1]Security Affairs: https://securityaffairs.com/196197/security/vpn-breach-exposes-58-million-connection-logs-despite-no-logs-claims.html
- [2]Bitdefender: https://www.bitdefender.com/en-us/blog/hotforsecurity/splitvpn-breach-58-million-connection-logs









