A VPN that promised "no logs" and "100% privacy" just leaked its users. In August 2026, SplitVPN, a Russian service formerly known as NotVPN, was added to Have I Been Pwned with 865,336 unique email addresses exposed, and the stolen database reportedly held nearly 58 million connection logs the company said it never kept. If you want the short version of the no-logs VPN breach: a privacy promise printed in marketing is not the same as privacy built into the architecture, and this incident is the difference made painfully visible.
This post walks through what actually happened, what "no logs" is supposed to mean versus what investigators found, how to check whether you were affected, what to do if you were, and how to judge whether any privacy app keeps the promise on its landing page. The lesson generalizes far beyond one VPN.
What happened to SplitVPN
SplitVPN was breached on July 21, 2026, and the compromised data was added to Have I Been Pwned on August 1, 2026, covering 865,336 unique email addresses. HIBP lists the exposed data classes as device information, email addresses, geographic locations, IP addresses, and partial credit card data. The service previously operated under the name NotVPN before rebranding.
The scale reported by researchers is larger than the headline email count suggests. According to reporting from Cybersecurity News, the leaked dataset contained roughly 23.4 million user records, 13.6 million device records, and 2.6 million payment records, plus nearly 58 million connection logs. A separate write-up put the stolen SQL database at about 17 GB and noted it was distributed on a cybercrime forum after the intrusion. The 58 million log figure comes from breach reporting rather than the company, so treat it as reportedly accurate pending SplitVPN's own accounting.
The exposed fields went well past an email address. Reporting describes IP addresses, country of residence, device identifiers, subscription status, partial payment card data (the first six and last four digits plus expiry), and recurring billing tokens. Researchers also reported administrative accounts with password hashes and operator action logs in the dump. Users were said to be concentrated in Russia, Iran, India, and Myanmar, places where a VPN is often the tool people use to get around censorship, which raises the stakes of a connection log far above the average marketing pitch.
Separate the confirmed from the alleged. The 865,336 email figure and the exposed data classes are the parts Have I Been Pwned verified against the dataset. The larger record and log counts come from security researchers who examined the raw dump, and one team reported cross-checking those numbers before publishing. SplitVPN has not published its own accounting of what was taken. When a single source carries a specific number, such as the 58 million connection logs, the honest framing is reportedly, not confirmed, and that distinction is the whole reason to read breach coverage carefully rather than the loudest headline.
What "no logs" is supposed to mean, and what was found
"No logs" is supposed to mean the provider does not record which sites you visit, when you connect, or from what IP address, so there is nothing to hand over, sell, or lose. A genuine no-logs design keeps the smallest amount of data needed to run the service and nothing that ties an identity to an activity. If the data does not exist, a breach cannot expose it. That is the entire point of the promise.
What investigators reported finding was the opposite. SplitVPN advertised a "No logs or history" policy with "100% privacy guaranteed," yet the leaked database reportedly contained a table tracking device-to-server connections running from June 2025 through the day of the breach in July 2026. One analysis put it bluntly, noting the service was still writing connection logs as it was being breached. A no-logs claim and a live logging table cannot both be true.
Why does a connection log matter so much? For a VPN, the log is the one record that can tie a real person to the traffic they wanted hidden. A person in a country that censors the internet uses a VPN precisely so no one can prove which sites they reached or when. A retained connection table, matched to an email and an IP, can reconstruct exactly that. The sensitivity of the data is inversely related to how much anyone should be storing it, and a no-logs service is supposed to store none of it.
A marketing promise and a database schema are two different things. The promise lives on the website. The schema decides what a breach can leak. When they disagree, the schema wins, and users find out only after the leak.
How to check if you were in the SplitVPN breach
Check Have I Been Pwned. The SplitVPN breach is a confirmed entry, so you can enter your email address at haveibeenpwned.com and it will tell you whether your address appears in this dataset (and any others). This is the fastest, most reliable answer to "was I in the SplitVPN breach."
- Search the exact email you used to sign up for the VPN, then repeat for any other addresses you use, because people often register with a secondary email.
- Turn on HIBP notifications so you are alerted automatically if that address surfaces in a future breach.
- Assume more than your email was exposed. The reporting describes IP addresses, device identifiers, partial card data and billing tokens in the same dataset, so a hit means treating the account as fully compromised, not just the email.
- If you paid by card, watch the statement for that card, since the first six and last four digits plus expiry were reportedly in the dump.
A partial card number (first six and last four digits) is not enough to charge your card by itself, but combined with your email and country it is enough for a convincing targeted phishing message. Be extra skeptical of any "billing problem" email that arrives in the weeks after a breach.
What to do if you were affected
Act as if the whole record leaked, because it likely did. The steps below are ordered by how much they reduce real risk, starting with the account itself and moving outward.
- Change the VPN account password immediately, and change it anywhere else you reused that same password. Reuse is how one breach becomes five.
- Turn on two-factor authentication on your email and any account that shared the password, so a stolen password alone is not enough to get in.
- Contact your bank or card issuer if you paid by card, mention the breach, and ask them to watch for or reissue the card. Reissuing kills the exposed billing token.
- Treat unexpected emails, calls or texts referencing your VPN, your card, or your location as suspect. Breach data is fuel for tailored phishing.
- Reconsider the provider. A service that advertised no logs while writing them, then lost them, has told you what it values. Moving to an audited alternative is a reasonable response.
None of these steps undo the exposure. A connection log, once leaked, cannot be recalled, and neither can a location or a device fingerprint. That is why the real defense is choosing tools that never collect the sensitive data in the first place, which is the next question worth answering. The order matters: react to the current breach today, then change the pattern that made you vulnerable to the next one.
How to tell if your VPN or privacy app is actually safe
Judge the architecture, not the adjective. "Private," "secure" and "no logs" are words anyone can print. The signals that actually predict whether an app protects you are structural, and you can check most of them before you sign up.
Look for an independent audit, not a self-declaration
A meaningful no-logs claim is verified by an outside firm that inspects the servers and configuration, then publishes a report. In the SplitVPN case, the contradiction was surfaced by outside researchers examining the raw dump, which is exactly the kind of scrutiny a company should invite before a breach forces it. Ask when the last audit was, who ran it, and whether the full report is public.
Check for data minimization
The strongest privacy signal is how little a service collects. If the connection logs, device IDs and billing tokens had never been stored, the breach would have had far less to expose. Read the privacy policy for what is actually retained and for how long, and be wary of any service that keeps a detailed history it does not need to operate.
Prefer architecture over slogans
Ask where your data lives, who holds the encryption keys, whether it is encrypted at rest, and whether the company can read it or train on it. These are answerable, technical questions. A company that can explain its isolation model and key management is describing privacy it built. A company that answers only with "we take your privacy seriously" is describing a slogan.
A useful test is to imagine the breach before it happens. Picture the company's database sitting on a criminal forum, exactly as SplitVPN's reportedly ended up, and ask what a reader of that file could learn about you. If the honest answer is "almost nothing, because it was never collected or it is encrypted with keys the company does not hold," the architecture is doing its job. If the honest answer is "my location history, my devices and my billing details," then the slogan on the homepage was never protecting you in the first place.
| Signal | No-logs slogan | Privacy by architecture |
|---|---|---|
| What backs the claim | A marketing line on the website | Isolation, key management and retention limits you can inspect |
| Data collected | Often more than admitted, as SplitVPN showed | Minimized to what the product needs to function |
| Who can read your data | Whoever holds the database, and anyone who breaches it | Scoped by per-user isolation and customer-managed keys |
| What a breach exposes | Everything quietly retained, including logs said not to exist | Far less, because sensitive data was never pooled or kept |
| How you verify it | You take it on faith | Independent audits, published retention, technical answers |
Where MemX fits this lesson
The gap between a privacy promise and a privacy design is the reason MemX was built the way it is. MemX is a personal memory app: you save documents, photos, voice notes and messages, then ask a question and get the answer with its source. That means it holds some of the most personal material you own, so "trust us" was never going to be the answer.
Instead, MemX is private by architecture. Your data sits behind per-user isolation, it is protected with customer-managed encryption keys, it is encrypted at rest, and it is not used to train models. Those are properties of how the system is constructed, not a phrase on a pricing page. MemX does not claim to be end-to-end encrypted or zero-knowledge, because honest architecture matters more than a bigger-sounding label. The point of the SplitVPN story is that the label is exactly what fails you at the worst moment. A design that never pools sensitive logs in the first place is what holds up when someone breaks in.
Before you trust any app with personal data, ask the same three questions you would ask a VPN: what do you collect, who can read it, and can you prove it. If the only answer is a slogan, keep the app at arm's length.
Frequently asked questions
01Was I in the SplitVPN breach?
Check haveibeenpwned.com and search the email you used for the VPN. The SplitVPN breach is a confirmed entry added on August 1, 2026, covering 865,336 email addresses. A match means your record was in the leaked dataset, so treat the whole account as compromised.
02How many people did the SplitVPN breach affect?
Have I Been Pwned lists 865,336 unique email addresses. Researchers reported a much larger dataset behind that, including roughly 23.4 million user records and nearly 58 million connection logs, though those larger figures come from breach reporting rather than the company itself.
03What data was leaked?
According to HIBP and reporting: email addresses, IP addresses, geographic locations, device information, and partial credit card data (first six and last four digits plus expiry). Researchers also described billing tokens and connection logs, which the service had claimed not to keep.
04Do VPNs really keep no logs?
It can, but only when an independent audit verifies it and the provider minimizes what it stores. SplitVPN advertised no logs while reportedly keeping a live connection table for over a year. Trust the audit and the retention policy, not the phrase on the homepage.
