HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

VPN Provider SplitVPN Exposes 58 Million Connection Logs, Undermining “No‑Logs” Claims

SplitVPN (formerly NotVPN) leaked a 17 GB SQL dump containing 58 million connection logs, 23 million user records, and payment tokens, revealing that the service retained metadata despite public “no‑logs” promises. The breach underscores the importance of verifiable privacy controls and audit‑ready evidence for SOC 2 and data‑protection regulations.

LiveThreat™ Intelligence · 📅 July 29, 2026· 📰 securityaffairs.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
securityaffairs.com

VPN Provider SplitVPN Exposes 58 Million Connection Logs, Undermining “No‑Logs” Claims

What Happened — A threat actor posted a 17 GB SQL dump from SplitVPN (formerly NotVPN) that contains 58 million connection‑log records, 23.4 million user records, 13.6 million device records, and 2.6 million payment tokens. The data spans June 2025 through July 21 2026, showing the service was actively logging despite public “no‑logs” guarantees.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates the risk of undocumented data collection that can invalidate privacy‑by‑design assertions required by SOC 2 CC6 (Confidentiality) and privacy regulations.
  • Highlights the need for continuous evidence that logging policies are enforced and that any retained metadata is justified, documented, and auditable.
  • Aligns with Verisq’s CookiePLUS Privacy capability, which helps organizations prove consent handling, data‑minimization, and DSAR readiness.

Who Is Affected — Consumers of privacy‑focused VPN services, especially users in high‑censorship regions (Russia, Iran, India, Myanmar); broader SaaS and cloud‑infrastructure providers that rely on third‑party VPNs for remote access.

Recommended Actions

  • Map the VPN’s logging practice to SOC 2 CC6 and privacy‑law requirements; capture policy documents, retention schedules, and evidence of actual log handling.
  • Conduct a data‑flow audit to verify that no unauthorized metadata is stored; if logs exist, ensure they are encrypted, access‑controlled, and covered by a documented retention policy.
  • Update privacy notices and consent mechanisms to reflect actual data collection, and prepare DSAR response procedures for the exposed records.

Technical Notes – The dump is a raw SQL database (≈ 17 GB) containing tables deviceProxy, users, and devices. No full credit‑card numbers were present (masked to BIN + last four), but emails, IP addresses, device IDs, approximate locations, subscription status, and recurring‑billing tokens were exposed. Source: Security Affairs

📰 Original Source
https://securityaffairs.com/196197/security/vpn-breach-exposes-58-million-connection-logs-despite-no-logs-claims.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

A privacy incident is a question about your consent record.

CookiePLUS and Verisq AI Trust Operations keep consent, DSAR, and data-handling evidence continuously ready — so a data-exposure event finds you prepared, not scrambling.

See how Verisq AI Trust Operations handles privacy →