VPN Provider SplitVPN Exposes 58 Million Connection Logs, Undermining “No‑Logs” Claims
What Happened — A threat actor posted a 17 GB SQL dump from SplitVPN (formerly NotVPN) that contains 58 million connection‑log records, 23.4 million user records, 13.6 million device records, and 2.6 million payment tokens. The data spans June 2025 through July 21 2026, showing the service was actively logging despite public “no‑logs” guarantees.
Why It Matters for Compliance & Audit Readiness
- Demonstrates the risk of undocumented data collection that can invalidate privacy‑by‑design assertions required by SOC 2 CC6 (Confidentiality) and privacy regulations.
- Highlights the need for continuous evidence that logging policies are enforced and that any retained metadata is justified, documented, and auditable.
- Aligns with Verisq’s CookiePLUS Privacy capability, which helps organizations prove consent handling, data‑minimization, and DSAR readiness.
Who Is Affected — Consumers of privacy‑focused VPN services, especially users in high‑censorship regions (Russia, Iran, India, Myanmar); broader SaaS and cloud‑infrastructure providers that rely on third‑party VPNs for remote access.
Recommended Actions
- Map the VPN’s logging practice to SOC 2 CC6 and privacy‑law requirements; capture policy documents, retention schedules, and evidence of actual log handling.
- Conduct a data‑flow audit to verify that no unauthorized metadata is stored; if logs exist, ensure they are encrypted, access‑controlled, and covered by a documented retention policy.
- Update privacy notices and consent mechanisms to reflect actual data collection, and prepare DSAR response procedures for the exposed records.
Technical Notes – The dump is a raw SQL database (≈ 17 GB) containing tables deviceProxy, users, and devices. No full credit‑card numbers were present (masked to BIN + last four), but emails, IP addresses, device IDs, approximate locations, subscription status, and recurring‑billing tokens were exposed. Source: Security Affairs