Skip to main content
Back to overview
High

SplitVPN Leaks Personal Data of 865,000 Users

VPN provider SplitVPN, previously known as NotVPN, has suffered a data leak exposing the personal data of 865,000 users.

Key points

  • VPN provider SplitVPN, previously known as NotVPN, has suffered a data leak exposing the personal data of 865,000 users. The compromised information, recently obtained and now circulating online, includes email addresses, device data, geographical lo
  • SplitVPN Leaks Personal Data of 865,000 Users

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Error · Confidentiality impact

Threat source not confirmed

03

Potential impact

Data Exposure

Confidentiality

Published
Jan 1, 2026
Updated
Aug 6, 2026
Confidence
High
Evidence
2 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch process controls, misconfiguration and accidental disclosure paths.

Business impact

Potential data exposure
Impact area
Confidentiality
Likely asset
User or customer data

Mentioned entities

SplitvpnData DisclosureUsers VPNSplitVPNNotVPNAdditionallyIDsRussian VPNHave I Been PwnedVPN

Quick context

Questions about this signal

What happened in this signal?

VPN provider SplitVPN, previously known as NotVPN, has suffered a data leak exposing the personal data of 865,000 users. The compromised information, recently obtained and now circulating online, includes email addresses, device data, geographical locations, IP addresses, and partial credit card details (first six and last four digits, plus expiration date). Additionally, 58 million proxy logs, containing user IDs, IP addresses of used proxy servers, and visited locations, were exfiltrated. SplitVPN, a Russian VPN provider, had claimed to not store user activity or connection logs. The method of data theft has not been disclosed. The affected email addresses have been added to the Have I Been Pwned data breach search engine. It was noted that 37 percent of the stolen email addresses had already been compromised in previous data leaks.

When was this signal reported?

Shadow Tier lists Jan 1, 2026 as the signal date.

Which organization is connected to this signal?

Splitvpn is the organization connected to this public signal.

Explore Splitvpn
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence