Skip to main content
LiMP VPN
All news

"No-Logs" VPN Breach Exposes 58M Connection Logs

"No-Logs" VPN Breach Exposes 58M Connection Logs

In short: A VPN service called SplitVPN (formerly NotVPN) suffered a data breach in July 2026: a 17 GB database with roughly 23.4 million user records went up for sale — and it contained nearly 58 million connection logs, directly contradicting the provider's "no-logs" promise. The logs run from June 2025 to 21 July 2026 and are detailed enough to reconstruct who connected, from where, to which server, and when. The lesson is not "VPNs are unsafe" but that "no-logs" is a marketing claim you cannot verify yourself — so it matters who runs the service and how it is designed.

What happened

In late July 2026 attackers put up for sale a 17 GB SQL database they said was stolen from SplitVPN. According to analyses published by security researchers, the archive holds about 23.4 million user records, 13.6 million device records and 2.6 million payment records — email addresses, IP addresses, user countries, device identifiers and subscription statuses among them. The most damaging part is what the service claimed it never kept: roughly 58 million connection logs, updated continuously from June 2025 until the day of the dump.

That single detail turns a routine breach into a privacy failure. A leaked email or password is bad, but changeable. A connection log is a map of your movements online — and this is exactly the data a genuine no-logs VPN is supposed to never write down. When the very records that were promised not to exist show up in a 17 GB file on a forum, the promise was never real.

Why "no-logs" is hard to verify

A VPN routes all of your traffic through its servers, so the provider is in a position to see and record a great deal: which server you used, your source IP, timestamps, data volumes. "No-logs" means the provider chooses not to store this. The problem is that the choice is invisible to the user — you cannot open the server and check. The claim is only as good as the company making it and, ideally, an independent audit that inspects the actual configuration.

SplitVPN kept logging for reasons providers usually cite quietly: billing, anti-fraud, capacity planning. Whatever the motive, the effect for users is the same as with the free apps we covered when popular free VPNs were caught leaking data — the data you were told did not exist becomes a liability the moment the provider is breached.

What is at risk for users

For the 23 million people in the database, the exposure is layered. Email plus subscription status invites targeted phishing. Email plus last-known IP and device ID can tie an online identity to a real location and a specific phone or laptop. And the 58 million connection logs, cross-referenced with timestamps, can show a pattern of life: when someone is typically online, from which country, and to which endpoints. None of this requires breaking any encryption — it is metadata the provider itself recorded and then failed to protect.

How do you choose a VPN you can actually trust?

Because you cannot audit the server yourself, judge the provider on signals you can check:

Who is behind it and where. A named legal entity and a real company are accountable in a way an anonymous app store listing is not. LiMP VPN is operated by a registered Russian company (OOO LiMP), not a faceless brand.

What data the app collects. Read the privacy policy and the app store data-safety label. If a "free" VPN asks for broad permissions or bundles analytics SDKs, assume your activity is a product.

A no-logs design, not just a slogan. The strongest position is a service that has no business reason to retain connection logs and says so plainly. LiMP VPN is a no-logs service for iOS and Android — see the plans, and follow more security news on our blog.

If you were affected. If you ever used SplitVPN or NotVPN, change the account password, change it anywhere you reused it, watch for phishing to that email, and consider the exposed IP and device data already public.

Sources

Reporting is based on the analysis by SecurityLab.ru (Positive Technologies), Security Affairs, SC Media and Bitdefender, which independently reported the SplitVPN breach and the 58 million connection logs.

"No-Logs" VPN Breach Exposes 58M Connection Logs | LiMP VPN