In short: On 23 July 2026 unidentified sellers offered a 17 GB archive allegedly stolen from a popular VPN service, SplitVPN (formerly NotVPN): 23.4 million accounts and around 58 million connection records — even though the service marketed itself on confidentiality. No independent confirmation of the full database exists yet, but the case is a sharp lesson: a "no-logs" promise is worth exactly as much as you can trust the provider behind it.
What happened?
On 23 July 2026 a listing appeared on a hacking forum offering a database allegedly taken from the VPN service SplitVPN (which previously operated as NotVPN). The sellers put the set at 23.4 million accounts and attached a compressed SQL dump; unpacked, the archive is around 17 GB. Alongside the accounts, they claim the leak includes payment operations, device information and customer activity.
The description lists email addresses, IP addresses, countries and subscription statuses, about 23.9 million authentication records with device identifiers and tokens, 13.6 million devices tied to Apple IDs, and roughly 2.6 million payment records with masked card numbers. It is close to what we examined in our report on apps that quietly leak your data — and how privacy actually works is explained in our piece on what a no-logs VPN is. One important caveat: there is no independent confirmation of the whole database yet, and the service itself has not publicly commented on the incident.
Why "no-logs" is about trust, not a slogan
The key detail here is not the number of accounts — it is the logs themselves. The service emphasised a private connection and no mandatory registration, yet the leaked set reportedly contains about 58 million deviceProxy records, with user identifiers, proxy servers and the resources traffic went to. If that is accurate, it means the service retained far more technical data than a user has any right to expect from a VPN that advertises confidentiality.
A genuine no-logs policy means there is simply nothing to keep: the provider does not record connection journals and does not tie traffic to a specific person, so even after a breach — or a request — there is nothing to hand over. A promise on a landing page and the technical reality on the servers are two different things, and you can only check it through independent signals: audits, jurisdiction, and how little data is collected. We go into this on our features page.
What it means for you and your data
A leak at a VPN is more dangerous than many others: the provider sees the addresses you connect to, and the combination of email, IP and payment history is ready-made material for targeted phishing and account takeover. But the blast radius is wider than one service. According to breach-intelligence service DLBI (22 July 2026), more than 35% of login attempts against their corporate-VPN honeypots used passwords straight from free-VPN leaks, and another 20% or so used automated variations of them.
The mechanics are simple and universal: people reuse one password across a personal VPN, their email and work systems, and attackers link leaked data to a specific company — especially when someone signs up everywhere with a corporate email. A single leak from a "minor" app becomes a skeleton key to far more valuable accounts. That is exactly why the breach of one VPN is a problem for more than its own customers.
How do you pick a VPN you can trust?
Look past the "no-logs" slogan at what the provider actually collects and stores. Good signs: a clear privacy policy, minimal data collection, no connection journals, modern protocols such as WireGuard, and transparency about who runs the service. Bad ones: a free VPN with no coherent business model — if you are not paying for the product, your data is often the product.
That is the principle behind LiMP VPN: a no-logs approach, encrypted traffic and data minimisation, so that even in the worst case there is simply nothing to hand over. How it works technically is shown on our features page, and the privacy basics live on our blog.
How to protect your data right now
Unique passwords everywhere. If one service leaks a password, a password manager keeps that single loss from unlocking your email, bank and work accounts — the exact scenario that password-reuse attacks exploit.
Two-factor authentication. An authenticator app or hardware key means a stolen password alone is not enough to log in.
Check your email. Have I Been Pwned shows which known breaches your address appears in; change passwords anywhere you reused them.
Choose your provider deliberately. A VPN carries all of your traffic — trust it only to someone who collects minimal data and keeps no logs.
Sources
This report is based on coverage by SecurityLab and CNews (July 2026).
