SplitVPN Breach: 865K Emails & IPs Exposed (2026)
In July 2026, the Russian VPN service SplitVPN (previously known as NotVPN) suffered a data breach . The incident exposed millions of customer records, including 865k unique email addresses. Other impacted data included IP addresses, the user's country, and partial payment card data (first 6 and las...
Overview
In July 2026, the Russian VPN service SplitVPN - formerly known as NotVPN - suffered a significant data breach that exposed roughly 865,000 unique customer email addresses. The full leak included millions of customer records, making this one of the larger VPN-related breaches in recent memory. The incident was reported to Have I Been Pwned (HIBP), and affected users can already check whether their information was compromised.
For a service whose entire purpose is protecting user privacy and anonymity, this breach is particularly damaging. A VPN that cannot protect its own customer database raises serious questions about its security posture and the safety of its users, especially those in restrictive online environments.
What Was Exposed
The breached database contained far more than just email addresses. Affected records included:
- Email addresses - 865,336 unique accounts
- IP addresses - the user’s originating IP at time of registration or use
- Country of origin - geographic location data
- Partial payment card data - the first 6 and last 4 digits of payment cards, plus card expiry dates
The combination of email addresses, IP addresses, and country data is especially concerning. For users who relied on SplitVPN to bypass censorship or hide their online activity, this breach effectively links their real identity (email) to their network activity and physical location. The partial card data, while not full payment credentials, can still be used in combination with other leaked information for targeted phishing attacks or social engineering.
Why the Payment Card Data Matters
While the exposed card data omits the middle digits and CVV, the first six and last four digits are not harmless. The first six digits identify the card issuer and bank, while the last four are commonly used as verification on customer service calls. Combined with the expiry date and a user’s email address, this information:
- Enables highly convincing phishing emails referencing “your recent SplitVPN payment”
- Provides attackers with enough detail to attempt account recovery on other services
- Creates a foundation for vishing (voice phishing) attacks that impersonate banks
If you used SplitVPN, consider any email that references your payment details or subscription as potentially malicious until verified through a separate channel.
How the Breach Happened
While SplitVPN has not published a detailed post-mortem, the breach pattern suggests a database exfiltration rather than a ransomware attack. The fact that millions of records were dumped, including the partial payment data, indicates the attackers gained access to the backend database rather than intercepting individual transactions.
This is particularly troubling because split-tunnel VPN services often store minimal data by design. The retention of IP addresses and partial card data suggests SplitVPN was collecting more information than strictly necessary for service operation, a practice directly at odds with the privacy guarantees VPNs typically market to their users.
What to Do Right Now
If you have ever used SplitVPN or its predecessor NotVPN, take the following steps:
-
Check Have I Been Pwned at haveibeenpwned.com and search your email address. The SplitVPN breach is indexed there, and you will receive an immediate result if your data was included.
-
Change your email password immediately, especially if you reuse passwords across services. The combination of your email address and IP data makes credential stuffing attacks highly viable.
-
Monitor your payment cards for unusual activity. Even though full card numbers were not exposed, the partial data leaked is enough to make you a target. Review recent statements and consider setting up transaction alerts.
-
Treat all future SplitVPN communications as suspicious. Any email claiming to be from the company could be a phishing attempt leveraging your leaked data.
Security Insight
A VPN that retains and then leaks IP addresses and partial payment data demonstrates a fundamental misunderstanding of what its users are paying for. This breach sits alongside the 2021 NordVPN and 2025 Atlas VPN incidents as a reminder that the VPN industry has a persistent problem with data collection. Any service that markets anonymity but stores more than the bare minimum of user data is a liability waiting to happen. For users in countries with restricted internet access, the stakes of a leak like this are existential - linking your VPN use to your real identity can have legal and personal consequences that extend far beyond a compromised account.
Further Reading
Investigate Breaches Safely with NordVPN
Researching exposed data, paste sites, or threat actor infrastructure? Route your OSINT traffic through a VPN to avoid attribution and keep your investigation IP separate from your corporate network.
Get NordVPN for ResearchAffiliate link — we may earn a commission at no extra cost to you.
Never miss a data breach report
Get real-time security alerts delivered to your preferred platform.
Related Breach Reports
In April 2026, the gaming community Reborn Gaming suffered a data breach due to a vulnerability in cPanel and WebHost Manager (WHM) . The breach exposed 126 unique email addresses along with IP addresses and Steam IDs. Reborn Gaming self-submitted the data to Have I Been Pwned.
In March 2026, the anime streaming service Crunchyroll suffered a data breach alleged to have impacted 6.8M users . The exposed data is reported to have originated from the company's Zendesk support system where "name, login name, email address, IP address, general geographic location and the conten...
In February 2026, the online gaming community Toy Battles suffered a data breach. The incident exposed 1k unique email addresses alongside usernames, IP addresses and chat logs. Following the breach, Toy Battles self-submitted the data to Have I Been Pwned.
In January 2026, the automotive research and car-shopping platform Edmunds was listed by the ShinyHunters hacking group as having been breached . Data purportedly obtained in the incident was later published publicly and included 178k unique email addresses, usernames, passwords, IP addresses, phone...