High

SplitVPN Breach: 865K Emails & IPs Exposed (2026)

In July 2026, the Russian VPN service SplitVPN (previously known as NotVPN) suffered a data breach . The incident exposed millions of customer records, including 865k unique email addresses. Other impacted data included IP addresses, the user's country, and partial payment card data (first 6 and las...

Overview

In July 2026, the Russian VPN service SplitVPN - formerly known as NotVPN - suffered a significant data breach that exposed roughly 865,000 unique customer email addresses. The full leak included millions of customer records, making this one of the larger VPN-related breaches in recent memory. The incident was reported to Have I Been Pwned (HIBP), and affected users can already check whether their information was compromised.

For a service whose entire purpose is protecting user privacy and anonymity, this breach is particularly damaging. A VPN that cannot protect its own customer database raises serious questions about its security posture and the safety of its users, especially those in restrictive online environments.

What Was Exposed

The breached database contained far more than just email addresses. Affected records included:

  • Email addresses - 865,336 unique accounts
  • IP addresses - the user’s originating IP at time of registration or use
  • Country of origin - geographic location data
  • Partial payment card data - the first 6 and last 4 digits of payment cards, plus card expiry dates

The combination of email addresses, IP addresses, and country data is especially concerning. For users who relied on SplitVPN to bypass censorship or hide their online activity, this breach effectively links their real identity (email) to their network activity and physical location. The partial card data, while not full payment credentials, can still be used in combination with other leaked information for targeted phishing attacks or social engineering.

Why the Payment Card Data Matters

While the exposed card data omits the middle digits and CVV, the first six and last four digits are not harmless. The first six digits identify the card issuer and bank, while the last four are commonly used as verification on customer service calls. Combined with the expiry date and a user’s email address, this information:

  • Enables highly convincing phishing emails referencing “your recent SplitVPN payment”
  • Provides attackers with enough detail to attempt account recovery on other services
  • Creates a foundation for vishing (voice phishing) attacks that impersonate banks

If you used SplitVPN, consider any email that references your payment details or subscription as potentially malicious until verified through a separate channel.

How the Breach Happened

While SplitVPN has not published a detailed post-mortem, the breach pattern suggests a database exfiltration rather than a ransomware attack. The fact that millions of records were dumped, including the partial payment data, indicates the attackers gained access to the backend database rather than intercepting individual transactions.

This is particularly troubling because split-tunnel VPN services often store minimal data by design. The retention of IP addresses and partial card data suggests SplitVPN was collecting more information than strictly necessary for service operation, a practice directly at odds with the privacy guarantees VPNs typically market to their users.

What to Do Right Now

If you have ever used SplitVPN or its predecessor NotVPN, take the following steps:

  1. Check Have I Been Pwned at haveibeenpwned.com and search your email address. The SplitVPN breach is indexed there, and you will receive an immediate result if your data was included.

  2. Change your email password immediately, especially if you reuse passwords across services. The combination of your email address and IP data makes credential stuffing attacks highly viable.

  3. Monitor your payment cards for unusual activity. Even though full card numbers were not exposed, the partial data leaked is enough to make you a target. Review recent statements and consider setting up transaction alerts.

  4. Treat all future SplitVPN communications as suspicious. Any email claiming to be from the company could be a phishing attempt leveraging your leaked data.

Security Insight

A VPN that retains and then leaks IP addresses and partial payment data demonstrates a fundamental misunderstanding of what its users are paying for. This breach sits alongside the 2021 NordVPN and 2025 Atlas VPN incidents as a reminder that the VPN industry has a persistent problem with data collection. Any service that markets anonymity but stores more than the bare minimum of user data is a liability waiting to happen. For users in countries with restricted internet access, the stakes of a leak like this are existential - linking your VPN use to your real identity can have legal and personal consequences that extend far beyond a compromised account.

Further Reading

Investigate Breaches Safely with NordVPN

Researching exposed data, paste sites, or threat actor infrastructure? Route your OSINT traffic through a VPN to avoid attribution and keep your investigation IP separate from your corporate network.

Get NordVPN for Research

Affiliate link — we may earn a commission at no extra cost to you.

Share:

Never miss a data breach report

Get real-time security alerts delivered to your preferred platform.

Related Breach Reports

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.