What the SplitVPN Breach Reveals About No-Logs Claims
A 17 GB database proved SplitVPN logged 58 million connections it swore it never kept. Here is what that means for anyone relying on a privacy promise.
On 21 July 2026, a 17 GB SQL database belonging to SplitVPN—a Russian provider previously branded as NotVPN—was extracted and distributed on the Altenen cybercrime forum. Have I Been Pwned confirmed the breach on 1 August 2026, with 865,336 accounts affected. The leaked data included email addresses, IP addresses, countries of origin, device identifiers, and partial payment card details.
That alone would be a serious breach. What made it especially damaging was a single table buried in the database: almost 58 million device-to-server connection log entries, recorded continuously from June 2025 right through to the day the database was stolen. SplitVPN had advertised, explicitly and prominently, a "No logs or history—100% privacy guaranteed" policy.
This article looks at what that contradiction means in practice, who bears the real risk, and how to think more critically about no-logs claims when choosing a VPN.
What the leaked data actually contained
The headlines focused on the account data—email addresses and partial card numbers—because those are the metrics that breach notification services track. But the connection log table is the more consequential part of this story.
Each entry in that table linked a specific device identifier to a specific VPN server at an exact timestamp. Chain those entries together and you have a timestamped map of when a user connected, from which IP address, and to which server. That is not just metadata in an abstract sense. For a user who connected to a server in, say, a country neighbouring their own to access blocked content, it is a record that could demonstrate their circumvention activity to any government or authority that subsequently obtained the data.
The affected user base was reportedly concentrated in Russia, Iran, India, and Myanmar—four countries where state surveillance of internet activity is active and where VPN use is frequently a response to censorship or legal restrictions. For users in those regions, the exposure is not merely embarrassing. It is potentially dangerous.
How a "no-logs" service ends up with 58 million log entries
There are a few ways this happens, and none of them are flattering.
Logging for operational purposes that never gets deleted
VPN infrastructure genuinely requires some transient data to function—session tokens, server load figures, authentication records. The question is what gets written to persistent storage and for how long. A provider might start logging connection events for debugging or capacity planning and simply never implement the deletion policy they described in their privacy page. The data accumulates. A year later, it is still there.
A gap between marketing and engineering
Privacy policies are written by marketing or legal teams. The actual logging behaviour is determined by developers configuring server software. In organisations without tight internal oversight, these two things can diverge without anyone noticing—or anyone choosing to notice. The policy says no logs; the database says otherwise.
Deliberate misrepresentation
It would be naive to rule this out. A provider that wants to appear trustworthy has commercial incentive to claim no-logs status regardless of what their servers actually do. Without independent verification, that claim costs nothing to make.
The SplitVPN breach does not tell us which of these applied. What it does tell us is that 58 million log entries were created and retained over at least thirteen months, and that the public-facing policy said the opposite. The gap between the two is not a technicality.
Why "no-logs" is a claim, not a guarantee
When a VPN provider publishes a no-logs policy, you are reading a statement of intent—or, in some cases, a statement of marketing. You have no direct way to verify it. You cannot inspect their servers. You cannot audit their database schemas. You are extending trust based on a document they wrote themselves.
This is not a cynical position. It is simply an accurate one. Understanding it changes how you should evaluate the claim.
There are things that do lend a no-logs claim more credibility:
- Independent technical audits. A third-party security firm reviewing server configuration and database contents provides external verification that a self-published policy cannot. Audits have limitations—they are a snapshot in time—but they are substantially more meaningful than a policy page.
- A clear technical explanation of what is and is not stored. Vague promises of "complete privacy" are less reassuring than a specific account of which data is written, where, for how long, and under what access controls.
- Jurisdiction and legal exposure. A provider subject to data retention laws has structural pressure to log, whatever their policy says. Jurisdiction matters.
- Demonstrated behaviour under legal pressure. If a provider has received law enforcement requests and demonstrably had no useful data to provide, that is a stronger signal than any policy document.
SplitVPN offered none of these. The "100% privacy guaranteed" language is the kind of absolute claim that should itself prompt scepticism—privacy in any technical system involves trade-offs, and anyone claiming otherwise is either oversimplifying or not telling you the full picture.
The specific risk to users in censorship-heavy regions
For most users in Western Europe or North America, a VPN connection log exposure is a privacy violation but not an immediate safety risk. For users in Russia, Iran, Myanmar, or India—all disproportionately represented in SplitVPN's user base—the picture is different.
In Iran, VPN use without government-approved services is technically illegal. In Myanmar, internet activity has been used as evidence in prosecutions since the 2021 coup. In Russia, VPN regulation has tightened significantly. In each of these contexts, a log showing that a specific device connected to a VPN server in a foreign country at a specific time is not just embarrassing data. It could be used to infer what that person was accessing, or simply to demonstrate that they were attempting to circumvent state controls.
The Altenen forum where this data was distributed is a cybercrime marketplace. The most immediate threat is fraud and phishing using the exposed account details. But the connection logs are now in the wild. Who else has them, and what they intend to do with them, is not knowable.
If you are using a VPN specifically because you face legal or safety risks from your internet activity being observed, the technical architecture of that VPN matters more than its marketing copy. You need to understand what data is written, where, and what happens to it—not just what a policy page says.
What a serious no-logs policy looks like in practice
At PremierVPN, our no-logs policy is built around a straightforward principle: we do not write connection logs to persistent storage. There is no table of device-to-server connections, no timestamp record of when you connected or disconnected, and no retention of the IP address you connected from. We are a UK-based independent provider, and we have structured our infrastructure specifically so that we do not hold data we cannot be compelled to produce.
We also offer an IP leak test so you can verify that your connection is behaving as expected on your side. That is not a substitute for server-side verification, but it is a concrete tool rather than an assertion.
For users in high-risk regions—where deep packet inspection or VPN traffic detection is a real concern—we offer PremierVPN X for macOS and PremierVPN X for Windows, which use the VLESS+REALITY protocol to make VPN traffic significantly harder to identify and block. The architecture of that protocol is explained in more detail in our VLESS+REALITY overview.
Questions worth asking before trusting any no-logs claim
The SplitVPN incident is a useful prompt to apply more rigorous scrutiny to privacy claims generally. Here are practical questions to put to any VPN provider's policy documentation:
- Has the no-logs claim been independently audited? If yes, who conducted the audit, when, and is the full report available?
- What data is collected for account management? Email addresses, payment records, and device identifiers may be stored for billing purposes even when connection logs are not. Understand the distinction.
- Where are the servers physically located, and what jurisdiction governs them? A provider headquartered in a privacy-friendly country may still run servers subject to data retention requirements in other jurisdictions.
- What happens if the provider receives a court order or government demand? Has this happened before? What was the outcome?
- Does the provider use shared or dedicated infrastructure? RAM-only servers, for instance, cannot retain data across reboots—that is a technical constraint rather than a policy promise.
Absolute guarantees—"100% privacy," "zero logs ever," "completely anonymous"—should prompt more questions, not less. Privacy is an engineering problem as much as a policy one, and the engineering deserves scrutiny.
The practical takeaway
The SplitVPN breach is not an argument that all no-logs claims are false. It is an argument that an unverified claim, however confidently stated, is not evidence of the underlying reality. Fifty-eight million log entries do not appear by accident in a database belonging to a service that never kept logs. Something went wrong—structurally, deliberately, or both—and users paid for it with their privacy.
Treat a no-logs policy the way you would treat any other technical specification: ask what it actually means, ask how it is enforced, and look for independent verification where it exists. The providers who welcome that scrutiny, and can point to concrete answers, are worth more consideration than those who offer certainty without explanation.
If you want to understand more about how VPN privacy works at a technical level, our guide on what a VPN is and how it works covers the fundamentals without the marketing gloss.
Share this article
Protect your privacy with PremierVPN
Fast, secure, and truly private VPN service with servers in 12+ countries.
Get Started