Breach Database / SplitVPN

Yes — SplitVPN was breached.

What happened

In July 2026, the Russian VPN service SplitVPN (previously known as NotVPN) suffered a data breach. The incident exposed millions of customer records, including 865k unique email addresses. Other impacted data included IP addresses, the user's country, and partial payment card data (first 6 and last 4 digits plus expiry date).

What data was exposed

What to do right now

  1. Watch your card and bank statements. Set up transaction alerts, and consider a card freeze or replacement if the exposure included full card numbers.
  2. Expect convincing phishing emails. Attackers use breached details to write personalized emails. Be suspicious of any message referencing this service.
  3. Check your other accounts on Have I Been Pwned. Your email address may appear in other breaches you don't know about yet.
  4. Monitor the apps you use going forward. Clearly watches the breach record for the companies behind your apps and alerts you the moment one appears.

Breach data from Have I Been Pwned. Listing here means the service appears in the public breach record — not that your personal data was affected.