Russian VPN service SplitVPN suffered a data breach in July 2026, exposing 865,336 unique email addresses along with IP addresses, location data, and partial payment card details.
Loading page…
Loading page…
Russian VPN service SplitVPN suffered a data breach in July 2026, exposing 865,336 unique email addresses along with IP addresses, location data, and partial payment card details.
According to Have I Been Pwned, the Russian VPN service SplitVPN — previously known as NotVPN — experienced a data breach in July 2026. The incident was reported by Security Affairs and disclosed publicly on August 1, 2026.
The breach exposed millions of customer records containing 865,336 unique email addresses. Also compromised were IP addresses, users' country-level geographic locations, device information, and partial payment card data consisting of the first six and last four digits of card numbers along with expiry dates.
Customers of SplitVPN (formerly NotVPN) who had accounts at the time of the breach are affected. Anyone who used the service and provided payment information may have had partial card details exposed.
If you have a SplitVPN account, change your password immediately and use a unique password not shared with other services. While the partial card data exposed is not sufficient for full fraud on its own, monitor your payment card statements for suspicious activity. Be alert to phishing attempts using your email address. Consider whether your VPN usage patterns or IP address history being exposed poses any privacy risk to you personally.