Data breach
SplitVPN data breach
865,336 accounts · breached July 21, 2026
What happened
In July 2026, the Russian VPN service SplitVPN (previously known as NotVPN) suffered a data breach. The incident exposed millions of customer records, including 865k unique email addresses. Other impacted data included IP addresses, the user's country, and partial payment card data (first 6 and last 4 digits plus expiry date).
What data leaked
- Device information
- Email addresses
- Geographic locations
- IP addresses
- Partial credit card data
What to do if you had an account
- Turn on two-step sign-in. Enable two-factor authentication where the service offers it, preferably with an authenticator app or a passkey. A leaked password alone is then not enough to get in.
- Expect targeted phishing. Leaked contact details are used to write convincing fake messages that mention the breached company or your real name. Do not click links in unexpected emails or texts about this account; go to the site by typing its address.
- Check your bank statements. Review recent card and account transactions and report anything you do not recognise. If full card numbers were exposed, ask your bank to replace the card.
Check your email at haveibeenpwned.com
We do not run email lookups ourselves. The search is done on haveibeenpwned.com, the service this list comes from.