Ethical Hacking News
A popular VPN service has exposed the connection logs of nearly 58 million users, contradicting its "no-logs" claims. The breach has raised serious concerns about the security and privacy practices of online services and highlights the importance of understanding what data is being collected and stored by these services.
58 million users' connection logs were exposed in a recent breach of SplitVPN. The breach contradicts the provider's "no-logs" policy claims. A stolen SQL database revealed user records, device records, payment records, and connection logs. The breach raises concerns about security and privacy practices of online services. Users' personal data exposed in the database includes emails, IP addresses, and device identifiers. To protect yourself, change passwords, enable two-factor authentication, and research VPN providers' data collection policies.
A recent breach of a popular VPN service has exposed the connection logs of nearly 58 million users, contradicting the provider's claims of "no-logs" policies. The breach, which was carried out by an attacker on the Altenen cybercrime forum, has highlighted the importance of understanding what data is being collected and stored by online services.
The VPN service in question, SplitVPN (formerly known as NotVPN), had promised users that it did not store connection logs or activity records. However, a 17 GB SQL database was stolen from the service, which contained the personal data of millions of users. The database included user records, device records, payment records, and connection logs, all of which were collected by the VPN provider.
The breach has raised serious concerns about the security and privacy practices of online services. It has also highlighted the importance of understanding what data is being collected and stored by these services. Many VPN providers claim to offer "no-logs" policies, but it appears that some of these claims are not entirely truthful.
The impact of this breach on users should not be understated. The personal data exposed in the database includes emails, IP addresses, device identifiers, approximate locations, subscription status, and recurring billing tokens. This information can be used to track a user's online activity and compromise their security.
To protect yourself from this type of breach, it is essential to take steps to secure your online accounts. First and foremost, you should change the passwords associated with any email addresses that may have been compromised. You should also enable two-factor authentication wherever possible, as well as factor in connection metadata records being exposed outside the operator's control when creating a threat model for your online activities.
Furthermore, it is essential to be aware of what data is being collected and stored by online services. Many VPN providers claim to offer "no-logs" policies, but these claims are often unauditable and unverifiable. It is crucial to do your research before selecting a VPN provider and to understand what data is being collected and stored.
The breach of SplitVPN has sent shockwaves through the cybersecurity community, highlighting the need for greater transparency and accountability from online service providers. As the use of online services continues to grow, it is essential that we prioritize our security and privacy in these digital spaces.
In conclusion, the breach of SplitVPN serves as a reminder of the importance of understanding what data is being collected and stored by online services. It highlights the need for transparency and accountability from VPN providers and emphasizes the importance of taking steps to secure your own online accounts.
Related Information:
https://www.ethicalhackingnews.com/articles/VPN-Breach-Exposes-58-Million-Connection-Logs-Despite-No-Logs-Claims-A-Cautionary-Tale-for-Users-ehn.shtml
https://securityaffairs.com/196197/security/vpn-breach-exposes-58-million-connection-logs-despite-no-logs-claims.html
Published: Wed Jul 29 05:14:25 2026 by llama3.2 3B Q4_K_M