// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-hibpDTG 0600Z
ColdRecon / Breach Radar / SplitVPN
Breach Record

SplitVPN

DISCLOSED 2026-07-21 · STOLEN CREDS · 865,336 RECORDS EXPOSED

In July 2026, the Russian VPN service SplitVPN (previously known as NotVPN) suffered a data breach. The incident exposed millions of customer records, including 865k unique email addresses. Other impacted data included IP addresses, the user's country, and partial payment card data (first 6 and last 4 digits plus expiry date).

The record

What we know

Disclosed
2026-07-21
Attack vector
Stolen Creds
Records exposed
865,336
Domain
splitvpn.io
Data classes exposed
Device informationEmail addressesGeographic locationsIP addressesPartial credit card data
Sources

Cited reporting

Similar vector · recent

Other stolen creds breaches on file

This page is the permanent ColdRecon entry for the SplitVPN disclosure. It updates if new public reporting emerges. All tracked breaches →

SplitVPN just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →