Back Feeds.Feedburner SplitVPN 'no logs' claim contradicted by massive data leak
The leaked database, distributed via the Altenen cybercrime forum and analyzed by Mysterium’s research team, contains approximately 23.4 million user records, 13.6 million device records, and 2.6 million payment records. Despite the VPN's explicit "no logs" promise, the data includes nearly 58 million connection logs detailing device connections to specific servers and their timestamps, running up to the day of the breach. While full credit card numbers were not exposed, the data includes masked card numbers, expiration dates, recurring billing tokens, emails, IP addresses, device identifiers, and approximate locations.
The user base is reportedly concentrated in Russia, Iran, India, and Myanmar, regions where VPNs are often used to circumvent state censorship. This leak poses a significant risk to users in these areas, potentially exposing individuals who used the VPN to evade government controls. The breach also revealed administrative accounts with password hashes and logs of operator actions, as well as infrastructure details for provisioning app store accounts.
Source: Security Affairs
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
