Feeds.Feedburner Massive Data Leak from SplitVPN Exposes Millions Despite 'No-Logs' Claims
Article Content
- •SplitVPN's data breach exposed 58 million connection logs, undermining its privacy claims.
- •The leaked data includes sensitive user information, affecting millions in censorship-heavy regions.
- •Cybercriminals exploited the VPN's vulnerabilities, highlighting the risks of using 'no logs' services.
A significant data breach involving SplitVPN has exposed approximately 58 million connection logs and millions of user records, contradicting the VPN's 'no logs' policy. The leaked database, distributed on the Altenen cybercrime forum, includes 23.4 million user records, 13.6 million device records, and 2.6 million payment records. Although full credit card numbers were not revealed, the data contains masked card numbers, expiration dates, and other sensitive information. The breach primarily affects users in regions like Russia, Iran, India, and Myanmar, where VPNs are used to bypass censorship. The incident raises concerns about the safety of users who relied on SplitVPN for privacy. The attack method involved unauthorized access to the VPN's database, revealing a significant gap in its security measures. Experts emphasize the need for users to be cautious and for companies to enhance their defenses against credential reuse attacks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track SplitVPN in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…