Threat Actor Claims Leak of 23.4 Million SplitVPN User Records

Nancy Tyson  - Tech Writer
Last updated: July 23, 2026
Human Written
Share
Threat Actor Claims Leak of 23.4 Million SplitVPN User Records
Radar Rundown
  • A threat actor allegedly claims to have leaked 23.4 million SplitVPN user records and 57.9 million proxy logs.

  • The alleged data reportedly includes payment details, device records, login tokens, and VPN network information.

  • Intel and Breaches highlighted the claim, but no independent source has confirmed the alleged leak or its full contents.

SplitVPN, a VPN service once known as NotVPN, has allegedly appeared on a cybercrime forum. A threat actor claims to have leaked data linked to millions of users and devices.

Intel and Breaches (@IBreaches) on X, formerly Twitter, first highlighted the alleged leak. According to the report, the threat actor claims access to 23.4 million user records.

The same claim also mentions 58 million proxy logs and data connected to 13.6 million devices. The alleged database could therefore contain information from a very large number of people.

However, no independent source has confirmed the claims. The available information also does not show a public confirmation from SplitVPN about the alleged incident.

What the threat actor claims

According to the cybercrime forum post, the alleged database contains several types of user information. The claimed data includes email addresses, IP addresses, countries, and subscription details. The threat actor also reportedly claims access to 2.6 million payment records.

These records allegedly contain masked card details, transaction amounts, and transaction timestamps. The reported card information is said to be masked. However, the alleged records still contain details about payments linked to affected users.

The threat actor also claims to have obtained nearly 58 million proxy logs. These logs reportedly include timestamps, user IDs, proxy IP addresses, and destination information.

The alleged logs could show details about activity linked to the VPN service. However, the available information does not confirm whether all the claimed records are genuine. The threat actor further claims access to 23.9 million authorization tokens.

The alleged database also reportedly contains 13.6 million device records. Those device records allegedly include device models, operating systems, device identifiers, and IP addresses. The claim also mentions administrator usernames, password hashes, and user role information.

The alleged leak reportedly includes information about SplitVPN’s VPN network as well. The claimed data includes proxy and relay node IP addresses.

Other alleged records reportedly contain Telegram usernames and email addresses. The threat actor also claims the database includes Apple IDs, WireGuard peer information, and server metrics.

According to the claim, the database measures about 21GB in size. The threat actor reportedly says the data becomes about 5GB after compression.

Why the Alleged Data Matters

The alleged leak stands out because of the wide range of information it reportedly contains. The claim goes beyond basic customer records and includes logs, devices, payment data, and network details. The alleged proxy logs could provide information about activity connected to the service.

The device records could also link users to specific devices, operating systems, and IP addresses. The exposure of sensitive data is a growing concern. 1.6 million patient records were allegedly stolen in an OpenLoopHealth cyberattack. The claimed authorization tokens could also be sensitive if they are valid and still active. The same applies to the alleged administrator details and password hashes.

The alleged VPN network data could also provide information about the service’s infrastructure. However, the available report does not confirm whether attackers can use any of these records. The claim also comes as cybercrime forums continue to feature alleged stolen databases. Threat actors often post such claims to attract buyers or attention from other criminals.

Some forum listings contain real stolen data. Others may contain old information, false claims, or data taken from earlier incidents. For that reason, the presence of a database listing does not prove that a company suffered a new breach.

Investigators must examine the data before confirming its source and authenticity. In this case, the alleged SplitVPN dataset has not received independent verification. No public evidence currently confirms that the entire database came from SplitVPN.

The available information also does not confirm whether the claimed figures accurately represent unique users, records, or devices. The threat actor’s claims remain the main source for the reported numbers.

SplitVPN leak remains unverified

At the time of reporting, no independent cybersecurity researcher or major security publication had publicly confirmed the alleged database. The information available also does not show a confirmed public response from SplitVPN about the alleged leak.

That means the company has not been publicly confirmed as acknowledging the incident based on the supplied information. The reported figures should therefore remain treated as allegations.

The threat actor claims the database contains millions of user records and tens of millions of logs. If investigators later confirm the data, the incident could involve a large amount of sensitive information. However, the current evidence does not allow the claims to be treated as established facts.

For now, the alleged leak is based on the cybercrime forum listing and the report from Intel and Breaches. Further investigation would be needed to verify the database and determine its true source. The available information also does not confirm whether SplitVPN systems were breached or how the alleged data was obtained.

It also does not establish whether the claimed records belong to current users. Until more evidence becomes available, the reported SplitVPN database should be considered an unverified alleged leak. Any conclusions about its size, contents, or impact remain subject to confirmation.

Share this article

About the Author

Nancy Tyson

Nancy Tyson

Tech Writer

Nancy has been working as a Cybersecurity writer for over three years and contributes her expertise in the VPN area. Due to the technology element in Nancy’s education, she has acquired the ability to assess the online security environment objectively and explain concepts in simple terms to the readers of articles in the field. Besides using her time to learn about new VPN services, Nancy likes cooking, reading a good book, and often going to parties.

More from Nancy Tyson

Comments

No comments.