- SplitVPN denies allegations that it stored 58 million VPN connection logs leaked in a reported database breach.
- The company admits some customer account information was exposed but says the disputed connection records are fabricated.
- Researchers claim the leaked metadata could reveal when devices connected to VPN servers if authentic.
- The incident highlights why independent no log audits and transparent security practices are essential for VPN providers.
A fresh controversy has put Russian VPN provider SplitVPN under scrutiny after claims emerged that a leaked database contained millions of connection logs, potentially contradicting the company’s no log policy. While SplitVPN firmly rejects the allegations and insists the disputed records are fabricated, the incident has once again highlighted a broader issue facing the VPN industry. Users are often expected to trust privacy promises that are difficult to verify on their own.
The case has drawn attention because SplitVPN is widely used by people seeking to bypass internet restrictions in countries with strict censorship. If a VPN marketed as privacy focused is accused of collecting connection information, even without browsing history, the implications can be significant for users who depend on anonymity.
Leaked database sparks questions over SplitVPN’s privacy claims
The controversy began after a threat actor reportedly shared a 17 GB SQL database on the Altenen cybercrime forum on July 21. The leaked files were claimed to have been stolen from SplitVPN and allegedly included customer related information, payment details, device records, and approximately 58 million connection logs.
Researchers at Mysterium VPN examined the leaked database and reported that one section, identified as the deviceproxy table, appeared to contain millions of records showing connections between user devices and VPN servers. According to their findings, the data mainly consisted of connection metadata such as timestamps, device identifiers, and server information rather than browsing activity or websites visited.
Although this type of information does not reveal browsing history, privacy experts note that connection metadata can still be sensitive. When combined with other information such as the last known IP address or device identifiers, it could potentially help establish when a person connected to a VPN server and from which location.
That possibility has raised concerns because many users rely on VPN services specifically to protect themselves in countries where internet surveillance or restrictions are common.
SplitVPN says the alleged connection logs are fabricated
SplitVPN has strongly denied that it stores connection logs in violation of its published privacy policy. The company acknowledged that some account related information included in the leaked database appears to be genuine. This reportedly includes customer email addresses, subscription status, country information, masked payment details, and device names.
However, the provider insists the alleged connection log records are entirely fake.
According to SplitVPN, the disputed deviceproxy table was not generated by its infrastructure and was allegedly inserted into the leaked database to increase its perceived value. The company maintains that its systems do not create or retain mappings between user devices, VPN servers, and connection timestamps.
Following the security incident, SplitVPN says it immediately responded by rotating access credentials, replacing encryption keys, changing VPN server IP addresses, closing the identified security weakness, and bringing in external cybersecurity specialists to review its infrastructure. The provider says normal operations have since resumed.
Despite these assurances, independent verification remains difficult. Without direct forensic evidence or an independent audit, users are left with conflicting claims from security researchers and the VPN provider itself.
Why this incident matters beyond SplitVPN
Whether the alleged connection logs are genuine or not, the incident exposes an ongoing challenge within the VPN industry.
If the leaked records are authentic, they would directly conflict with SplitVPN’s no log policy, raising serious questions about how user information is handled. Even metadata that excludes browsing history can become valuable when combined with other identifiers, especially in regions where VPN usage may attract legal scrutiny.
If the records are fabricated, users still face uncertainty because there is no easy way to independently confirm the company’s claims. The existence of leaked customer account information alone may undermine confidence among subscribers who chose the service specifically for privacy.
This situation reinforces an important lesson for VPN users. Marketing claims about no log policies are valuable only when supported by technical safeguards and independent verification.
Independent audits remain the strongest measure of trust
The SplitVPN controversy serves as another reminder that privacy promises should be backed by evidence rather than marketing language.
Many leading VPN providers now commission regular independent audits to verify that they do not retain identifiable user activity. These assessments allow outside security firms to inspect infrastructure, logging practices, and operational controls, providing customers with greater confidence that stated privacy policies match real world implementation.
Beyond independent audits, privacy focused services increasingly rely on technologies designed to minimize the amount of data that can be retained. Features such as RAM based servers, kill switches, stronger encryption, and advanced security architecture reduce the likelihood that sensitive information remains available even if infrastructure is compromised.
Ultimately, VPN users should remember that privacy depends on more than a company’s public statements. Technical design, transparent security practices, and regular third party verification remain the strongest indicators that a provider is committed to protecting customer data when it matters most.
Follow TechBSB For More Updates
