All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
When you pay for a no-log VPN, you're really paying for one promise: that it's not keeping a record of what you do online. Turns out that's not always the case.
A Russian VPN called NotVPN, later rebranded SplitVPN, made that promise in plain language, advertising “No logs or history” and “100% privacy guaranteed.” Then a 17 GB copy of its database turned up for sale on a cybercrime forum, holding roughly 58 million connection logs.[1]
This incident is a stark reminder that a no-logs VPN is only as safe as the proof behind the claim, and the main form of proof is an independent audit. Without one, “no logs” is a statement no customer can verify.
Why an unverifiable no-logs VPN is a risk for anyone
How to choose a no-logs VPN you can actually trust
Bottom line: a no-logs VPN means nothing without proof
What the NotVPN “no-logs” breach actually exposed
According to the Mysterium research team, which obtained the leaked file and checked it against the raw database, the dump contains about 23.4 million user records, 13.6 million device records, 2.6 million payment records, and roughly 58 million connection logs. Reporting on the findings, Security Affairs confirmed the same numbers.
A connection log is simply a record that a specific device connected to a specific server at a specific time. It is not a list of the websites someone visited, so this is connection metadata rather than full browsing history. But metadata is exactly what the phrase “we never store your connection logs” promises not to keep. The logs ran continuously from June 2025 to July 21, 2026, the day of the dump, which means the service was still writing them as it was being breached.
Cross-referenced with the account emails and last-seen IP addresses in the user table, those logs are enough to reconstruct who connected, from where, and when, for tens of millions of people.
One piece of good news: no full card numbers were exposed. Payment data was masked to the first six and last four digits. The real exposure is the link between a person’s email, their payment history, and their recurring billing token, not a usable card number.
Why your no-logs VPN may not be as safe as you think
Any VPN can call itself no-logs. It is a marketing phrase, and nothing stops a provider from printing it while still recording logs, which is exactly what NotVPN did.
With a conventional VPN, the provider controls what gets written to its database, and the customer has no way to see inside it. The no logs claim held up only until the database appeared on a forum.
The way to know whether a no-logs claim is real is an independent audit. The provider hires an outside security firm and gives it access to inspect the systems that would do the logging. Auditors review server configurations, source code, and data-handling practices, test whether the servers actually discard connection data instead of storing it, and then publish a report describing what they found.
Firms such as Cure53, Leviathan Security, and PwC perform this kind of review for major VPNs. A completed audit turns "trust us" into a document you can read, which is the difference between a checked no-logs VPN and an unchecked one.
“No-logs” is a promise, not a guarantee, unless the provider proves it. The strongest proof is an independent audit and RAM-only servers that cannot retain data through a reboot. See which no-logs VPNs have been independently audited.
How to choose a no-logs VPN you can actually trust
The takeaway is to stop taking the words “no-logs VPN” at face value and check for evidence instead. Four things tell you whether a claim is real:
- Look for a recent independent audit. A trustworthy provider hires an outside security firm to inspect its systems and publishes the full report, not just a press release. Check the date. An audit from a few years ago tells you little about today’s infrastructure.
- Prefer RAM-only servers. Servers that run entirely in memory wipe everything on every reboot, so there is nothing sitting on a disk to leak later. It is the strongest technical backing a no-logs claim can have.
- Check the jurisdiction and transparency reports. Look for where the company is based and whether it publishes records of government data requests, ideally cases where it was asked for data and had none to hand over. Learn more about the 5, 9, and 14 Eyes Alliance.
- Be wary of free VPNs. If you have wondered whether free VPNs are safe, this breach is a useful answer. Running servers costs money, and when you are not paying, your data often is. Sticking to a vetted, paid, most secure VPN removes that incentive.
Once you know what to look for, the shortlist gets short fast. NordVPN is one provider that holds up against these standards, with a no-logs policy backed by independent third-party audits.
Bottom line: a no-logs VPN means nothing without proof
A no-logs VPN is only as trustworthy as the proof behind the claim. NotVPN shows what happens when there is none: tens of millions of logs from a service that swore it kept zero.
Before you trust a VPN with your privacy, confirm that its no-logs policy has been independently audited and that its servers are built so it cannot quietly keep records in the first place. The label is easy to print. The proof is what counts.
[1] A “No-Logs” VPN That Kept 58 Million Connection Logs: Inside the NotVPN / SplitVPN Breach