58 Million Logs Just Leaked From a 'No-Logs' VPN

A breached VPN that promised “100% privacy” was quietly keeping 58 million connection logs, a reminder that a no-logs VPN is only as good as its proof.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

When you pay for a no-log VPN, you're really paying for one promise: that it's not keeping a record of what you do online. Turns out that's not always the case.

A Russian VPN called NotVPN, later rebranded SplitVPN, made that promise in plain language, advertising “No logs or history” and “100% privacy guaranteed.” Then a 17 GB copy of its database turned up for sale on a cybercrime forum, holding roughly 58 million connection logs.[1]

This incident is a stark reminder that a no-logs VPN is only as safe as the proof behind the claim, and the main form of proof is an independent audit. Without one, “no logs” is a statement no customer can verify.

In this article
What the NotVPN “no-logs” breach actually exposed
Why an unverifiable no-logs VPN is a risk for anyone
How to choose a no-logs VPN you can actually trust
Bottom line: a no-logs VPN means nothing without proof

What the NotVPN “no-logs” breach actually exposed

According to the Mysterium research team, which obtained the leaked file and checked it against the raw database, the dump contains about 23.4 million user records, 13.6 million device records, 2.6 million payment records, and roughly 58 million connection logs. Reporting on the findings, Security Affairs confirmed the same numbers.

A connection log is simply a record that a specific device connected to a specific server at a specific time. It is not a list of the websites someone visited, so this is connection metadata rather than full browsing history. But metadata is exactly what the phrase “we never store your connection logs” promises not to keep. The logs ran continuously from June 2025 to July 21, 2026, the day of the dump, which means the service was still writing them as it was being breached. 

Cross-referenced with the account emails and last-seen IP addresses in the user table, those logs are enough to reconstruct who connected, from where, and when, for tens of millions of people.

One piece of good news: no full card numbers were exposed. Payment data was masked to the first six and last four digits. The real exposure is the link between a person’s email, their payment history, and their recurring billing token, not a usable card number.

Why your no-logs VPN may not be as safe as you think

Any VPN can call itself no-logs. It is a marketing phrase, and nothing stops a provider from printing it while still recording logs, which is exactly what NotVPN did.

With a conventional VPN, the provider controls what gets written to its database, and the customer has no way to see inside it. The no logs claim held up only until the database appeared on a forum.

The way to know whether a no-logs claim is real is an independent audit. The provider hires an outside security firm and gives it access to inspect the systems that would do the logging. Auditors review server configurations, source code, and data-handling practices, test whether the servers actually discard connection data instead of storing it, and then publish a report describing what they found.

Firms such as Cure53, Leviathan Security, and PwC perform this kind of review for major VPNs. A completed audit turns "trust us" into a document you can read, which is the difference between a checked no-logs VPN and an unchecked one.

“No-logs” is a promise, not a guarantee, unless the provider proves it. The strongest proof is an independent audit and RAM-only servers that cannot retain data through a reboot. See which no-logs VPNs have been independently audited.

How to choose a no-logs VPN you can actually trust

The takeaway is to stop taking the words “no-logs VPN” at face value and check for evidence instead. Four things tell you whether a claim is real:

  1. Look for a recent independent audit. A trustworthy provider hires an outside security firm to inspect its systems and publishes the full report, not just a press release. Check the date. An audit from a few years ago tells you little about today’s infrastructure.
  2. Prefer RAM-only servers. Servers that run entirely in memory wipe everything on every reboot, so there is nothing sitting on a disk to leak later. It is the strongest technical backing a no-logs claim can have.
  3. Check the jurisdiction and transparency reports. Look for where the company is based and whether it publishes records of government data requests, ideally cases where it was asked for data and had none to hand over. Learn more about the 5, 9, and 14 Eyes Alliance.
  4. Be wary of free VPNs. If you have wondered whether free VPNs are safe, this breach is a useful answer. Running servers costs money, and when you are not paying, your data often is. Sticking to a vetted, paid, most secure VPN removes that incentive.

Once you know what to look for, the shortlist gets short fast. NordVPN is one provider that holds up against these standards, with a no-logs policy backed by independent third-party audits.

Bottom line: a no-logs VPN means nothing without proof

A no-logs VPN is only as trustworthy as the proof behind the claim. NotVPN shows what happens when there is none: tens of millions of logs from a service that swore it kept zero.

Before you trust a VPN with your privacy, confirm that its no-logs policy has been independently audited and that its servers are built so it cannot quietly keep records in the first place. The label is easy to print. The proof is what counts.

#1 Rated VPN for Privacy and Security
5.0
Editorial Rating
Get Deal
On NordVPN's website
2026 Editors’ Choice
Best Overall VPN
VPN
NordVPN
PROMOTION: Get 75% Off + 3 Months Extra
  • Our #1 rated VPN, which has increased download speeds by up to 36% across all regions in our testing
  • Historically unlocks Netflix libraries in the US, Canada, UK, and Australia with no errors
  • Bundles with ad blocker, data removal, and encrypted storage for a more complete privacy setup
Author Details
Steph Trejos is a Certified Anti-Money Laundering Specialist (CAMS), a credential that reflects deep expertise in financial crime, fraud patterns, and cyber threats. As a Senior Product Testing Editor at All About Cookies, she has personally evaluated nearly 200 digital security products and brings that forensic rigor to every review she oversees. Before joining AAC, she produced publications on financial crime and cyber threats at ACAMS.

Citations

[1] A “No-Logs” VPN That Kept 58 Million Connection Logs: Inside the NotVPN / SplitVPN Breach