Russian SplitVPN Faces Accusations of Breaching No-Log Policy

Russian-based virtual private network (VPN) provider SplitVPN has been accused of violating its no-log policy after a data breach exposed user records and connection logs. This development raises significant concerns for users in Europe who rely on such services to bypass internet censorship.

Background

SplitVPN, formerly known as NotVPN, provides a service that is widely used in countries with heavy internet restrictions. The company has been accused of storing 58 million alleged connection logs linked to its MySQL database after an incident exposed user data including email addresses and masked credit card information. Mysterium VPN’s research team analyzed the leaked SQL database and claimed it contained around 58 million connection logs.

Market / Industry Impact

The breach highlights a broader issue in the European cybersecurity market, where trust is often placed solely on no-log policies without verifiable safeguards. Such incidents can erode user confidence in these services, particularly for individuals living in countries with stringent internet regulations and potential legal repercussions from using VPNs illegally.

What to Watch

  • Independent Audits: Users should look for independent audits of a company's privacy practices before trusting their no-log claims.
  • Additional Security Features: Advanced security features such as kill switches, double VPN servers, post-quantum encryption, and RAM-only servers can provide an extra layer of protection.
  • Regulatory Developments: European regulators may respond to this breach with stricter oversight or guidelines for data handling in the cybersecurity sector.

Takeaway

While SplitVPN denies storing connection logs that could be traced back to individual users, the incident underscores the importance of verifying claims made by VPN providers. Users should prioritize services that undergo regular independent audits and offer robust security features to protect their privacy.