``` A Russian VPN service that actively promoted itself as a privacy tool for evading censorship has suffered a catastrophic data breach that blatantly contradicts its core promises. A threat actor is now distributing a 17 GB database on the Altenen cybercrime forum, allegedly stolen from SplitVPN (formerly NotVPN), containing around 58 million connection logs and millions of user, device, and payment records.
The breach delivers a fatal blow to the service's central claim. SplitVPN marketed itself with a strict "no-logs" policy, a critical assurance for users trusting a VPN with their sensitive activity. The massive trove of detailed connection logs demonstrates the company was, in fact, retaining exactly the user activity data it publicly disavowed. For customers who relied on this promise to shield their browsing or access blocked content, this represents a profound betrayal.
According to reporting by Security Affairs, the leaked database extends far beyond session metadata. It reportedly includes user account information, device identifiers, and payment details, creating a comprehensive profile of affected users. The immediate implications are severe: anyone who used SplitVPN must assume all credentials and financial information linked to the account are compromised. Essential first steps include changing passwords for the VPN and any other services where those credentials were reused, revoking stored payment methods, and monitoring financial accounts for fraud.
The incident also underscores the critical, often overlooked factor of jurisdiction. Operating from Russia, SplitVPN was subject to national laws that can mandate data retention and surveillance, regardless of a provider's own policy statements. This breach provides stark evidence that a company's privacy pledge can be meaningless when it conflicts with local legal requirements. Users who employed the service to circumvent censorship now face the grim possibility that their sensitive connection histories are exposed to criminals—and potentially to other actors who acquire the data.
For the broader tech and open-source community, the episode reinforces hard lessons about digital trust. Marketing slogans are not a substitute for verifiable practice. Independent, third-party audits of a provider's infrastructure and policies remain one of the few methods to meaningfully validate their claims. Furthermore, using open-source VPN clients offers a crucial layer of transparency, allowing security researchers to examine what data is actually transmitted from a user's device. While not foolproof, these measures significantly increase accountability.
The consequences are disproportionately severe for individuals in restrictive environments who depend on VPNs for safety and access. A breach of this scale doesn't just cause inconvenience; it can expose patterns of behavior that lead to real-world harm. This reality must drive the industry toward greater transparency and compel users to favor providers that submit to external scrutiny.
Until further details emerge about the breach's origin and SplitVPN provides a formal response, all former customers should operate under the assumption of total compromise and take immediate protective action. The lesson for the entire market is unequivocal: a no-logs pledge is worthless without independent, technical evidence to support it.
一項積極標榜自身為規避審查私隱工具的俄羅斯VPN服務,遭遇災難性數據洩露,徹底違背其核心承諾。一名威脅行為者現正於暗網犯罪論壇Altenen分發一個17GB的數據庫,據稱從SplitVPN(原名NotVPN)竊取,包含約5,800萬條連線日誌及數百萬用戶、設備及支付紀錄。
此次洩露對該服務的核心主張造成致命打擊。SplitVPN以嚴格的「零日誌」政策進行市場推廣,此乃用戶將敏感網絡活動託付予VPN的關鍵保證。龐大的詳細連線日誌儲存庫證明,該公司實際上保留了其公開否認的用戶活動數據。對於依賴此項承諾以隱藏瀏覽活動或存取被封鎖內容的客戶而言,這構成嚴重背叛。
據《Security Affairs》報導,洩露的數據庫遠超會話元數據範圍。據悉包含用戶帳戶資料、設備識別碼及支付詳情,構成受影響用戶的完整資料檔案。直接影響嚴重:任何使用SplitVPN者均須假設與該帳戶相關的所有憑證及財務資料已遭洩露。緊急應對措施包括更改VPN及其他重用相同憑證的服務密碼、撤銷儲存的支付方式,並監控金融帳戶以防詐騙。
事件同時凸顯司法管轄權這項常被忽視的關鍵因素。SplitVPN在俄羅斯營運,受國家法律約束,無論服務商自身政策聲明如何,均可強制數據留存及監控。此次洩露提供明確證據,顯示當公司私隱承諾與本地法律要求衝突時,承諾可能毫無意義。利用該服務規避審查的用戶,如今面臨其敏感連線記錄可能已遭犯罪分子——或其他獲取數據的行為者——取得的嚴峻可能。
對更廣泛的科技及開源社區而言,此事件強化了關於數碼信任的深刻教訓。市場營銷口號無法替代可驗證的實踐。對服務商基礎設施及政策進行獨立第三方審計,仍是實質驗證其主張的少數方法之一。此外,使用開源VPN客戶端可提供關鍵透明度層級,讓安全研究人員能審查用戶設備實際傳送何類數據。此類措施雖非萬無一失,但顯著提升問責能力。
對依賴VPN保障安全及存取權限的限制環境中個人而言,後果尤為嚴重。如此規模的洩露不僅造成不便;更可能揭露導致現實傷害的行為模式。此現狀必須推動行業提升透明度,並促使用戶優先選擇接受外部審查的服務商。
在洩露源頭細節進一步明朗及SplitVPN正式回應前,所有前客戶應假設已遭全面洩露並立即採取防護行動。對整個市場的教訓明確無誤:缺乏獨立技術證據支持的零日誌承諾毫無價值。
