SplitVPN Breach Exposes 865,000 Email Addresses and Partial Payment Card Data
What Happened — In July 2026 the Russian‑operated VPN service SplitVPN (formerly NotVPN) suffered a data breach that released 865,336 unique email addresses, associated IP addresses, geographic locations, device information, and partial credit‑card details (first 6 and last 4 digits plus expiry).
Why It Matters for Compliance & Audit Readiness
- The incident is a textbook example of a credential‑related compromise that SOC 2’s Logical Access Controls (CC6.1) are designed to prevent and evidence.
- Continuous monitoring of password policies, MFA enforcement, and privileged‑access reviews provides the audit trail needed to demonstrate “reasonable security” to auditors.
- Mapping this breach to your SOC 2 control set helps you identify gaps, collect remediation evidence, and maintain a defensible posture for future assessments.
Who Is Affected – VPN providers, SaaS platforms handling user authentication, and any organization that relies on SplitVPN for remote access.
Recommended Actions –
- Verify that all SplitVPN‑related credentials have been rotated and that MFA is enforced for every user.
- Update your SOC 2 access‑control evidence repository with logs of password‑policy changes, MFA enrollment, and any anomalous login activity detected during the breach window.
- Conduct a focused control‑mapping exercise to confirm that CC6.1 (Logical Access Controls) and CC6.2 (User Access Reviews) are fully implemented and auditable.
Source: Have I Been Pwned – SplitVPN Breach
Technical Notes – The breach disclosure does not specify a single exploit; the attack vector appears to be a compromise of SplitVPN’s authentication store, leading to exposure of email, IP, and partial card data. No CVE identifiers were provided. Source: same as above