Breach: SplitVPN (865,336 accounts) — Device information, Email addresses, Geographic locations
BREACH. Sourced from hibp, summarised by Matproof.
AI Analysis
What changed and what to do.
On July 21, 2026, a data breach affecting SplitVPN was published on Have I Been Pwned, exposing 865,336 user accounts. The compromised data includes device information, email addresses, and geographic locations. This incident indicates that a virtual private network provider, which markets itself on privacy and security, suffered a significant data exposure, undermining user trust and potentially revealing sensitive metadata about subscribers.
Organizations in all sectors are affected if their employees or customers used SplitVPN for remote work or personal browsing. This is particularly critical for sectors with strict data protection obligations, such as finance, healthcare, and legal services, where the exposure of email addresses and location data could facilitate targeted phishing, social engineering, or physical security threats. Any company that reimbursed or mandated VPN usage for staff should treat this as a third-party risk event.
Compliance teams should immediately verify whether any corporate email addresses appear in the breach using HIBP’s domain search. If affected, they must reset credentials, enforce multi-factor authentication, and review access logs for suspicious activity. Additionally, update your vendor risk register to reflect SplitVPN’s failure, assess whether this constitutes a notifiable breach under GDPR or other regulations, and issue a clear advisory to employees about phishing risks. Finally, consider recommending alternative VPN providers with a stronger security track record.
This summary is AI-generated for orientation purposes. For regulatory action, always consult the original source linked above.
Map this to your controls
Connect regulatory changes to your compliance work.
Matproof maps every regulator update directly to your controls and surfaces the ones that affect your organisation — across 21 frameworks.