Basic Fit has leaked the data of hundreds of millions of users. They don't know how to fix it

Basic-Fit, the largest low-cost gym chain in Europe, has confirmed a significant data breach affecting approximately 1 million members in several countries, with around 200,000 affected just in the Netherlands. The company, which operates more than 2,150 gyms and has over 4.5 million members in total, detected the intrusion through internal monitoring tools, stopping unauthorized access within minutes, although not before a considerable volume of data from its members was downloaded. You’re going to sweat The attack focused on […]

Basic-Fit, the largest low-cost gym chain in Europe, has confirmed a significant data breach that affects approximately 1 million members in several countries, with around 200,000 affected just in the Netherlands. The company, which operates more than 2,150 gyms and has over 4.5 million members in total, detected the intrusion through internal monitoring tools, stopping unauthorized access within minutes, although not before a considerable volume of data from its members was downloaded.

You are going to sweat

The attack focused on the system that Basic-Fit uses to record member visits to its facilities, and did not affect its broader infrastructure. The compromised data includes sensitive personal information, but the company has assured that no identity documents or passwords were accessed, and so far there are no indications that the leaked data has been misused. Basic-Fit has formally notified the Dutch Data Protection Authority as part of its obligations under the GDPR.

The company has directly informed all affected members about the incident and has advised them to be vigilant for suspicious emails or calls and to monitor their bank statements for anomalies. Cybersecurity experts warn that the exposure of personal information, such as banking data and full contact details, increases the risk of phishing and financial fraud targeting the affected individuals.

So far, Basic-Fit has not revealed the identity of the actors behind the intrusion, and investigations into the incident are ongoing. This data breach occurs in a context where other significant security incidents have affected organizations in the Netherlands, such as the case of the telecommunications provider Odido, which exposed millions of customer records in 2023.