Basic-Fit Breach Exposes 1 Million Members’ Personal and Bank Data
Basic-Fit’s centralized member-visit system was breached, exposing personal details and bank information of about one million gym members across six European countries. The breach was detected and stopped within minutes, but attackers accessed names, addresses, dates of birth, phone numbers, email addresses, and bank details. Passwords were not accessed, which limits immediate account takeover risks but does not prevent fraud.
The affected countries include the Netherlands, Belgium, France, Germany, Luxembourg, and Spain, with approximately 200,000 members impacted in the Netherlands alone. Basic-Fit confirmed the breach after pressure from media and notified affected members and data protection authorities. The attackers exploited a single system that holds membership data for all these countries, making it a high-value target with a broad blast radius.
Access to bank details combined with personal membership information enables highly targeted phishing and financial fraud campaigns that leverage genuine membership context. This breach shows how centralized data systems can become a single point of failure across multiple countries, increasing the risk and scale of exposure even when passwords remain secure.