2026 Basic-Fit — member data access (~1M members; ~200k NL; IBANs; Apr)
Data compromised
Names, DOB, contact info, bank account details (no passwords/ID docs per company)
Technical writeup
European gym operator Basic-Fit publicly confirmed unauthorized access to member-oriented systems, with Reuters and trade outlets reporting on the order of one million affected members across several European markets and roughly 200,000 in the Netherlands. Disclosed categories included names, birth dates, contact details, and bank account identifiers; the company stated passwords and ID documents were not involved and described rapid detection and containment with phishing called out as the main follow-on risk.
Root cause
Unauthorized access to member systems (specific vector not fully detailed in initial press)