2026 SATS ASA — criminal data breach; file server / shared storage (Nordic fitness)
Data compromised
Internal administrative files; subset of member and employee personal data per company—counts not finalized in early releases
Technical writeup
SATS ASA (Oslo-listed Nordic fitness operator behind SATS, ELIXIA, and related club brands across Norway, Sweden, Denmark, and Finland) disclosed unauthorized access to its IT environment with initial detection March 14, 2026, and public updates through late March–early April 2026. Official press releases and Euronext-listed company news described a criminal data breach involving a file server used for shared internal storage—particularly bookkeeping-oriented administrative documents—with some member names and contact details and a limited set of deeper personal fields, plus employee groups, while core membership systems holding payment cards, passwords, and photos were stated not to be affected. The company reported containment steps, law-enforcement and DPA notification, and ongoing forensics. This entity is not Singapore aviation caterer SATS Ltd.
Root cause
Unauthorized access to internal file server / shared storage (per SATS ASA statements)