← Twizzit

2026 Twizzit — vuln copied club/youth PII; Chirojeugd Vlaanderen confirms; minors possible

2026 Unknown records affected Share on X

Data compromised

Per Chirojeugd Vlaanderen email to volunteer leaders (Twizzit notified the organisation): first and last names, profile photos, and email addresses; data relating to minors may also be involved. Passwords, bank account numbers, and payment details were not leaked per the organisation. Platform serves >5,500 organisations and >1.2M users — that is platform size, not an attested census of copied records. Affected-person count unpublished.

Technical writeup

Verified via Chirojeugd Vlaanderen confirmation reported by The Brussels Times with Belga (26 Sep 2026). Twizzit, a Belgian SaaS used by sports federations/clubs/youth orgs, suffered a data breach in which an unauthorised party exploited a platform vulnerability and copied personal data. Chirojeugd Vlaanderen said Twizzit informed it of the incident; volunteer-leader email lists names, profile photos, and emails as stolen; minors’ data may be involved; passwords and payment details said not leaked. Twizzit reportedly stopped the attack, fixed the vulnerability, and added security measures; investigation ongoing. Platform marketing cites >5,500 orgs / >1.2M users — not treated as confirmed affected census. recordsAffected 0; companyConfirmed true (customer org confirmation + Twizzit notification acknowledged in press).

Root cause

Unauthorised party exploited a vulnerability in the Twizzit sports/youth SaaS platform and copied personal data (Chirojeugd Vlaanderen notice via Belga / Brussels Times)

References