2026 Twizzit — vuln copied club/youth PII; Chirojeugd Vlaanderen confirms; minors possible
Data compromised
Per Chirojeugd Vlaanderen email to volunteer leaders (Twizzit notified the organisation): first and last names, profile photos, and email addresses; data relating to minors may also be involved. Passwords, bank account numbers, and payment details were not leaked per the organisation. Platform serves >5,500 organisations and >1.2M users — that is platform size, not an attested census of copied records. Affected-person count unpublished.
Technical writeup
Verified via Chirojeugd Vlaanderen confirmation reported by The Brussels Times with Belga (26 Sep 2026). Twizzit, a Belgian SaaS used by sports federations/clubs/youth orgs, suffered a data breach in which an unauthorised party exploited a platform vulnerability and copied personal data. Chirojeugd Vlaanderen said Twizzit informed it of the incident; volunteer-leader email lists names, profile photos, and emails as stolen; minors’ data may be involved; passwords and payment details said not leaked. Twizzit reportedly stopped the attack, fixed the vulnerability, and added security measures; investigation ongoing. Platform marketing cites >5,500 orgs / >1.2M users — not treated as confirmed affected census. recordsAffected 0; companyConfirmed true (customer org confirmation + Twizzit notification acknowledged in press).
Root cause
Unauthorised party exploited a vulnerability in the Twizzit sports/youth SaaS platform and copied personal data (Chirojeugd Vlaanderen notice via Belga / Brussels Times)
References
- https://www.brusselstimes.com/belgium/2334762/flemish-youth-sports-platform-falls-victim-of-data-breach
- http://brusselstimes.com/belgium/2334762/flemish-youth-sports-platform-falls-victim-of-data-breach
- https://ground.news/article/major-data-leak-at-app-used-by-many-sports-clubs-chiro-also-warns-be-extra-alert-for-phishing