Basic-Fit
Incident posture
Timeline
Summary
Basic-Fit disclosed a data breach affecting about one million members across several European countries after detecting unauthorized access to its systems that was blocked within minutes. The compromised data included names, email addresses, physical addresses, phone numbers, dates of birth, and bank account details, though the company said it does not store identification documents or passwords. Approximately 200,000 of the affected members are from the Netherlands, with the remainder in Spain, Germany, France, Belgium, and Luxembourg. The company stated it is unaware of any leaked or misused data and no ransomware group has claimed responsibility.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Basic-Fit detected unauthorized access to its systems shortly before issuing a press release on Monday, and the intrusion was blocked within minutes of detection. Upon discovering the breach, the company launched an internal investigation to determine the scope and nature of the unauthorized activity. No further details about the exact timing of the initial detection were provided in the public statements.
The investigation revealed that data belonging to active members in several European countries had been downloaded by the attacker. Compromised information included names, email addresses, physical addresses, phone numbers, dates of birth, and bank account details. Basic-Fit stated that it does not store identification documents for members and that no passwords were accessed during the incident. The company reported that approximately 200,000 affected members are located in the Netherlands.
Basic-Fit disclosed that the total number of impacted members across Europe is approximately one million, with additional affected individuals in Spain, Germany, France, Belgium, and Luxembourg. In its press release, the company noted that it has over five million members and operates about 1,500 clubs throughout Europe. Basic-Fit indicated that it is not aware of any leakage or misuse of the stolen data and that no ransomware group has claimed responsibility for the attack. The company stated that the intrusion was blocked within minutes of detection and that it had released a public statement detailing the incident.
Sources
Sources available to members: 1 source.