Back to Blog
Cybersecurity April 16, 2026 5 min read

Basic-Fit Data Breach Exposes Bank Details of 1 Million Gym Members Across Six Countries

Europe's largest gym chain disclosed a breach affecting roughly 1 million members in the Netherlands, Belgium, France, Spain, Luxembourg, and Germany. Exposed data includes names, addresses, and bank account numbers.

Basic-Fit Data Breach Exposes Bank Details of 1 Million Gym Members Across Six Countries

Basic-Fit, Europe’s largest gym chain with over 1,700 clubs across 12 countries, disclosed a data breach affecting approximately 1 million members in six European countries. The exposed data includes names, addresses, email addresses, phone numbers, dates of birth, and bank account details — enough for targeted phishing campaigns and fraudulent direct debit attacks.

The breach hit members in the Netherlands (around 200,000), Belgium, Luxembourg, France, Spain, and Germany. Basic-Fit said its monitoring systems detected the intrusion and stopped it “within minutes,” but not before attackers exfiltrated records at scale.

No passwords were accessed. No government ID documents or payment card numbers were part of the leaked dataset. The bank account details — likely IBAN numbers collected for monthly membership fees — represent the most significant risk. Under SEPA Direct Debit mandates, a creditor with your IBAN and authorization reference can initiate withdrawals. Fraudulent SEPA claims are reversible, but the process takes time and can trigger overdrafts.

The attack vector hasn’t been disclosed publicly. Basic-Fit’s rapid detection suggests endpoint monitoring was in place, but 1 million records exfiltrated in “minutes” indicates either an extremely wide data access window or a highly efficient extraction mechanism. Both possibilities point to insufficient access controls on the underlying database.

Basic-Fit operates under Dutch law and is fully subject to GDPR. The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) has been notified, as required when a breach affects more than 500 EU residents. GDPR’s fine ceiling is 4% of global annual turnover — Basic-Fit reported €1.1 billion in revenue for 2024, putting the theoretical maximum penalty above €44 million.

What to do if you’re a Basic-Fit member:

  • Watch for phishing emails impersonating Basic-Fit, your bank, or government agencies in your country
  • Contact your bank to flag your IBAN as potentially compromised and request monitoring of unauthorized direct debit mandates
  • Enable two-factor authentication on any account tied to the email address you used with Basic-Fit
  • Review bank statements for unexpected direct debits over the next 60–90 days

Whether regulators treat “within minutes” containment as a sufficient organizational measure under GDPR Article 32 is an open question. Detection speed helps. But the volume of records extracted before containment will feature in any enforcement decision.

This is the second significant European gym chain breach in three years. Consumer-facing businesses holding large direct-debit databases are a consistent target — and Basic-Fit’s 1 million-member footprint across six countries makes it a particularly attractive one.

data-breach gdpr basic-fit cybersecurity europe