TL;DR: Basic-Fit, Europe's largest gym chain with 5.8 million members, confirmed on April 14 that hackers breached its systems and downloaded personal data belonging to roughly 1 million members across the Netherlands, Belgium, Luxembourg, France, Spain, and Germany. The stolen data includes names, addresses, emails, phone numbers, birth dates, and (critically) bank account details. The company claims it stopped the intrusion "within minutes." No threat actor has claimed responsibility. If you're a Basic-Fit member, your bank should be your first call.
Your Gym Knows Your Bank Details. Now Hackers Do Too.
Basic-Fit disclosed the breach on April 14, 2026, after its monitoring systems flagged unauthorized access to member data [1]. The company said the intrusion was "detected and stopped within minutes." But minutes was all it took to download data on a million people.
Think about what you hand over when you sign up for a gym membership. Name, address, email, phone number, birth date. Standard stuff. But Basic-Fit also stores your bank account details for monthly direct debit payments. That's IBAN numbers. Sitting in a database. Now in someone else's hands.
The company rushed to clarify what wasn't stolen: no passwords, no identification documents. Cold comfort when the attackers have your bank account number, full name, date of birth, and home address: everything needed to authorize fraudulent transactions or open accounts in your name.
Six Countries, One Million Members
The breach spans Basic-Fit's operations across six European countries:
- Netherlands: ~200,000 members confirmed affected
- Belgium, Luxembourg, France, Spain, Germany: remaining ~800,000 members across these markets
Basic-Fit operates over 2,150 gyms across 12 countries under the Basic-Fit and Clever Fit brands, with 5.8 million registered members total [2]. That means roughly one in six members got caught in this breach.
The company emailed affected members directly, warning them to watch for phishing attempts. They also notified data protection authorities in each affected country, including the Dutch Autoriteit Persoonsgegevens, which has been increasingly aggressive about GDPR enforcement this year.
Why Bank Details Make This Breach Different
Most data breaches expose the usual lineup: emails, names, maybe passwords. Annoying, but manageable. Bank account details change the equation.
With your IBAN, name, and address, an attacker can:
- Set up fraudulent direct debits: in some European banking systems, all you need is an IBAN to initiate a collection
- Impersonate you to your bank: date of birth + address + account number is often enough to pass phone verification
- File fraudulent tax returns: especially in the Netherlands and Belgium, where bank accounts are tied to tax identity
- Conduct targeted phishing: emails that reference your actual bank, actual address, and actual account are devastatingly effective
Basic-Fit says there's "no evidence of data misuse" so far [3]. That qualifier ("so far") is doing a lot of heavy lifting. Stolen financial data often surfaces weeks or months later, after it's been packaged and sold on dark web marketplaces.
"Stopped Within Minutes" Doesn't Mean What You Think
Basic-Fit is leaning hard on the speed of its response. Detected quickly. Stopped within minutes. External security experts brought in immediately.
Here's the problem: modern data exfiltration doesn't need hours. Automated tools can scrape and compress database exports in seconds. A well-prepared attacker with a database connection can pull a million records faster than you can read this paragraph.
"Stopped within minutes" means the access was brief. It doesn't mean the damage was limited. Basic-Fit confirmed as much by acknowledging that "external security experts subsequently confirmed that intruders had downloaded some data" [1]. "Some data" turned out to be a million people's financial information.
No ransomware group has claimed responsibility, which is unusual for a breach of this scale. Either the attackers are sitting on the data for a private sale, they haven't finished exploiting it, or this was an opportunistic smash-and-grab rather than a planned extortion operation.
What to Do if You're a Basic-Fit Member
Contact Your Bank Now
Tell them your account details were exposed in a breach. Ask about setting up alerts for unusual direct debit requests or unauthorized transactions. Some European banks can flag or block new direct debit mandates.
Monitor Your Account Daily
Check your bank statements every day for the next few months. Look for small test transactions. Attackers often start with tiny amounts to verify an account is active before making larger withdrawals.
Watch for Targeted Phishing
Attackers now have your real name, address, and bank details. Expect convincing emails pretending to be from Basic-Fit, your bank, or tax authorities. Don't click links in emails. Go directly to official websites.
Consider Changing Your Bank Account
If your IBAN has been compromised, the safest option is opening a new account and migrating your direct debits. It's a hassle. It's also the only way to fully close the door.
GDPR Enters the Chat
Basic-Fit operates across the EU, which means GDPR applies in full force. Under the regulation, companies must notify authorities within 72 hours of discovering a breach, which Basic-Fit appears to have done.
But GDPR also requires "appropriate technical and organizational measures" to protect personal data. When a breach exposes bank account details for a million people, regulators are going to want answers about what those measures looked like.
The Dutch DPA fined Booking.com €475,000 in 2021 for a 22-day delay in breach notification. The scale of Basic-Fit's exposed data, particularly the financial component, could attract significantly larger penalties. GDPR allows fines up to 4% of annual turnover. For Basic-Fit, with €1.42 billion in revenue, that ceiling is north of €56 million [4].
Whether regulators pursue enforcement depends on what the investigation reveals about Basic-Fit's security posture. Was the database encrypted? Were bank details stored separately from other personal data? Was access properly segmented? Those answers will determine whether this breach was bad luck or negligence.
Your Gym Collects More Data Than You Think
Basic-Fit isn't unique in hoarding member data. Most gym chains store:
- Full payment details (bank accounts or credit cards) for recurring billing
- Check-in logs showing exactly when you visit and which location
- Biometric data if they use fingerprint or facial recognition scanners at entry
- App usage data including workout plans and body measurements
- Photo IDs uploaded during registration
Basic-Fit says identification documents weren't part of this breach. But the fact that they collect them, and store them alongside payment data, is the real issue. Every piece of data a company collects is a piece of data that can be stolen.
If you can pay for your gym membership with a prepaid card or privacy-focused payment method, do it. The less financial data sitting in their systems, the less damage a breach can do.
References
- Help Net Security - Basic-Fit hack compromises data of up to 1 million members (April 14, 2026)
- The Register - Gym giant Basic-Fit breached with at least 1M affected (April 13, 2026)
- Security Affairs - Personal data of 1 million gym members compromised in Basic-Fit security incident (April 2026)
- SecurityWeek - Europe's Largest Gym Chain Says Data Breach Impacts 1 Million Members (April 2026)
- Cybernews - Basic-Fit breach exposes bank details, puts 1 million members at risk (April 2026)