Egidio
Case file Β· August 21, 2026

Basic-Fit: 1 million bank details, six countries at once

Basic-Fit confirmed a data breach affecting roughly one million members, including bank details, across the six countries where the chain operates: France, Belgium, Germany, Spain, Luxembourg and the Netherlands.

⚠️ Confirmed by the chain itself. Basic-Fit acknowledged the leak and reported the incident to the relevant authorities. What remains unclear is the exact per-country breakdown of affected members β€” the figure given is a global one, not split by country.

The numbers

1M
Members roughly affected, whose data leaked including bank details.
Basic-Fit statement, April 2026.
6
Countries affected: France, Belgium, Germany, Spain, Luxembourg, the Netherlands.
MacGeneration, CNEWS, April 2026.
0
Passwords compromised, according to the company's statements.
Basic-Fit statement.
1
System targeted: the one recording member check-ins at clubs β€” not the payment systems directly.
Basic-Fit statement.

Timeline

CONFIRMED
April 13-14, 2026
Basic-Fit confirms it was the victim of a personal-data leak affecting roughly one million members. The company reports unauthorized access to the system that records member check-ins at its clubs, present across all six countries where it operates.
CONFIRMED
Follow-up
The company specifies the nature of the affected data: name and address, email, phone number, date of birth, subscription information, and bank details. No passwords compromised, according to Basic-Fit.

🌍One incident, continent-wide reach

This case illustrates a different pattern from the France-only breaches documented elsewhere on this site: a single chain, a single compromised system, but an affected population spanning six countries at once, because the company's digital infrastructure is centralized. The geography of the leak follows the geography of the company, not a hacker targeting one specific country.

What it changes for you

If you are or were a Basic-Fit member in any of these six countries, your bank details are among the potentially exposed data. The main risk is an attempted fraudulent charge, or a call posing as the gym's customer service to "verify your payment details." That's the same mechanism documented in From Leak to Scam.

πŸ”’ Watch your bank statements for any unrecognized charge, and be wary of any call asking you to confirm an IBAN or card number, even if it cites your exact membership. See how Medusa links channels together.

Frequently asked questions

Is the Basic-Fit breach confirmed?

Yes, by the chain itself: roughly one million members affected, bank details included, via unauthorized access to the check-in recording system.

Which countries are affected?

France, Belgium, Germany, Spain, Luxembourg, and the Netherlands.

Are my passwords affected?

No, according to Basic-Fit. Bank details, identity and contact information are among the exposed data instead.

πŸ“Œ Last checked: August 21, 2026. Verifiable information to report: contact@egidio.app.

Related reading

Cite this page Egidio β€” The Threat Laboratory, "Basic-Fit: 1 million bank details, six countries at once," egidio.app/en/laboratoire/basic-fit-six-country-breach/. Licensed CC BY 4.0.

Free to reuse, including commercially, with attribution. Reuse terms.