Latest
FitnessKPI denies breach after gym member data leaks/FitnessKPI denies breach after gym member data leaks/FitnessKPI denies breach after gym member data leaks/FitnessKPI denies breach after gym member data leaks/
← Tech & AI
Tech & AI · Oct 6, 2026 · 4 min read

1,848 Gym Members' Data Leaked. Someone Used a Staff Password.

A hacker posted the records of 1,848 gym members, including dates of birth and payment histories. The software was not broken into. Someone signed in with a staff login.

Alice covers growth, retention and technology for fitness and wellness operators at The Run Rate.

Editorial collage of an open padlock and a membership card file
Make The Run Rate one of your go-to sources on Google Add The Run Rate on Google
1,848
Member records exposed
160,000
Payment entries in the files
0
Banking details taken

A hacker posted the records of 1,848 gym members in France last week. Names, dates of birth, payment histories, unpaid balances.

The company whose software holds that data, FitnessKPI, says its platform was not breached. It is probably right.

Both of those things being true at once is the part worth your time.

Was FitnessKPI actually breached?

On the evidence so far, no. The company says it reviewed its access logs. It found no compromise of its database, servers or infrastructure, and no vulnerability exploited in the platform or its API. Someone signed in through the normal login page, using a real username and password belonging to a customer administrator account. They saw what that account was allowed to see. Cybernews analysed the leaked files itself and found every profile traced to a single gym, which supports the company's account rather than contradicting it. Nobody broke in. Someone logged in.

What was in the files

A hacker using the name Syrv4x posted the data late last week, claiming 1,848 member records. Cybernews reported that all of it traces to Genae Écully, a club near Lyon. Genae runs a few gyms in the area and is a FitnessKPI customer.

In the filesNot in the files
Names, emails, phone numbersCard numbers
Gender, age, date of birth, postal codeCVV codes
Membership details and contractsBank account details
Bookings and attendanceHealth information
Payment history and unpaid balances

Roughly 160,000 of the entries relate to payments: amounts, invoice dates, payment status, outstanding debts. FitnessKPI says it does not collect card numbers, CVV codes, bank details or health data, so none of that was there to take.

No banking details sounds reassuring until you read what is there instead.

Why "we were not breached" does not help you

If the access came through a customer's own administrator account, then the security boundary that failed was not the vendor's. It was the gym's. How that username and password reached a third party is not established, and FitnessKPI has not said. The possibilities are the ordinary ones. A password reused somewhere that was breached. A login shared across staff. An account belonging to someone who left months ago. A phishing email that worked.

This is valid-credential access (someone signing in with a real username and password rather than exploiting a flaw in the software). It is the failure mode no amount of vendor security review will catch. Your software can be flawless and your front desk can still be the way in.

There is a sharper irony here. Genae uses FitnessKPI to work out which members are likely to cancel. The behavioural profile built to predict churn is now the behavioural profile available to whoever wants to impersonate the club.

What someone can actually do with this

The Cybernews research team made the point plainly. This data supports credible phishing, because the sender can name the plan the person actually holds and the payments they actually made. An email that knows your plan and your last invoice does not look like a scam.

The unpaid balances are worse. Someone can send a real-looking reminder for a real outstanding amount to the exact member who owes it, and ask them to pay through a link. We have written before about members handing their own data to tools nobody vetted. This is the other direction: the data a member handed to you, used against them.

What to do this week

Four things, none of which need a security budget.

Pull the admin user list on every platform you run and delete every account belonging to someone who no longer works for you. Then check whether any login is shared between people, because a shared account cannot be traced to anyone when something goes wrong. Turn on two-factor authentication wherever your vendor offers it, which is the single control that would have stopped this one. And give front desk staff the access they need rather than the access that was convenient to set up.

Then ask your vendor two questions in writing. Can you list every admin login on my account? Can you show me when each one last signed in? If the answer to either is no, that is worth knowing before you need it rather than after.

We said when Mindbody started benchmarking studios against each other that you are on both sides of the data you hand over. This is the other half of that trade. Your software vendor can do everything right and still hand your members' lives to someone holding one password that should have been switched off in March.

Frequently Asked Questions

Was FitnessKPI hacked?
FitnessKPI says no. The company states it reviewed its access logs and found no compromise of its database, servers or infrastructure, and no vulnerability exploited in its platform or API. It says a third party signed in through the standard login process using valid credentials belonging to a customer administrator account, and accessed only what that account was authorised to see. Cybernews analysed the leaked files and found all profiles traced to one gym, which supports that account. How the credentials reached the third party has not been established.
What data was exposed in the FitnessKPI leak?
According to the dark web listing analysed by Cybernews, the files contain member names, email addresses, phone numbers, gender, ages, dates of birth, postal codes, membership details, contracts, bookings, payment information and unpaid balances, covering 1,848 members of Genae \u00c9cully near Lyon. Around 160,000 entries relate to payments. FitnessKPI says it does not collect or store card numbers, CVV codes, bank account details or member health information, so those were not involved.
What should a gym owner do about this?
Treat admin credentials as the security boundary, because in this case they were. Pull the admin user list on every platform you run and remove accounts belonging to anyone who has left. Check whether any login is shared between staff, since a shared account cannot be traced to a person. Enable two-factor authentication wherever your vendor supports it. Then ask your vendor in writing for a list of every admin login on your account and when each last signed in.
More from The Run Rate