A hacker posted the records of 1,848 gym members in France last week. Names, dates of birth, payment histories, unpaid balances.
The company whose software holds that data, FitnessKPI, says its platform was not breached. It is probably right.
Both of those things being true at once is the part worth your time.
Was FitnessKPI actually breached?
On the evidence so far, no. The company says it reviewed its access logs. It found no compromise of its database, servers or infrastructure, and no vulnerability exploited in the platform or its API. Someone signed in through the normal login page, using a real username and password belonging to a customer administrator account. They saw what that account was allowed to see. Cybernews analysed the leaked files itself and found every profile traced to a single gym, which supports the company's account rather than contradicting it. Nobody broke in. Someone logged in.
What was in the files
A hacker using the name Syrv4x posted the data late last week, claiming 1,848 member records. Cybernews reported that all of it traces to Genae Écully, a club near Lyon. Genae runs a few gyms in the area and is a FitnessKPI customer.
| In the files | Not in the files |
|---|---|
| Names, emails, phone numbers | Card numbers |
| Gender, age, date of birth, postal code | CVV codes |
| Membership details and contracts | Bank account details |
| Bookings and attendance | Health information |
| Payment history and unpaid balances |
Roughly 160,000 of the entries relate to payments: amounts, invoice dates, payment status, outstanding debts. FitnessKPI says it does not collect card numbers, CVV codes, bank details or health data, so none of that was there to take.
No banking details sounds reassuring until you read what is there instead.
Why "we were not breached" does not help you
If the access came through a customer's own administrator account, then the security boundary that failed was not the vendor's. It was the gym's. How that username and password reached a third party is not established, and FitnessKPI has not said. The possibilities are the ordinary ones. A password reused somewhere that was breached. A login shared across staff. An account belonging to someone who left months ago. A phishing email that worked.
This is valid-credential access (someone signing in with a real username and password rather than exploiting a flaw in the software). It is the failure mode no amount of vendor security review will catch. Your software can be flawless and your front desk can still be the way in.
There is a sharper irony here. Genae uses FitnessKPI to work out which members are likely to cancel. The behavioural profile built to predict churn is now the behavioural profile available to whoever wants to impersonate the club.
What someone can actually do with this
The Cybernews research team made the point plainly. This data supports credible phishing, because the sender can name the plan the person actually holds and the payments they actually made. An email that knows your plan and your last invoice does not look like a scam.
The unpaid balances are worse. Someone can send a real-looking reminder for a real outstanding amount to the exact member who owes it, and ask them to pay through a link. We have written before about members handing their own data to tools nobody vetted. This is the other direction: the data a member handed to you, used against them.
What to do this week
Four things, none of which need a security budget.
Pull the admin user list on every platform you run and delete every account belonging to someone who no longer works for you. Then check whether any login is shared between people, because a shared account cannot be traced to anyone when something goes wrong. Turn on two-factor authentication wherever your vendor offers it, which is the single control that would have stopped this one. And give front desk staff the access they need rather than the access that was convenient to set up.
Then ask your vendor two questions in writing. Can you list every admin login on my account? Can you show me when each one last signed in? If the answer to either is no, that is worth knowing before you need it rather than after.
We said when Mindbody started benchmarking studios against each other that you are on both sides of the data you hand over. This is the other half of that trade. Your software vendor can do everything right and still hand your members' lives to someone holding one password that should have been switched off in March.