Basic-Fit data breach exposes roughly one million members across six countries
TL;DR
Basic-Fit confirmed on 13 April 2026 that attackers accessed a system holding member data for approximately one million of its 5.8 million customers across six countries. Exposed data includes names, addresses, email addresses, phone numbers, dates of birth, and bank account numbers. Basic-Fit's own monitoring cut off the access within minutes, but external security experts have confirmed that a large volume of data was downloaded in that short window.
Incident Response PlaybookExpand
- Confirm the exposure and reproduce the access path.
- Close the exposure and restrict the affected system. Preserve snapshots and logs before any clean-up.
- Pull database, application, and network logs to determine what was accessed, by whom, and over what window.
- Determine whether exfiltration actually occurred or only access.
- Quantify the scope: which records, which fields, how many individuals per country.
- Run structured forensic evidence collection across affected systems.
- Check for secondary exposures. Attackers who find one path often find others.
- Notify legal counsel and the Autoriteit Persoonsgegevens (Dutch DPA) within 72 hours, with equivalent notifications to regulators in the other affected countries.
- Notify affected members and provide clear guidance on what the exposed data enables and what it does not.
- Prepare external communications that match what forensics actually show, not what the first-hour assumption was.
- Post-incident review focused on detection-to-containment-to-exfiltration timing, not just detection.
The Basic-Fit data breach, in brief
On 13 April 2026, Dutch fitness chain Basic-Fit confirmed a Basic-Fit data breach affecting approximately one million of its 5.8 million members. The incident spans six countries: the Netherlands, Belgium, France, Spain, Luxembourg, and Germany. In the Netherlands, roughly 200,000 members are affected. Basic-Fit has notified the Autoriteit Persoonsgegevens, the Dutch data protection authority, under the AVG (the Dutch implementation of GDPR).
Exposed data includes membership information, names, addresses, email addresses, phone numbers, dates of birth, and bank account numbers. Passwords were not exposed, and Basic-Fit does not store copies of identity documents.
What happened
Basic-Fit's own monitoring systems detected unauthorised access to a customer data environment. According to the company's statement, the access was cut off within minutes. That is fast by any reasonable standard.
According to reporting from Hart van Nederland and Bright, external security experts who reviewed the incident confirmed that during those minutes a large volume of data was already downloaded. Basic-Fit has not disclosed the attack vector, and no group has claimed responsibility. Attribution is unknown, and we are not going to guess.
Coverage by ANP (carried by welingelichtekringen.nl, zeelandnet.nl and others) and VRT NWS for the Belgian side established the one-million figure and the cross-border scope within hours of Basic-Fit's disclosure. The Telegraaf and AD reported the initial 200,000 figure for Dutch members. At time of writing, Basic-Fit has communicated via direct email to affected members and statements to the press. We did not find a dedicated incident page on corporate.basic-fit.com; if one is published, it will be the authoritative source.
How the attack worked
Here is the uncomfortable part: we do not know, and neither, in public at least, does anyone else. Basic-Fit has described the access as unauthorised and has not disclosed the entry point. Speculating on the technique serves no one.
What we can say is how the outcome happened, which is almost more interesting. Detection worked. Containment worked. The attackers still left with a million records. This is the shape of modern data theft: once an attacker is inside a database worth copying, exfiltration can outrun containment. Bulk SELECT queries against a populated customer table move fast. The gap between "we saw them" and "they were gone" is often measured in seconds, not hours.
Basic-Fit did a lot right here. Monitoring caught it. Response was measured in minutes, not weeks. Disclosure came within a day. Those are not the places this story hurts.
Who is affected
Approximately one million of Basic-Fit's 5.8 million members, across six markets: the Netherlands (around 200,000), Belgium, France, Spain, Luxembourg, and Germany. Omroep Brabant noted that the company operates 41 locations in North Brabant alone, which gives a sense of how concentrated the Dutch customer base is regionally.
The exposed data is a complete personal profile for fraud purposes: full name, home address, date of birth, email address, phone number, and bank account number. That combination is the raw material for convincing fake incasso (direct debit) requests, targeted phishing, and identity impersonation against Dutch consumers, who are by far the largest affected group.
What this means for your organisation
The Basic-Fit story is a consumer breach on its face. For Dutch business decision-makers, the relevant takeaways are not about fitness memberships.
First, the detection-to-exfiltration gap is where exposure actually lives. Detection within minutes is excellent. It also was not enough. If your board has been reassured that "we have monitoring in place," that is the start of the conversation, not the end. The question worth answering is: how fast can your SOC or EDR actually cut network egress from a database server, and has anyone ever timed it under realistic conditions?
Second, the data your suppliers hold about you matters as much as your own perimeter. Many Basic-Fit members signed up with work email addresses. For the IT manager at a mid-sized Dutch company, there is now a reasonable chance that a hundred of your employees appear in this dataset, with full name, home address, DOB, and phone number attached to a verified work email. That is a spearphishing list pointed at your company, built by someone else.
Third, expect the follow-on wave. A dataset this size typically surfaces in fragments over the next six to twelve months: targeted phishing emails referencing real Basic-Fit membership details, fake SEPA direct debit notifications, and impersonation of Basic-Fit in customer service scams. The useful question is not whether that wave is coming. It is whether your phishing defences are tuned to catch messages that contain accurate personal details, because the old "obvious typos and weird sender" training is about to age badly.
Organisations that want continuous visibility into what attackers already hold about them, including leaked credentials and exposed data tied to their domain, can get that through SecDesk's Threat Exposure Management service. It is the closest equivalent to seeing your company through the attacker's side of the glass.
Talk to a senior responder about Basic-Fit data breach exposes roughly one million members across six countries.
Schedule a response callNeed incident response?
- Two-hour SLA
- Dutch senior responders
