Europe’s largest budget gym chain just handed hackers a very useful dataset.
Basic-Fit, which operates more than 2,150 clubs across 12 European countries and counts roughly 5.8 million registered members, confirmed on April 13 that attackers broke into one of its internal systems and walked off with personal data belonging to approximately one million people. The affected members are spread across the Netherlands, Belgium, Luxembourg, France, Spain, and Germany.
What got taken: full names, home addresses, email addresses, phone numbers, dates of birth, and bank account numbers, specifically IBANs. Passwords and government ID documents were not in the compromised system, Basic-Fit says.
The IBAN detail matters. A lot.
What They Actually Got
Most breach disclosures focus on the email and password combo, which is familiar enough that people have learned to change passwords and move on. This one is different. With a name, an IBAN, a home address, and a date of birth, an attacker has everything needed to submit a fraudulent SEPA direct debit mandate against someone’s bank account. SEPA’s chargeback window is 13 months for unauthorized transactions, which sounds reassuring until you consider that small, recurring debits often go unnoticed for months. The administrative burden of clawing that money back falls entirely on the victim.
This is not theoretical. SEPA mandate fraud is already a documented attack pattern across Europe, and gym membership payments are specifically structured as recurring low-value direct debits. The dataset Basic-Fit just lost is, functionally, a pre-filled fraud template.
The System That Got Hit
Basic-Fit says the breach came from its club visit-registration system, the platform that logs when members swipe through turnstiles at each location. This system operates across all the affected countries from a centralized database. That architectural choice, one shared platform handling member access data across six countries, is what turned a single intrusion into a seven-figure breach.
The company says its monitoring tools detected anomalous activity and severed the unauthorized access within minutes. Within minutes is the kind of claim that sounds like a win until you realize that bulk data exfiltration at scale can happen in seconds. The breach confirms the access was terminated, not that the download was stopped before it completed.
Franchise locations used separate systems and were not affected, Basic-Fit noted. That distinction provides cover for about 430 franchise clubs, but does nothing for the estimated one million members whose data came from company-owned locations.
The Disclosure Math Doesn’t Add Up
Basic-Fit’s initial public statement emphasized 200,000 members in the Netherlands. The company fulfilled its legal obligation by notifying the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within GDPR’s 72-hour window. Dutch media quickly reported the full scope: closer to one million across six countries.
That gap, 200,000 in the press release versus one million in the actual data, is worth noting. Basic-Fit is headquartered in Hoofddorp, Netherlands, which makes the Dutch regulator its lead supervisory authority under GDPR. Notifying that authority with partial figures while the broader disclosure trickled out through media reporting is not illegal, but it is a pattern regulators have noticed before.
Basic-Fit reported revenues of approximately €1.1 billion in 2025. Under GDPR Article 83, a fine can reach 4% of annual global turnover, which puts the theoretical ceiling around €44 million. Whether the Autoriteit Persoonsgegevens concludes that Basic-Fit’s security measures were inadequate will depend on the forensic investigation currently underway with external specialists.
Netherlands Is Having a Rough Year
Basic-Fit’s breach landed on the same day that Booking.com disclosed its own incident, affecting reservation data including names, contact details, and booking information. Both companies are Dutch. Neither connection has been publicly established by investigators, and it could be coincidence. But it fits a pattern that has been building for months.
In February 2026, Dutch telecom firm Odido had 6.2 million customer records exposed. Three major incidents across two months at Dutch companies, each involving centralized databases of consumer identity and financial data, suggests that European consumer data is being systematically targeted, and that the companies holding it have not been keeping pace with the threat.
Basic-Fit advised affected members to watch for phishing attempts and monitor their bank accounts. That advice is correct and also insufficient. Phishing emails built on this dataset will use real names, real addresses, real membership details, and potentially real IBAN numbers to appear credible. Standard phishing warnings were designed for spray-and-pray attacks. This is a precision dataset.
What This Means If You Live in the Netherlands
If you are a Basic-Fit member in the Netherlands, here is what just happened to your daily life. Someone you have never met now has your full name, your home address, your date of birth, your phone number, your email, and your bank account number. They can submit charges against your bank account. They can build phishing emails that reference your real gym, your real address, your real membership. They can sell that package to someone else who does the same thing.
The practical steps: check your bank statements for any SEPA direct debit entries you did not authorize, going back 90 days. Call your bank and ask them to flag new SEPA mandates for manual approval before processing. Treat any email that mentions Basic-Fit, your membership, a billing issue, or a password reset as suspicious until further notice. The phishing that follows breaches like this is not the clumsy “Dear Customer” spam most people know how to spot. It will use your real name, your real address, and your real bank details. It will look right.
This is what your €20 a month gym membership just cost you.
What This Means If You Live in America
Basic-Fit does not operate in the United States. But every American who pays for a gym membership, a streaming subscription, a meal kit, or any recurring monthly charge should look at this and ask one question: does the company holding my payment details treat security like a cost center or a priority?
The answer, almost universally, is cost center. American gym chains like Planet Fitness, LA Fitness, and Equinox run the same centralized membership platforms that Basic-Fit runs. Subscription services from meal kits to streaming apps store the same combinations of name, address, date of birth, and payment information. The ACH system in the United States is functionally similar to SEPA in Europe: once someone has your bank routing and account number, initiating a debit is not difficult.
The difference is regulatory. Europe has GDPR, which at least gives regulators the power to fine companies up to 4% of annual revenue for inadequate security. The United States has no federal equivalent. State-level breach notification laws exist, but they mandate disclosure, not prevention. If an American gym chain lost a million members’ bank details tomorrow, the regulatory consequence would be a press release and maybe a class action lawsuit that settles for $2.50 per affected person three years later.
Basic-Fit’s breach is a European story. The vulnerability it exposes is universal.
Basic-Fit has not disclosed how the attacker gained access in the first place. That question matters more than the company’s response time. An intrusion stopped within minutes that still exfiltrated a million records suggests the attacker knew exactly what they were looking for and where to find it. Whether that came from a credential compromise, an API vulnerability, or something else entirely will shape what every subscription business holding consumer payment data needs to do next.
That answer has not been provided yet.