Security Guides
The gym's 'payment failed' message is the bait: what Basic-Fit members should do after the data breach (IBAN and visit data)
Basic-Fit disclosed on April 13, 2026 unauthorized access to the system that records member visits, exposing contact details, dates of birth and bank account details. What members should do: direct debits, fake 'payment failed' messages and where to get help.
For: current and former Basic-Fit members in the Netherlands, Belgium, Luxembourg, France, Spain and Germany who received the incident notice, and anyone who gets a "we couldn't collect your membership fee" message. This article is based on Basic-Fit's official press release, its privacy statement and guidance from EU and national authorities. It does not cover how the access happened.
What members should do today
Read the notice, and ask for your data if you want to know exactly what's held
Basic-Fit says it has already informed the members whose data was involved. To find out exactly what it holds on you, make a right of access request: Basic-Fit's privacy statement gives the address requestprivacy@basic-fit.com and says requests are handled within 4 weeks. Write to that address yourself; don't reply to a message that arrives "from Basic-Fit".
If you get a 'payment failed' message, don't tap: open the app yourself
According to its privacy statement, when a fee goes unpaid Basic-Fit sends payment reminders by email first, then by text message. So a "payment failed" message is sometimes real, which makes it the perfect disguise. Basic-Fit's warning page says fake messages often urge you to make a payment, use links that don't lead to www.basic-fit.com, and that Basic-Fit never asks for bank or personal details by email or unsolicited message. Check your fee status by opening the app or My Basic-Fit yourself (see what is phishing?).
Check your statements for creditors you don't recognise
Every direct debit on your statement shows the name of the creditor collecting it. Look for ones you don't recognise. The EU's Your Europe portal says you have the right to get a direct debit taken by mistake refunded within 8 weeks. In Spain, the Banco de España explains that if you never authorised the debit, the deadline is 13 months. Ask your bank how to request a refund in your country.
Don't reverse the legitimate gym fee 'just in case'
The IBAN risk is debits from other creditors, not Basic-Fit's own. Basic-Fit's privacy statement says unpaid fees lead to reminders and, if they are not resolved, the case is passed to a collection agency. If you want to leave, cancel through Basic-Fit's official channels.
Be wary of anyone who uses your club or schedule to sound legitimate
According to the Dutch public broadcaster NOS, the membership information included payment status and which clubs the member had visited in the previous week. Someone knowing your club doesn't prove they're from Basic-Fit. Never verify a message using the message itself.
Report fraud, and don't reuse passwords
If you find fraudulent use, tell your bank and report it to the police in your country. In Spain, INCIBE's free and confidential 017 helpline answers from 8 a.m. to 11 p.m. every day. Basic-Fit says passwords were not accessed, but if you reused your Basic-Fit password elsewhere, a password manager makes changing it easy.
Email + phone + membership type
→ "We couldn't collect your fee, update your payment here"
Check: your fee in the app or My Basic-Fit, never via the link
IBAN + name + address
→ Direct debits from creditors you don't know
Check: debits on your statement; ask your bank for a refund
Club and recent visits
→ A message or call that "knows" where you train
Check: knowing your club proves nothing; contact them via the app
Passwords and ID documents: not affected (per Basic-Fit)
What happened (per Basic-Fit)
The following comes from Basic-Fit's April 13, 2026 press release and what the company and its spokesperson told Reuters and The Register.
Before April 13, 2026
Basic-Fit's system monitoring detects unauthorized access to the system that records members' visits to its clubs. The company says it was stopped within minutes of discovery. The press release doesn't give the date.Investigation
External security experts find that some of the data stored in the system was downloaded, concerning active members in several countries.April 13, 2026
Basic-Fit publishes its press release, says it has notified the relevant data protection authority and that the members involved have been informed. It tells Reuters the total is around 1 million members.Since
Basic-Fit says the investigation so far has not shown the data being available anywhere or misused, and that it continues to monitor the issue with external specialists.
- System
- The system that records members' visits to Basic-Fit clubs
- Downloaded
- Membership information, name and address details, email addresses, phone numbers, dates of birth and bank account details
- Not affected
- Passwords (not accessed). Basic-Fit says it does not hold members' identification documents
- Membership details
- Per NOS: membership number and type, payment status, and the clubs visited in the previous week
- Scope
- Active members; around 200,000 in the Netherlands. Per Reuters, franchise clubs in other countries use a separate system that was not affected
- Authorities
- The relevant data protection authority was notified. Basic-Fit's privacy statement names the Dutch Autoriteit Persoonsgegevens as lead authority and lists each country's authority
- Misuse
- None found as of the press release, according to the company
How to read it: 'no action needed' doesn't mean 'no risk'
Basic-Fit said the main risk for affected members would be phishing attempts. And unlike a password, an IBAN can't be changed with a click: it stays your account for years. Basic-Fit's privacy statement says member data is deleted 2 years after a membership ends; data that has already been downloaded doesn't follow that schedule. So watching your debits isn't a few weeks' job, it's a habit.
Why a gym is a special case: a monthly debit and a weekly routine
Most breaches involving bank details are about one-off purchases. A gym differs in two ways:
What makes the scam believable
- The fee is collected every month by direct debit, so "a problem with your payment" always seems plausible
- Basic-Fit does send payment reminders by email and text when a fee goes unpaid
- The message can quote your membership type, your club or your recent visits
- Pressure: "your access will be blocked today", "your case is going to collections"
How to check without falling for it
- Open the app or My Basic-Fit yourself and look at your fee status
- A link that doesn't go to www.basic-fit.com isn't Basic-Fit
- Basic-Fit says it never asks for bank or personal details by email or unsolicited message
- It already has your bank details: there's no reason to "re-enter" them via a link
This site's view: separate 'the debit you know' from 'the debits you don't'
After the Endesa breach in Spain we recommended checking the direct debits on your statement. Here there's a new twist: your statement already contains a legitimate debit from the same source, the gym fee. That invites two opposite mistakes: paying a scammer posing as Basic-Fit, or reversing the real fee out of fear and ending up in arrears. Our rule is simple: handle the Basic-Fit debit inside the app; send debits from creditors you don't know back through your bank. If your bank app can alert you to every debit, switch it on: you'll see an odd one the same day.
For companies holding IBANs alongside activity data, the lesson is to limit which system holds both: a visit log doesn't need an account number to open a turnstile. See the minimum security baseline for organizations and, for the legal frame, what is the GDPR?
The same "your details are correct, so the message must be real" trap showed up in the Booking.com reservation data breach. If your bank alerts and login codes arrive on your phone, also review smartphone security basics.
Sources (public record)
The facts in this article are based on the public information below. No attacker claims or figures not published by Basic-Fit are used.
- Basic-Fit, "Basic-Fit informs members on an unauthorised data access" (press release, April 13, 2026) — corporate.basic-fit.com (PDF)
- Basic-Fit, privacy statement (visit registration, payment problems, retention, authorities; Spanish version) — basic-fit.com
- Basic-Fit, "Careful with Fake Promotions" — basic-fit.com
- Reuters (via Yahoo Finance), "Basic-Fit data breach exposes details of a million gym members" (April 13, 2026; total figure, franchise system, phishing risk) — finance.yahoo.com
- The Register (April 13, 2026; countries named by Basic-Fit's spokesperson) — theregister.com
- NOS (April 13, 2026, in Dutch; detail of membership information) — nos.nl
- European Union, Your Europe, "Payments, transfers and cheques" (direct debit refunds) — europa.eu
- Banco de España (Portal del Cliente Bancario), "Adeudos domiciliados" (in Spanish) — clientebancario.bde.es
- INCIBE, Tu Ayuda en Ciberseguridad (017, in Spanish) — incibe.es
Update history
2026-09-30: First version, based on Basic-Fit's April 13, 2026 press release, its privacy statement and warning page (checked September 30, 2026), statements reported by Reuters and The Register, and EU and Spanish authorities' guidance.
Read next
- Another European breach with IBANs: Endesa (Spain: ID numbers and IBANs) / Odido (Netherlands)
- Correct details, fake message: The Booking.com reservation data breach
- Scams that follow a breach: What is phishing? / Choosing a password manager
- Other 2026 incidents: List of breaches and cyberattacks (Japan and worldwide)
- For operators: The minimum security baseline for organizations
FAQ
QWhat was exposed in the Basic-Fit breach?
According to Basic-Fit's April 13, 2026 press release, data was downloaded from the system that records members' visits to its clubs: membership information, name and address details, email addresses, phone numbers, dates of birth and bank account details. Basic-Fit says it does not hold members' identification documents and that no passwords were accessed.
QHow many members were affected, and in which countries?
The press release refers to active members in several countries and puts the number in the Netherlands at around 200,000. Basic-Fit told Reuters the total was around 1 million members, and a spokesperson named six countries to The Register: the Netherlands, Belgium, Luxembourg, France, Spain and Germany. According to Reuters, the franchise clubs in other countries use a separate system that was not affected.
QCan someone set up direct debits with my IBAN?
An IBAN doesn't let anyone into your online banking, but it can show up on direct debits you never authorised. The EU's Your Europe portal says you have the right to a refund within 8 weeks for a direct debit taken by mistake. In Spain, the Banco de España explains that if you never authorised the debit, the deadline is 13 months. Check your statements for creditors you don't recognise and ask your bank about the procedure in your country.
QI got a message saying my membership payment failed. Is it real?
It might be: Basic-Fit's privacy statement says that when a member doesn't pay, it first sends payment reminders by email and then by text message. That is exactly why a fake 'payment failed' message is so convincing. Basic-Fit's own warning page says fake messages often urge you to make a payment, use links that don't lead to www.basic-fit.com, and that Basic-Fit never asks for bank or personal details by email or unsolicited message. Don't tap the link; open the app or My Basic-Fit yourself and check there.
QShould I reverse my Basic-Fit direct debits as a precaution?
Don't reverse the legitimate gym fee as a precaution. The risk is debits from creditors you don't recognise. Basic-Fit's privacy statement says unpaid fees lead to reminders and, if not resolved, the case is passed to a collection agency. If you want to leave, cancel through Basic-Fit's official channels.
QWhere can I complain or ask about my data?
You can ask Basic-Fit what data it holds on you (a right of access request) at requestprivacy@basic-fit.com; its privacy statement says it handles requests within 4 weeks. The same statement says its lead supervisory authority is the Dutch Autoriteit Persoonsgegevens, and lists the national authorities in each country (for example the CNIL in France and the AEPD in Spain).