Personal data of 1 million gym members compromised in Basic-Fit security incident

2026-04-15T02:51:42Zd44ed2bb00ebecab7dff61e752aa8514f71b7ea599a968ddc5ca404b2f0ee380
Booking.comCISA-KEVCVE-2025-0520Citizen-LabDLL-sideloadingHandalaOperation AtlanticPlugXRCEShinyHuntersShowDocSignalUAE-breach-claimsWebloccrypto-theftdata-breachdata-leakfake-installeriPhone-forensicslaw-enforcementmalwarenation-state-linkedprivacy-forensicsvulnerability-exploit

What happened

This SecurityAffairs feed reports multiple significant incidents: a data breach at Basic-Fit exposing ~1M members' personal and banking data; an international law-enforcement operation (“Operation Atlantic”) disrupting ~$45M in cryptocurrency theft and freezing ~$12M for victims; an 8.1GB data leak attributed to ShinyHunters affecting Rockstar Games (anti-cheat code, analytics, support tickets); active exploitation of a critical ShowDoc RCE (CVE-2025-0520, CVSS 9.4); CISA additions to its Known Exploited Vulnerabilities catalog (including Adobe, Fortinet, Microsoft Exchange/Windows, Apple, and

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
d44ed2bb00ebecab7dff61e752aa8514f71b7ea599a968ddc5ca404b2f0ee380
Enrichment time
2026-04-15T02:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.