FitnessKPI denies data breach but confirms some logs still spilled
Attendance habits of some gym-goers were exposed.

Gym management platform FitnessKPI denies data breach. By Shutterstock.
- FitnessKPI denies its platform was breached and says someone used valid customer administrator credentials.
- Files shared online appear to link 1,848 Genae Écully members to the exposed data.
- The data includes contact details, membership records, bookings, contracts, and payment-related information.
- Researchers warn criminals could use the records to create convincing phishing messages and fake payment reminders.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Gym management platform FitnessKPI has denied that its data was recently compromised. An analysis of files allegedly stolen and shared on a dark web forum suggests that one particular gym in France, belonging to Genae, a gym operator and a client of FitnessKPI, was targeted.
Late last week, a hacker calling themselves Syrv4x claimed on a dark web forum to have successfully retrieved data of 1,848 members from the databases of FitnessKPI. Meanwhile, the alleged victim disagrees.
FitnessKPI is an Spanish AI-powered business intelligence and fitness club management platform, designed to help gym operators, chains, and franchises manage operational and membership data.
According to the dark web post, the exposed information includes:
- Member names
- Email addresses
- Phone numbers
- Gender
- Ages
- Dates of birth
- Postal codes
- Membership details
- Contracts
- Payment information
- Unpaid balances
- Bookings, and other account and operational data
No major intrusion, firm says
FitnessKPI said it has conducted a technical investigation of access logs and denied that its database, servers, and infrastructure were compromised. Nor was any vulnerability in the platform or its API exploited, the company said.
“The incident involved access to the application using valid credentials belonging to a
customer administrator account,” FitnessKPI explained in a statement sent to Cybernews.
“A third party in possession of the username and password logged into FitnessKPI through the standard login process and accessed information that the account was authorized to view.”
Has your password leaked?
No data belonging to other customers or information outside the scope authorized for that particular account was accessed, FitnessKPI added. In other words, the incident was limited to the affected location.
That location apparently is the Genae Écully gym, located near the French city of Lyon. Cybernews has analyzed the files shared on the dark web and said that all the profiles in the batch were linked to that particular gym.
Phishing campaigns are possible
Genae, which operates a few other gyms in the Lyon area, is indeed a FitnessKPI client and uses the platform to analyze customer activity, for instance, to identify gym members likely to cancel their subscriptions.
Nearly 160,000 entries in the files are related to payments. Once again, all such data – including amounts, invoice and payment dates, payment statuses, and information related to unpaid debts – are linked to Genae Écully. However, no banking information was exposed.
FitnessKPI does not collect or store credit card numbers, CVV codes, IBANs, or health information relating to club members. This type of information is therefore not part of the data managed by the platform,FitnessKPI explained in its statement.
Of course, the data could be considered quite sensitive because it exposes a particular gym-attendance habit – payment data – and a behavioral profile, the Cybernews research team said.
"This data could be used to build credible phishing campaigns. Someone could, for instance, impersonate Genae Écully by knowing the membership plan an individual actually subscribed to and their payment history,” our researchers explained.
It’d also be possible for threat actors to misuse data relating to unpaid invoices. They could send fake reminders using real payment information to induce a victim to pay up.