#basicfit

2 posts · Last used 29d

Back to Timeline
Erik van Straten @ErikvanStraten@todon.nl · Apr 13, 2026
Replying to @ErikvanStraten@todon.nl
CLOUDFLARE IS EVIL Basic Fit klanten: "welkom" bij de club der gelekten! (https://nos.nl/artikel/2610253-basic-fit-getroffen-door-hack-gegevens-van-200-000-nederlandse-leden-gelekt) Voor de ICS phishingsite, die al ca. 1 maand live is achter Cloudflare (en die ik hierboven al twee maal noemde), ontving ik gisteren een phishingmail. De (niet direct zichtbare) link daarin stuurt mijn browser naar een "doorstuursite": https:⧸⧸luxeinteriors.pk Dat is een vermoedelijk gehackte website. Die site stuurde ook zojuist nog mijn browser als eerste door naar de ICS phishingsite: https:⧸⧸lcs.1419.info (en die site zelf vult de URL vervolgens aan met "/index.php" en daarna met "/id/"). Nieuw is de verticale "Feedback" knop aan de rechterkant. Ook nog niet gebanned door Cloudflare is: https::⧸⧸digitaalformulier.4417.info Eerder beschreef ik de "Mijn Overheid Berichtenbox" nepsite die daar te vinden was. De getoonde foutmelding is hartstikke nep. Ik vermoed dat hier, na een witwasperiode, weer een phishingsite op verschijnt. Geen dank, Cloudflare! #CloudflareIsEvil #CloudflareIsCrimineel #BigTechIsEvil #Odido #OdidoDataLek #BasicFit #BasicFitDataLek
4
0
3
Fabio Manganiello @fabio@manganiello.eu · Apr 15, 2026
The problem here isn’t much that #BasicFit has been hacked. Today’s tech stacks are so complex and distributed over multiple systems that all IT products are always one S3 dump away or one token leak away from being hacked. The problem is that a gym perhaps is not supposed to store all this information about their customers: Full nameDate of birthEmailAddressPhone numberBank account details If gyms could still operate fine 20 years ago without gathering all these details, then I don’t see why they need them now. My full name and a customer ID should be more than enough to know who I am, for the purposes that the gym needs. And if payments are externalized to external payment processors, then there should also be no need to store bank details or credit card numbers. The best way to mitigate the impact of data hacks is to not store the data you don’t need in the first place - even if you think that you can make an extra buck from it by selling it to data brokers. At the very least, pick on the habit of using one-off email aliases, fake phone numbers and fake dates of birth when you know that that information is very unlikely to ever be needed. https://www.bleepingcomputer.com/news/security/european-gym-giant-basic-fit-data-breach-affects-1-million-members/
4
3
8

You've seen all posts