Cyber & AI intelligence
Wasteland.
Briefs indexed2927
Issues30
Published Mondays07:30 CT
▣ Breach COLRUYT-JIMS-FITNE 2026-09-29

Colruyt Jims Fitness: 150,000 Member Records Stolen and Offered for Sale

"Colruyt Group has confirmed that an unauthorised third party got into the member management system of Jims, its Belgian fitness chain. The attacker viewed and copied personal data, which has since been offered for sale…"

Colruyt Group has confirmed that an unauthorised third party got into the member management system of Jims, its Belgian fitness chain. The attacker viewed and copied personal data, which has since been offered for sale online. According to VRT NWS, the parent company confirmed that about 150,000 members of 31 of the chain's 85 Belgian clubs are affected. The access happened between 13 and 20 July 2026. Colruyt first described the victims as "a limited group of customers" and only acknowledged the real scale at the end of September, after the dataset had been advertised on a leak forum. The exposed data includes names, addresses, dates of birth, email addresses, membership details and, for some members, bank account numbers (IBANs). No threat actor has been publicly named.

A note on sourcing: none of the eight sources is a primary document. We have no Colruyt press release or regulator filing, only Belgian and Dutch news coverage and a breach-tracking site. The company's position comes from spokesperson Hanne Poppe's quotes to VRT, HLN, Belga and Nieuwsblad, and from the member notification email as those outlets quote it.

What Happened

The timeline, pieced together from the sources:

Outlets differ on how firmly Colruyt itself confirmed the 150,000 figure. VRT NWS, HLN and Tweakers (citing VRT) say Colruyt confirmed it. The Belga wire copy carried by La Libre and Sudinfo quotes Colruyt only on "up to 31 clubs" and attributes the 150,000 figure to the attacker's claim as reported by FrenchBreaches. Nieuwsblad does the same. The most defensible reading is that roughly 150,000 is the attacker's figure, and that Colruyt has accepted it in some statements while framing it as "up to 31 of 85 clubs" in others.

According to Colruyt, only Jims systems were affected. Other Colruyt Group systems, recently acquired clubs (La Libre notes Jims recently took over the NRG chain) and Jims clubs in Luxembourg are all out of scope. Colruyt has not said which Belgian clubs are affected.

Colruyt says the Belgian Data Protection Authority (GBA/APD) was notified "within the applicable timeframes". Aurélie Waeterinckx of the GBA confirmed the notification to Nieuwsblad. Colruyt has also filed a formal police complaint.

What Was Taken

Company account (Colruyt, via spokesperson and member email): - Name - Postal address - Date of birth - Email address - Membership data - IBAN, "in certain cases"

The company says no passwords and no health data were exposed. According to Belga, the affected people include both members and potential customers (prospects) linked to the 31 clubs, so the dataset may go beyond current members.

Attacker's sample (FrenchBreaches, not independently verified): FrenchBreaches describes the 1,000-record sample as also containing phone numbers, customer identifiers and BIC codes alongside IBANs. None of these three fields appears in Colruyt's public list. Phone numbers matter here because Colruyt's own notification warns about phone-based fraud. FrenchBreaches also said the exact number of records with IBANs had not been confirmed.

Volume: About 150,000 people, as claimed by the attacker and reported by VRT NWS, HLN, Tweakers, Nieuwsblad and FrenchBreaches as a confirmed or claimed figure. Belga, in La Libre and Sudinfo, frames it as "up to 150,000". No source gives a different number.

Sensitivity: Moderate to high. There are no credentials or health data, but name, address, date of birth and IBAN together are a complete kit for direct-debit fraud, impersonation and convincing phishing. The data is already for sale on a dark web forum.

Why It Matters

The breach was disclosed late and understated at first. Phishing built on the stolen data was reaching members by late July. Colruyt's first message to customers warned about fake emails without saying where they came from, and its first acknowledgement of a breach described a "limited group". The full scope only came out after the dataset appeared on a leak forum on 22 September, about two months after the intrusion. For defenders, the lesson is familiar: first scoping estimates are often wrong, and the initial disclosure should say so.

The phishing was the early warning. Targeted phishing that uses correct member details is often the first outside sign that customer data has been stolen. Here a member noticed before the scale was understood. Organisations should treat a sudden wave of brand-impersonation phishing aimed at their own customers as a possible breach indicator and investigate it, rather than only issuing a general warning.

IBAN plus identity data enables direct-debit fraud. In the SEPA region, a victim's name, address and IBAN can be enough to set up fraudulent direct debits or to write very convincing "refund" and "payment problem" lures. Colruyt told members to be especially careful with messages about membership, payments, refunds, account changes or direct debits (domiciliëringen).

Leisure and membership businesses are frequent targets. Belga's reporting notes recent incidents at the Belgian table tennis federation and the Fédération francophone de Gymnastique. Sports and fitness operators hold payment data for large numbers of people, but their security investment rarely matches that of retail or banking.

The Attack Technique

The technical details are thin, and this brief will not guess beyond what the sources say.

What is reported: - An unauthorised third party gained access to "parts of the member and customer management system" (HLN) or "the member management system" (Nieuwsblad, quoting the notification). Data was "consulted and copied". - The access window ran from 13 to 20 July, which points to a week of access or repeated downloads rather than a single snapshot. - Colruyt says the "accounts concerned" were reset and given extra security. The sources do not say whether these were staff or administrator accounts on the management platform or member-facing accounts. Tweakers notes it is unclear what the extra security involves. If staff accounts were reset, that would fit credential-based access to a SaaS or web-based membership platform, but no source confirms this. - After the theft came two stages of monetisation. First, phishing campaigns from lookalike emails and domains in late July, which Colruyt says it had blocked. Second, sale of the dataset on a leak forum by September.

Not reported: the initial access vector, whether the membership platform is in-house or third-party, any ransomware or extortion demand, or who the actor is. Nobody has publicly named a group, and FrenchBreaches calls the claim "credible" without naming the author.

What Organizations Should Do

  1. Investigate customer-targeted phishing as a possible breach. If members report phishing that uses accurate personal or membership details, start a data-exposure investigation immediately. A generic "beware of fake emails" notice is not enough. Correlate the targeted recipients with your customer databases to find the source.
  2. Lock down access to membership and CRM platforms. Require phishing-resistant MFA on every staff and administrator account for membership, billing and CRM systems, including SaaS tools. Restrict bulk export and API access, and alert on unusual query or download volumes, especially across many clubs or sites.
  3. Minimise and segment payment data. Store IBANs and BICs tokenised or in a separate billing system instead of alongside general member records. Remove prospect and former-member data you have no legal reason to keep. Here, "potential customers" were apparently exposed too.
  4. Take a conservative approach to scope in disclosures. Say publicly that initial counts are provisional, and update notifications as forensics progress. Watch leak forums and breach trackers so an attacker's claim does not come out before your own figure.
  5. Take down impersonation infrastructure early. Monitor for lookalike domains and spoofed sender addresses, enforce DMARC at p=reject on your own domains, and prepare templated customer guidance for direct-debit and refund scams.
  6. Tell affected customers what to do. Advise them to check bank statements for unknown direct debits, dispute any they did not authorise (SEPA allows refunds of direct debits), and treat any unsolicited contact about payments or account changes as suspect, whether it arrives by email, SMS or phone.

Sources: Data breach at Colruyt’s Jims fitness chain much larger than though... | Datalek bij Colruyts fitnessketen Jims: gegevens van 150.000 leden... | La chaîne de salles de sport Jims victime d’une cyberattaque : les... | Datalek bij Colruyts fitnessketen Jims veel groter dan gedacht: geg... | Hackers bieden gegevens van 150.000 leden fitnessketen Jims aan op... | JIMS piraté : les données de 150 000 adhérents de salles de sport... | La chaîne de salles de sport Jims victime d'une cyberattaque - La... | “Naam, adres, e-mailadres... werden online aangeboden”: gegevens va...