SYS::ONLINE
Wasteland.
Briefs1665
Issues21
SinceFeb 2026
LIVE
▣ Breach RESAMANIA-FITNESS- 2026-08-02

Resamania: 5.2 Million Record Leak Claimed by Actor @84City

"A threat actor using the handle @84City published a database of 5,273,884 unique records on a dark web forum on August 1, 2026, claiming the data was stolen from Resamania, the fitness and sports club management SaaS…"

A threat actor using the handle @84City published a database of 5,273,884 unique records on a dark web forum on August 1, 2026, claiming the data was stolen from Resamania, the fitness and sports club management SaaS platform operated under the Xplor Technologies portfolio. The claim is documented by Brinztech, whose breach alert lists the record count, the geographic spread, and the field structure of the dump. As of publication, no Resamania or Xplor statement, no regulator filing, and no national CERT advisory appears in the source set for this brief, and the eight sources reviewed contain exactly one that documents the incident itself. Readers should treat the leak as claimed and partially corroborated by circumstantial evidence, not as vendor-confirmed.

What Happened

According to Brinztech's alert, the dataset surfaced on a dark web forum on August 1, 2026, attributed to an actor posting under the alias @84City. The stated volume is precise rather than rounded, at 5,273,884 unique records, which is typical of a dump where the seller has deduplicated and counted rows rather than estimated. Precision in a forum post is a marketing signal, not a verification signal, and it should not be read as independent confirmation of scale.

The claimed geographic footprint spans multiple European markets with heavy concentration in France, the United Kingdom, Switzerland, Belgium, Luxembourg, Germany, and Spain. That distribution is consistent with what is publicly observable about the platform. Traffic analytics for resamania.com place its core audience in France, followed by the United Kingdom and Spain, with roughly 331,670 visits in June 2026 across a three month range of about 310,000 to 382,000. Resamania's corporate lineage also fits: Benoît Vincent's professional profile lists him as General Manager of Resamania and Deciplus at Xplor Technologies since October 2025, following thirteen years at Groupe STADLINE, the French club management software business Xplor absorbed. Xplor's UK-facing arm markets the same product line as Xplor Gym from Newcastle upon Tyne, targeting multi-site and franchise operators with billing, access control, CRM, and member management.

None of that corroborates the breach. It corroborates that a platform of the described shape, ownership, and geographic reach exists, and that a European multi-tenant member database of this order of magnitude is plausible.

What Was Taken

The single source describing the dump lists the following field categories:

The RIB exposure is the part that changes the risk calculus. A stolen payment card can be frozen and reissued in hours, and the liability model is well understood by both banks and consumers. A RIB is a durable account identifier tied to the account holder's bank relationship. Paired with a verified full name, postal address, and date of birth from the same row, it supports convincing direct debit fraud and highly targeted social engineering against both the account holder and their bank's support staff. Victims typically discover unauthorised SEPA debits after the fact, and the reversal process is slower and more manual than a card chargeback.

The combination of date of birth, address, and an active gym subscription record also enables precise pretexting. An attacker who can recite a member's club, subscription end date, and billing arrangement clears most consumer trust thresholds on a phone call.

Why It Matters

Fitness management SaaS is a concentration point. A single platform holds member records aggregated across hundreds of independently operated clubs, each of which believes it owns its own customer relationship and most of which have no visibility into their vendor's security posture. When the platform fails, every downstream brand fails simultaneously, and the operators learn about it from a forum post rather than from their own telemetry.

That structural problem is the same one driving the most active SaaS intrusion campaigns of the past year, even though those campaigns are separate incidents with no established link to this one. Microsoft's mapping of ShinyHunters activity, summarised by Rescana, documents three distinct paths into Salesforce environments that exploit no software vulnerability at all: abused OAuth trust, compromised third-party vendor integrations, and misconfigured guest access. The Klue incident of June 12, 2026 followed the same shape, with attackers using stolen OAuth tokens to bulk-query Salesforce CRM data across multiple enterprise tenants, an attack Obsidian Security characterised as a SaaS supply chain access violation rather than a platform flaw. The lesson defenders should carry into the Resamania case is that the trust relationship between a SaaS platform and its tenants is now a primary attack surface, independent of whether that is what happened here.

The Attack Technique

The intrusion vector is unknown. The source documenting the leak describes the dataset and the actor alias, not the method, and offers no timeline for initial access, dwell time, or exfiltration. There is no ransom note, no leak site branding, and no claimed CVE in the material reviewed.

One weak external observation is worth recording with appropriate caveats. A third-party scan of aqualoft.resamania.fr, a single customer subdomain, reports zero of six standard security headers present, with Content-Security-Policy, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy all missing, alongside a slow response time and a clean record across eight blacklist databases. Missing response headers are a hygiene finding on one tenant subdomain. They are not a bulk data exfiltration path, and treating them as the cause would be unfounded. What they do suggest is that per-tenant subdomains in this estate may not be held to a uniform hardening baseline, which is a reasonable thing for operators to ask their vendor about.

Attribution is likewise thin. The alias @84City appears in one report and carries no established history in the sources reviewed. Do not conflate this actor with ShinyHunters, UNC6040, UNC6240, UNC6395, Storm-3138, or Icarus, all of which appear in this source set only in connection with the unrelated Salesforce and Klue campaigns.

Corroboration and Confidence

Accounts do not conflict here, because there is effectively only one account. The 5,273,884 figure comes from a single OTHER-tier report relaying a forum post, with no competing figure from a regulator, the vendor, or established security press to range it against. Confidence in the existence and character of the platform is high. Confidence in the record count, the field list, and the actor identity rests entirely on one unverified chain from seller to reporter. That distinction should survive into any downstream customer notification or risk register entry.

What Organizations Should Do

  1. Gym and club operators using Resamania, Xplor Gym, or Deciplus should contact their account manager in writing today and request confirmation or denial of the claim, the affected date range, and the field list. Log the request and the response time, because both matter for your own GDPR Article 33 clock if the claim is substantiated.
  2. Treat the RIB exposure as the priority workstream. Coordinate with your payment provider on heightened scrutiny of new direct debit mandates referencing your merchant identity, and prepare member-facing guidance on how to spot and dispute unauthorised SEPA debits.
  3. Prepare member notification copy now rather than after confirmation. Members whose names, dates of birth, addresses, and banking identifiers are in a public dump face immediate, well-resourced phishing, and a slow notification is worse than a hedged one.
  4. Inventory and scope every OAuth token, API key, and integration credential connecting your systems to fitness, CRM, and billing SaaS. Both the Klue and ShinyHunters campaigns show that a persistent token grants access indistinguishable from the legitimate integration until it is revoked, so rotate on a schedule and alert on integration logins from infrastructure inconsistent with the vendor's known footprint.
  5. Demand tenant-level logging from your SaaS vendors, specifically bulk read and export events attributable to your data. Without it you cannot determine your own exposure and are dependent on the vendor's disclosure timeline.
  6. Brief front-desk and member services staff. Attackers holding subscription dates and personal details will call your clubs impersonating members and your vendor impersonating support, and staff should have a verification path that does not rely on details present in the leaked fields.

Sources: Massive Database of 5.2 Million Records Leaked from Fitness SaaS Pl... | Resamania — aqualoft.resamania.fr Trust Score & Analysis Bitverzo | resamania.com Website Traffic, Ranking, Analytics June 2026 | WOW! Have you recovered from Elevate yet?! Resamania | Benoît VINCENT | The Trusted Integration That Wasn't: Inside the Klue SaaS Supply Ch... | Active Exploitation Alert: ShinyHunters Abuse OAuth and Vendor Inte... | Klue OAuth Integration Breach Exposes Salesforce Customer Data in I...