Synergym and VivaGym: Hackers leak 770,000 Synergym records, overwhelming the chain's historical member census

Synergym and VivaGym: Hackers leak 770,000 Synergym records, overwhelming the chain's historical member census

Synergym Customer Data Resurfaces in Alleged Breach, Company Denies Recent Attack

Over 770,000 Synergym customer records including names, ID numbers, addresses, dates of birth, phone numbers, emails, and banking details (IBAN/BIC) have been advertised on a cybercrime forum, raising concerns about potential identity theft and financial fraud. The leaked data, however, appears to stem from an earlier incident in 2024, which Synergym claims was detected, mitigated, and reported to Spain’s Data Protection Agency and affected users at the time.

Synergym, now part of VivaGym following an April 2024 acquisition, denies any recent breach, insisting the exposed data is not new. The company’s statement contrasts with the scale of the current leak, which far exceeds the 300,000 members it reported at the time of the acquisition. While Synergym maintains that the incident was resolved in compliance with regulations, the resurfacing of old data underscores persistent risks, including the reuse of sensitive information by malicious actors.

The case follows a similar breach at Basic-Fit in April, where 400,000 members’ personal and financial data was exposed. Both incidents highlight vulnerabilities in the fitness sector, particularly around the handling of customer records and the long-term risks of data exposure, even when initial breaches are addressed. Synergym, founded in 2013 in Málaga, operates over 160 clubs across Spain.

Source: https://www.apdnoticies.com/en/data-protection/hackers-leak-770-000-synergym-records-overwhelming-the-chain-s-historical-member-census_17750_102.html

Synergym España cybersecurity rating report: https://www.rankiteo.com/company/synergym-holding

VivaGym cybersecurity rating report: https://www.rankiteo.com/company/vivagym

"id": "SYNVIV1782614316",
"linkid": "synergym-holding, vivagym",
"type": "Breach",
"date": "1/2024",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '770,000',
                        'industry': 'Fitness',
                        'location': 'Spain',
                        'name': 'Synergym',
                        'type': 'Company'}],
 'customer_advisories': 'Yes',
 'data_breach': {'data_exfiltration': 'Yes',
                 'number_of_records_exposed': '770,000',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Names',
                                              'ID numbers',
                                              'Addresses',
                                              'Dates of birth',
                                              'Phone numbers',
                                              'Emails',
                                              'Banking details (IBAN/BIC)']},
 'date_detected': '2024',
 'date_resolved': '2024',
 'description': 'Over 770,000 Synergym customer records including names, ID '
                'numbers, addresses, dates of birth, phone numbers, emails, '
                'and banking details (IBAN/BIC) have been advertised on a '
                'cybercrime forum. Synergym denies any recent breach, stating '
                'the data stems from an earlier incident in 2024 that was '
                'mitigated and reported.',
 'impact': {'brand_reputation_impact': 'Yes',
            'data_compromised': '770,000 customer records',
            'identity_theft_risk': 'Yes',
            'payment_information_risk': 'Yes'},
 'initial_access_broker': {'data_sold_on_dark_web': 'Yes'},
 'lessons_learned': 'Persistent risks of data exposure even after initial '
                    'breaches are addressed; vulnerabilities in the fitness '
                    'sector around handling customer records.',
 'references': [{'source': 'Cybercrime forum advertisement'}],
 'regulatory_compliance': {'regulatory_notifications': 'Reported to Spain’s '
                                                       'Data Protection '
                                                       'Agency'},
 'response': {'communication_strategy': 'Statement to affected users and '
                                        'public',
              'incident_response_plan_activated': 'Yes',
              'remediation_measures': 'Mitigated and reported to Spain’s Data '
                                      'Protection Agency'},
 'title': 'Synergym Customer Data Resurfaces in Alleged Breach',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.