[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fdcyadwwe42ce":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":11,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":33,"seoTitle":34,"seoTitleEn":35,"seoDescription":34,"seoDescriptionEn":36,"logoUrl":37,"isVerified":4,"isSensitive":38,"isSpamList":38,"isMalware":38,"company":39},"68e3266eda11adda488250be","8fit","8fit Data Breach","8fit.com","2018-07-01T00:00:00.000Z","2019-03-21T18:50:00.000Z","2026-07-20T04:24:13.668Z","Database leak","https:\u002F\u002F8fit.zendesk.com\u002Fapi\u002Fv2\u002Fhelp_center\u002Fen-us\u002Farticles\u002F360017746394.json",[14,16,17,18],"https:\u002F\u002F8fit.zendesk.com\u002Fhc\u002Fen-us\u002Farticles\u002F360017746394-Notice","https:\u002F\u002F8fit.com\u002F","https:\u002F\u002F8fit.com\u002Ficons\u002Ficon-512x512.png?v=be31b1022d6aea469c76bcb6c04c11f4",15025407,"known",null,"unknown","Critical",[25,26,27,28,29,30,31,32],"Auth tokens","Email addresses","Genders","Geographic locations","IP addresses","Names","Passwords","Profile photos","\u003Cp>The July 2018 8fit breach affected 15,025,407 unique email addresses and bcrypt password hashes.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>\u003Cstrong>Verified data classes include email addresses, names, genders, geographic locations, IP addresses, bcrypt password hashes, expired authentication tokens and profile photos.\u003C\u002Fstrong> The canonical catalogue counts 15,025,407 unique email addresses, while the company notice said approximately 20 million user details may have been affected; these figures measure different scopes and should not be merged into one total. Passwords were stored as bcrypt hashes rather than plaintext. Weak or reused passwords may still be vulnerable to offline guessing and can expose accounts on other services. The company said some Facebook authentication tokens had expired, so their presence does not automatically mean that a live session could be accessed. It also stated that payment information, social security numbers and conversations between users and coaches were not obtained.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>The breach occurred in July 2018, and accounts created after that month were reported as unaffected. 8fit learned of a potential incident on 8 February 2019; the data appeared for sale on a dark-web marketplace that month and was added to the verified catalogue on 21 March 2019. The company said it opened an investigation, worked with security firms and law enforcement, contacted users and strengthened its systems. Evidence confirms a direct leak of 8fit user data, but the exact technical vulnerability that enabled access is not publicly verified. The event is therefore classified as a database leak rather than a third-party supplier breach, without claiming that SQL injection, an employee account, cloud configuration or another entry method was responsible.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Risk is highest for people who reused their 2018 8fit password on email, social media, shopping or workplace accounts. Bcrypt provides a strong protection layer, but short, predictable or common passwords can still be guessed with enough time and computing power. A name, gender, location, IP address and profile image can help an attacker create convincing fitness-membership, subscription, coach-support or password-reset messages. A match does not prove current account takeover, theft of payment information or exposure of health records. Expired tokens do not provide direct access to a current Facebook session, although reviewing connected accounts and application permissions remains useful. Even an inactive 8fit account can matter if the same email and password pattern persists elsewhere. A sound assessment considers password reuse, the last password change, active sessions and personalised suspicious messages together.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>\u003Cstrong>If you reused the password or a close variation from your 2018 8fit account, create a long, unique password on every affected service.\u003C\u002Fstrong> Secure the primary email account, password manager, financial services and other identities capable of resetting accounts first. Review active sessions and recognised devices, verify recovery details, and enable a passkey or multifactor authentication where available. Do not treat a version of the same password with an added number or symbol as independent. Avoid following links in messages that use 8fit, fitness plans, membership renewal, payment problems or coach contact as a pretext; open the known site or application directly. Review application permissions on connected Facebook and other social accounts and remove access you no longer use. If you see an unexpected reset, new-device alert or forwarding-rule notice, begin the service's official recovery process.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>A password manager that generates a separate random password for every service limits cascading account takeover even if an old bcrypt hash is eventually guessed. Move to passkeys where supported and use phishing-resistant authentication on the primary email account. Keep recovery codes offline and review connected applications and social-login permissions regularly. Remember that a profile photo, location and fitness interest can strengthen targeted messages, and verify sensitive requests through an independent channel. Organisations responding to employee-address matches should combine password resets with session revocation, password-reuse prevention and suspicious-sign-in monitoring. Service providers should combine modern password-hashing parameters, unique salts, access segmentation, data minimisation and incident detection. Unused accounts and unnecessary profile fields should be removed on a regular schedule.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>\u003Cstrong>Check your email address through the secure search field to learn whether it appears in the 8fit record and prioritise password changes after a match.\u003C\u002Fstrong> A result does not mean the bcrypt hash was definitely cracked, the account was taken over, or payment and health data were exposed; it reports that the address exists in the verified dataset. Recall password patterns used at that time, replace the same or similar password everywhere it remains active and review recent sessions on the primary email account. Verify unexpected fitness or subscription messages by opening the application directly. No result cannot guarantee that the address was absent from every other incident. Continued monitoring, unique passwords, strong authentication and connected-application reviews provide effective defence if the old data is reused years later.\u003C\u002Fp>","","8fit Data Breach (15 Million Reported Records)","8fit Data Breach. 15 Million reported records were reported. Reported data: Auth tokens, Email addresses, Genders. Review the scope, risks, and protective…","\u002Fuploads\u002Flogo\u002F8fit-official.webp",false,{"name":7,"sector":40,"country":41,"website":9,"websiteArchiveUrl":34,"websiteStatus":34,"websiteCheckedAt":21},"Health and Fitness","Germany"]