[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3ckchgrhut3b0":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":31,"seoTitle":32,"seoTitleEn":33,"seoDescription":32,"seoDescriptionEn":34,"logoUrl":35,"isVerified":4,"isSensitive":4,"isSpamList":36,"isMalware":36,"company":37},"68e3266eda11adda4882520e","Glofox","Glofox Data Breach","glofox","glofox.com","2020-03-27T00:00:00.000Z","2021-01-10T01:30:48.000Z","2026-07-27T16:11:13.163Z","Verified breach record","https:\u002F\u002Foag.ca.gov\u002Fsystem\u002Ffiles\u002FFinal%20Version%20-%20Customer%20Comms.pdf",[15,17,18],"https:\u002F\u002Fwww.irishtimes.com\u002Fbusiness\u002Ftechnology\u002Firish-start-up-glofox-investigates-possible-data-breach-1.4414837","https:\u002F\u002Fwww.twingate.com\u002Fblog\u002Ftips\u002Fglofox-data-breach",2330735,"known",null,"unknown","Critical",[25,26,27,28,29,30],"Dates of birth","Email addresses","Genders","Names","Passwords","Phone numbers","\u003Cp>The Glofox data breach is a verified incident affecting archived data from March 27, 2020, on the Ireland-based Glofox platform, which provides membership, booking, and customer management software for gyms and fitness studios. On LeakData, this incident is tracked with 2,330,735 unique accounts. Verified data fields include dates of birth, email addresses, gender information, names, passwords, and phone numbers. Passwords are not verified in plain text; the affected password field is associated with unsalted MD5 hashes. This distinction is important, but the risk of account takeover is still high for weak or reused passwords.\u003C\u002Fp>\n\u003Cp>The Glofox incident is considered sensitive due to its context of fitness and membership management. Gym memberships, combined with phone numbers, birth dates, and gender information, can make phishing messages more personal. The type of services a user is interested in, the email and phone they registered with, and the password pattern they may have chosen provide valuable signals for an attacker. Since it has not been confirmed that credit card or payment method data was affected, the risk assessment should focus not on the assumption of a financial card leak but on account security, password reuse, targeted messages, and the potential misuse of personal profile data.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The verified data categories are birth dates, email addresses, genders, names, passwords, and phone numbers. Email address and name information can be used for fake login alerts, membership renewal messages, reservation notifications, or password reset traps. Phone numbers open an additional channel for SMS fraud and fake support calls. Birth date and gender information help the attacker make the message appear more personal. This combination poses a higher social engineering risk than an email leak alone.\u003C\u002Fp>\n\u003Cp>The password field requires special attention. Unsalted MD5 hashes are considered weak according to modern security standards; weak passwords can be guessed quickly or compared with previous leaks. If the user has reused the same password on email, gym accounts, social media, or other online services, the risk extends beyond the Glofox account. Even if the plaintext password is not verified, password change and the removal of password reuse should be taken as urgent measures due to the weakness of the hash type.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified incident date is based on archive data from March 27, 2020, and the list date is tracked as January 10, 2021. Therefore, it is not correct to interpret the Glofox result in a user search as a new violation dated 2025. Later dates may be related to the data appearing again in different lists, being verified, or added to systems; the actual date of the incident is the March 2020 period.\u003C\u002Fp>\n\u003Cp>It is not confirmed that financial information, credit card, and payment method data have been exposed. Notifications emphasize that there is no plaintext password; therefore, the disclosure does not present the password as a plaintext leak. At the same time, the fact that password hashes are protected with a weak method does not change the reality that users need to take action. The report should avoid exaggerated claims and clearly explain the combined risk of phone number, birth date, and password hashes.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The group at the highest risk are users who have a gym or fitness studio membership through Glofox and reuse the same password on other accounts. For these individuals, an attacker can initiate login attempts on other services using their email address and password hash. The second group consists of members who have shared their phone number and date of birth. This information can be used in messages that appear personal, such as fake membership renewals, fake class bookings, fake payment alerts, or account security notifications.\u003C\u002Fp>\n\u003Cp>The third risk group consists of people who use the same email address for work, gym, health, social media, and financial accounts. Gym membership should not be directly classified as health data; however, when combined with personal routine, lifestyle, and contact information in the gym context, it increases privacy risk. Therefore, users seeing a Glofox match should review not only their gym account but all critical accounts linked with the same credentials.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>The first step is to change the password used for the Glofox or affiliated gym account to a unique and strong password. If the same or a similar password has been used in other accounts, new and different passwords should be chosen for all of those accounts. The email account should also be protected, as password reset links are often managed through email. Multi-factor authentication should be enabled on critical accounts, and if possible, a one-time code application or security key should be preferred.\u003C\u002Fp>\n\u003Cp>Glofox should not be clicked directly on links in emails and SMS messages themed around gyms or reservations. The user should manually enter the address to verify it when receiving notices about membership renewal, class booking, payment issues, or account security alerts. Passwords, verification codes, or payment information should not be shared during phone calls. Since date of birth and phone number could have been leaked, these pieces of information alone should not be considered proof of identity in authentication questions.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>In the long term, users should use separate passwords for the gym, e-commerce, and social media accounts, generate strong passwords with a password manager, and reduce unnecessary personal data on old accounts. Permanent information such as phone numbers and birth dates are difficult to change; therefore, they can appear again in fraud messages even years after a leak. If the user no longer uses their old fitness account, they should reduce account settings, communication preferences, and unnecessary profile information.\u003C\u002Fp>\n\u003Cp>The Glofox breach demonstrates that in membership management systems, password security and personal profile data need to be protected together. Weak protection of hashed passwords, when combined with phone numbers and birth dates, creates long-term risks. Regular password hygiene, email security, vigilance against SMS-based fraud, and protection of account recovery channels reduce the likelihood of such old data breaches being reused.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>Users matching with Glofox on LeakData should consider the result as the gym membership and account data incident dated March 27, 2020. A match does not necessarily mean that credit card or payment method data was definitely leaked; however, due to email, phone number, date of birth, gender, name, and password hashes, there is a risk to account security and targeted messaging. User action should focus on changing passwords, strengthening the email account, and verifying fake notifications received via phone.\u003C\u002Fp>\n\u003Cp>The most appropriate approach for this incident is to take over accounts and reduce social engineering risk without causing financial card panic. The user should change their Glofox password, clean up all accounts using the same password, enable multi-factor authentication, and check gym or reservation-themed messages through official login channels. These steps significantly reduce the likelihood that an old archived data breach will be used in new fraud attempts.\u003C\u002Fp>","","Glofox Data Breach (2.3 Million Reported Records)","Glofox Data Breach. 2.3 Million reported records were reported. Reported data: Dates of birth, Email addresses, Genders. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fglofox_com.webp",false,{"name":7,"sector":38,"country":39,"website":10,"websiteArchiveUrl":32,"websiteStatus":32,"websiteCheckedAt":21},"Fitness management software","Ireland"]