Massive Data Breach at Basic-Fit and Booking.com Exposes Millions of Customer Records

Massive Data Breach at Basic-Fit and Booking.com Exposes Millions of Customer Records

First seen 13 Apr 2026, 21:03 UTC www.vrt.bewww.nrc.nl 73% similarity 66.0

Article Content

Browse articles
ThreatCluster

A significant data breach has occurred at Basic-Fit, affecting approximately 1 million customers across six countries, including the Netherlands, Belgium, France, Spain, Luxembourg, and Germany. The compromised data includes sensitive information such as names, addresses, email addresses, phone numbers, birth dates, and bank account details. Basic-Fit reported that the breach was detected and contained shortly after it began, but data from about 200,000 Dutch customers and 150,000 to 200,000 Belgian customers were already downloaded. The incident was reported to the Dutch Data Protection Authority within the legally required 72 hours. Concurrently, Booking.com has also experienced a security incident, where unauthorized access to customer booking information has been detected, although the extent of the impact remains unclear. Both companies are currently investigating the breaches and have taken steps to secure their systems. No identities or passwords were reported stolen in the Basic-Fit breach.

Key Points: • Basic-Fit data breach affects 1 million customers across six countries. • Sensitive customer information, including bank details, has been compromised. • Booking.com also reports unauthorized access to customer booking data.

ThreatCluster AI

Timeline

2026-04-10
Data breach at Basic-Fit occurs.
2026-04-11
Basic-Fit detects and contains the breach.
2026-04-13
Basic-Fit publicly announces the data breach.
2026-04-13
Booking.com reports unauthorized access to customer data.

Community

Browse all →

Tracked Entities in This Story