Basic-Fit disclosed a breach affecting about 200,000 customers in the Netherlands after unauthorized access allowed attackers to download personal data before the intrusion was stopped. The exposed information included membership details, names, addresses, email addresses, phone numbers, dates of birth, and bank account details. The company said it notified affected customers and reported the incident to the Dutch Data Protection Authority, while media reports indicated the wider impact may extend beyond the Dutch customer base and raised questions about controls that failed to prevent large-scale data exfiltration.
Booking.com also warned customers that unauthorized third parties may have accessed reservation-related information after suspicious activity was detected on a number of bookings. The potentially exposed data included customer names, email addresses, phone numbers, and other booking details submitted during the reservation process. Booking.com said the full scope of the incident remains under investigation, reset PIN codes tied to affected reservations, and urged customers to watch for suspicious activity and phishing attempts leveraging the stolen information.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Booking.com alerted an undisclosed number of customers that unauthorized third parties may have accessed reservation-related information, including names, email addresses, and phone numbers. The company said it detected suspicious activity tied to a number of reservations, reset affected reservation PINs, and advised customers to monitor for unusual activity.
Basic-Fit publicly disclosed that a data breach affected 200,000 customers in the Netherlands. The company said it had notified affected customers and reported the incident to the Dutch Data Protection Authority.
Basic-Fit said attackers gained unauthorized access to its systems and downloaded customer data before the intrusion was contained within minutes. The stolen information included membership details, names, addresses, email addresses, phone numbers, dates of birth, and bank account details.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cyberwarzone.com
Open sourcecyberwarzone.com
Open sourcecyberwarzone.com
Open sourcenos.nl
Open sourcetheregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.