BODY20 Allegedly Breached as 205K Member Records Offered for Sale

A threat actor claims to be selling 205,773 alleged BODY20 member records containing personal information, signed documents, and membership forms.
Screenshot of a forum post claiming an alleged breach of BODY20 Global. The post advertises the sale of 205,773 purported member records, claiming the dataset includes names, addresses, phone numbers, email addresses, dates of birth, IP addresses, signatures, liability waivers, membership agreements, cancellation forms, and records involving minors.
Screenshot of a threat actor’s post alleging the sale of more than 205,000 BODY20 member records, including personal information, membership documents, liability waivers, and other sensitive files.

Fitness franchise BODY20 has allegedly suffered a data breach after a threat actor claimed to be selling a database containing 205,773 member records. The unverified listing, published on August 15, 2026, advertises customer information, signed membership documents, and liability waiver forms for $8,000.

The claims have not been independently verified by BreachNews, and BODY20 had not issued any public statement at time of publication.

Threat actor claims 205,773 records

According to the listing, the alleged breach dates to July 2026 and affects BODY20 Global USA, which operates more than 100 Electro-Muscle Stimulation (EMS) fitness studios across the United States.

The threat actor claims the dataset contains 205,773 member records, including:

  • Full names
  • Home and mobile phone numbers
  • Email addresses
  • Physical addresses
  • Dates of birth
  • IP addresses
  • Customer signatures
  • Liability waiver and release forms
  • Membership agreement forms
  • Cancellation forms

The listing also alleges that records relating to minors are included within the dataset.

Company response claims remain unverified

The threat actor further alleges that BODY20 is aware of the incident, that members have not been properly notified, and that the company failed to adequately secure the affected information. Those claims have not been independently verified, and no evidence was provided confirming the company’s knowledge of the alleged incident.

The listing includes sample files and states the database is being offered for sale for $8,000 through a private transaction. BreachNews has not reviewed the full dataset and cannot confirm the authenticity or origin of the information.

Latest fitness sector claim

If authentic, the alleged dataset could expose sensitive personal information that may be used in phishing campaigns, identity theft, or fraud. Signed waiver forms and membership agreements could also provide additional personal details beyond standard customer contact information.

The same threat actor has recently published similar alleged breach listings targeting organizations in the fitness sector, including Nebbia and George Brown Sports Clubs.

BreachNews will update this article if BODY20 confirms or disputes the alleged breach.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site