FitandLean Allegedly Exposed 199K User Fitness Profiles Through Misconfigured Firebase

A threat actor claims a misconfigured Firebase database exposed analytics tied to nearly 200,000 FitandLean users, including body weight tracking and workout activity.
Cropped screenshot of a forum post alleging that FitandLean exposed a publicly accessible Firebase analytics database containing nearly 200,000 user identifiers and hundreds of thousands of fitness tracking events. The post summarizes the alleged exposed data categories, affected fitness programs, and claimed record counts.
Cropped screenshot of the alleged FitandLean database exposure post. The image highlights the claimed Firebase misconfiguration and summary of the allegedly exposed analytics data. The database URL, threat actor identifier, sample records, download information, and other sensitive technical details have been redacted or omitted for safety and readability.

A threat actor has allegedly exposed a production Firebase Realtime Database belonging to FitandLean, claiming the instance contained analytics data tied to nearly 200,000 users across multiple fitness and weight management applications.

According to the forum post, the database was allegedly accessible without authentication due to a Firebase misconfiguration, allowing full read access to production analytics data. BreachNews has not independently verified the claim, and FitandLean had not issued any public statement at time of publication.

Health-related analytics allegedly exposed

The threat actor claims the exposed database contained 361,701 analytics events associated with 199,768 unique Firebase Authentication user IDs spanning nine fitness programs, including FitandLean, FitandHot, Pilates, Day30Fit, FitandFlat, FitandSlim, FitandFirm, Min7Fit, and FitandStrong.

According to the post, the allegedly exposed analytics included user identifiers, workout progress, course enrollment activity, body weight measurements, goal weights, weight change history, session duration, application usage metrics, trial enrollment events, and in-app purchase indicators.

The actor further claimed the largest volume of events originated from the FitandLean application, accounting for approximately 260,000 analytics records, followed by FitandHot and several other fitness programs operated through the same platform.

Potential privacy implications

The post claims the exposed records relied on persistent Firebase Authentication user identifiers rather than names or email addresses. While those identifiers are not inherently personal information on their own, the threat actor alleged they could potentially be linked to real identities if combined with information from other data sources.

The actor also argued that the dataset allegedly included sensitive health-related information because it tracked users’ body weight, target weight, fitness goals, workout progression, and engagement with weight-loss programs. If accurate, such information could increase the risk of targeted phishing, profiling, or other privacy harms.

BreachNews has not verified whether the database was publicly accessible or whether the claimed records originated from a live production environment.

Part of a broader pattern

The alleged FitandLean exposure is one of several recent claims published by the same threat actor involving allegedly misconfigured Firebase databases. The actor has also claimed similar exposures affecting MyPhoto Inc., Cars Software AS, American Auto Shipping, Allstate Tax LLC, BudBoard.co, and Qara.net. Those allegations have not been independently verified by BreachNews.

The forum post also claimed additional organizations may be disclosed in future publications as part of the same series of alleged Firebase exposures.

FitandLean had not issued any public statement at time of publication.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site