Skip to main content
LiMP VPN
All news

DDX Fitness Breach Exposes Client Photos and Personal Data

DDX Fitness Breach Exposes Client Photos and Personal Data

In short: On August 13, 2026, archives containing client photos and personal data from DDX Fitness — Russia's largest fitness chain with 168 clubs and roughly 900,000 members — surfaced on dark web forums. The company has launched an internal investigation; the full scale of the breach has not been confirmed.

What Happened

The incident was first reported by Russian Telegram channel Baza in the early hours of August 13, 2026. Archives allegedly containing DDX Fitness customer data appeared on dark web forums and closed cybercrime communities. TASS confirmed the reports citing information security sources; Habr, CNews Safe, and thecode.media then covered it in detail.

DDX Fitness is Russia's largest fitness operator: 168 clubs across 64 cities, approximately 900,000 active subscribers, and 17.6 billion rubles in 2025 revenue. The company runs its own proprietary club management platform and mobile app for bookings and payments — the systems most likely to hold the member photos taken at reception desks during sign-up. For practical tips on reducing your digital footprint, see LiMP VPN features.

DDX Fitness issued a statement: "Information about a possible incident involving customer personal data has appeared in the public domain. An internal investigation is underway in full compliance with legal requirements." The company also said it had strengthened its information security measures.

What Data Was Exposed

According to Habr and CNews Safe journalists who reviewed the circulating archives, the leaked data reportedly includes:

  • Customer photographs — primarily taken at reception desks during membership registration;
  • Club visit dates and times;
  • Total visit counts;
  • Purchase information (memberships, additional services);
  • Club location addresses associated with each account;
  • Personal data linked to the user's app profile.

No bank card or payment data has been confirmed as part of the breach by the company or independent security researchers at the time of publication.

According to Mentoday, the archives reportedly contain data belonging to well-known Russian public figures — actor Yuri Kolokolnikov and influencers Sasha Teslong and Alexandra Mitroshina — which amplified public attention to the incident and raised broader questions about biometric data storage by large service providers.

Legal Consequences for DDX

Under Russia's Federal Law No. 152-FZ on Personal Data (amended in 2024 with significantly higher penalties), companies face fines of 3 to 15 million rubles for a breach of this type — and up to 3% of annual revenue in cases of repeated violations. For DDX, with 17.6 billion rubles in 2025 revenue, the latter figure could be substantial. The company is also legally required to notify Russia's telecommunications regulator Roskomnadzor within 24 hours of confirming an incident and provide a detailed response report within 72 hours.

What This Means for Ordinary Users

Gym photos might seem like minor data at first glance. But combined with visit history, purchase details, and personal profile information, they create a detailed digital portrait with a biometric component.

The practical risks include:

  • Targeted phishing. An attacker who knows your name, photo, and which DDX club you visit can craft convincing fraudulent messages impersonating the company, a bank, or a government agency. Social engineering tactics built on this kind of data are detailed in our article on remote access scams.
  • Social engineering. A gym photo is more than an image — it can be used to establish false trust or bypass visual identity verification in certain services.
  • Cross-breach correlation. Leaked databases are rarely isolated. Criminals actively merge datasets from multiple incidents — your DDX data may be combined with data from other breaches to build richer profiles.

What to Do Right Now

Whether you are a DDX Fitness member or want to reduce your future exposure:

  1. Check your email for known breaches. HaveIBeenPwned shows which incidents include your address — enable breach alerts to be notified early.
  2. Enable two-factor authentication everywhere you can. Even if your email is exposed, an attacker cannot access your accounts without the second factor.
  3. Be cautious about any contact claiming to be from DDX. The company will not request passwords or payment details via messenger or phone. Verify any suspicious message by navigating directly to the official website — not through a provided link.
  4. Minimize the data you share with apps. If an application requests unnecessary permissions, consider whether you actually need the service.
  5. Use a VPN on public Wi-Fi at gyms and clubs. LiMP VPN encrypts your traffic and hides your IP address — it will not prevent a company's servers from being hacked, but it protects your data on shared networks. See the LiMP VPN features page for details.

Sources

DDX Fitness Breach Exposes Client Photos and Personal Data