logo

No gains, just pains as 1.6M fitness phone call recordings exposed online

ID: e36ef5da-3c2e-50dc-84d6-d631f72321e1

STIX ID: report--e36ef5da-3c2e-50dc-84d6-d631f72321e1

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2025-09-09

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

HelloGym left an unencrypted, publicly accessible AWS repository containing ~1.6 million MP3 call recordings (2020–2025) belonging to customers and staff of major gym brands. The files included names, phone numbers, billing/payment discussions, employee credentials, and voice data that could be abused for social engineering or voice-cloning; the exposure was discovered by a researcher who shut it down after about a week. The report warns of risks from impersonation and deepfakes and recommends encryption, penetration testing, and data retention/segmentation controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.