No gains, just pains as 1.6M fitness phone call recordings exposed online
ID: e36ef5da-3c2e-50dc-84d6-d631f72321e1
STIX ID: report--e36ef5da-3c2e-50dc-84d6-d631f72321e1
Feed Name: The Register (Security)
HelloGym left an unencrypted, publicly accessible AWS repository containing ~1.6 million MP3 call recordings (2020–2025) belonging to customers and staff of major gym brands. The files included names, phone numbers, billing/payment discussions, employee credentials, and voice data that could be abused for social engineering or voice-cloning; the exposure was discovered by a researcher who shut it down after about a week. The report warns of risks from impersonation and deepfakes and recommends encryption, penetration testing, and data retention/segmentation controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
