Exclusive Sensitive info from hundreds of thousands of gym customers and staff – including names, financial details, and potentially biometric data in the form of audio recordings – was left sitting in an unencrypted, non-password protected database, according to a security researcher who shut it down. Leaky database hunter Jeremiah Fowler claims he discovered the wide-open AWS repository managed by HelloGym in late July and shared his findings with The Register. The database remained open for a week, and Fowler said it took a bit of digging to determine who was responsible for the repository of audio calls. "It was only after calling, asking individual gyms that mentioned their locations in the recording," he told The Register. "I asked who they use to record their calls and one of the managers finally told me." HelloGym provides sales, marketing, phone-answering, and VoIP call services for several top gyms including Anytime Fitness, Snap Fitness, and UFC Gym, among others, and the database contained 1.6 million audio files from a number of franchise locations of some of the largest fitness brands in the US and Canada. Some of these calls were also shared with The Register. HelloGym declined to comment for this story. The audio recordings, all stored as MP3s, mentioned people's names, phone numbers, and reasons for the call, such as to renew or cancel memberships. Based on the file dates and timestamps, these calls and voice recordings were collected between 2020 and 2025. A...
Call audio from gym members, employees in open database
The Register
·Jessica Lyons
·Published Sep 9, 2025
·Updated
Affected Software
2 affected components
HelloGym unknown
AWS unknown
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the exposure of sensitive audio recordings from gym members and employees due to an unsecured database.
2
What sensitive information was exposed in the data breach?
The breach included names, financial details, and potentially biometric data from hundreds of thousands of gym customers and staff.
3
What security implications does this incident highlight?
This incident underscores the risks associated with unencrypted and non-password protected databases containing personal data.
4
Which organizations are mentioned as affected by this security issue?
The article mentions HelloGym and AWS as associated with the exposed data.
5
How can organizations prevent similar data breaches in the future?
Organizations can prevent such breaches by implementing strong encryption, ensuring databases are password protected, and regularly auditing data security practices.