$4.99/mo - Save 61% With Exclusive 2-Year Plan + 4 Months Free!Claim Now

KillSec Ransomware Gang Targets Clubfit Software, Exposes Client Data

  • Last updated December 4, 2024
  • written by
    Writer

Melbourne, December 4, 2024 – The KillSec ransomware gang has claimed responsibility for a data breach involving Clubfit Software, an Australian gym management software provider, and has begun leaking sensitive information on its darknet site.

Clubfit Software, which offers cloud-based solutions for gym management, has become the latest victim of cybercriminal activity, with KillSec announcing the breach and sharing what it claims is 1% of the stolen data, amounting to nearly 200 gigabytes.

In a post dated November 24, KillSec stated, “One per cent of data is published,” linking to a file hosting site and indicating that further updates would follow. The gang has provided files as evidence of their breach, including gym membership agreements that contain personal information such as names, addresses, phone numbers, emails, and emergency contact details, many of which include signatures.

While KillSec has not disclosed a ransom amount or a payment deadline, it has indicated that the company can pay for data deletion and that individuals unrelated to the company may contact them for data purchase agreements. The gang has also begun contacting Clubfit’s clients, which include 694 gyms and fitness centers, such as Anytime Fitness and other notable franchises.

KillSec, which began operations in October 2023 and rebranded as a ransomware-as-a-service operation in June 2024, describes itself as a “prominent hacktivist group” that blends elements of activism with hacking. Their previous Australian victim was Vogue Homes.

Clubfit Software provides a comprehensive gym management solution that includes payment tracking, reporting, access control, marketing, and statistical analytics. The company has not yet responded to inquiries regarding the breach.

The incident highlights the ongoing threat posed by ransomware groups and the vulnerabilities faced by businesses in safeguarding sensitive customer data.