The Glofox Breach Happened in 2020. The MD5 Passwords Are Still Being Cracked.
HEROIC analysts uncovered the Glofox breach while tracking credential trading activity across dark web forums. In March 2020, this Irish gym management software company recieved a severe database compromise that exposed 2,320,068 membership records. The leaked data included email addresses, phone numbers, full names, birthdays, gender information, and unsalted MD5 password hashes, a combination that gives attackers both personal identity data and easily crackable credentials for immediate exploitation.
Why Unsalted MD5 Passwords, Birthdays, and Gender Data From Glofox Are a Targeted Attack Risk
Unsalted MD5 hashes are among the most accessable password formats for attackers to crack. Without a salt, identical passwords produce identical hashes, meaning entire lookup tables can reverse thousands of hashes in seconds. When cracked passwords are combined with birthdays and gender from the Glofox breach, attackers can build convincing identity profiles. These profiles are partcularly useful for bypassing knowledge-based authentication questions at financial institutions and telecom providers.
What Was Exposed in the Glofox Breach
- Email Address
- Phone Number
- First Name
- Last Name
- Birthday
- Gender
- Password Hash (unsalted MD5)
Why the Glofox Breach Still Poses Active Risk Years After It Occured
The Glofox breach occured in March 2020, but the data has continued to circulate and resurface in new contexts across underground forums and Telegram channels. Gym membership platforms collect highly personal data tied to real identities, billing addresses, and health habits. Any of the 2.3 million affected users who reused their Glofox password elsewhere remain vulnerable to account takeover today. The unsalted MD5 hashing means most passwords in this dataset have likely already been cracked by threat actors with access to modern GPU rigs.
How a Database Breach Works
A database breach occurs when an attacker gains unauthorized access to a server-side database by exploiting application vulnerabilities, weak credentials, or misconfigurations. In software-as-a-service environments like gym management platforms, a single database may hold records for users across many business clients. Attackers export the full user table, compress it, and distribute it through private channels and public forums where other criminals use it for credential stuffing and fraud.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion leaked records, including the Glofox breach, to tell you instantly whether your email address has been compromised. Run a free scan at HEROIC.com and see what information criminals may already have about you.
Breach Breakdown
2,320,068 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds