Skip to content

PayAsUGym

Disclosed Dec 17, 20169 years ago400,260 accountsUnverified

In December 2016, an attacker breached PayAsUGym's website exposing over 400k customers' personal data. The data was consequently leaked publicly and broadly distributed via Twitter. The leaked data contained personal information including email addresses and passwords hashed using MD5 without a salt.

What is known

People affected400,260 (accounts in the leaked data, per Have I Been Pwned)
DisclosedDec 17, 2016
HappenedDec 15, 2016
AttackNot stated
Data exposedEmails, IP addresses, Names, Payment cards, Passwords, Phone numbers
SectorTech
StatusUnverified: not yet confirmed by an official notice, a filing or the organization
Check your emailHave I Been Pwned

Sources

Source
Have I Been Pwned: PayAsUGymhaveibeenpwned.com · Aggregator

Notices filed

WhereFiledPeople
Have I Been Pwnedaccounts in the dataDec 17, 2016400,260
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Have I Been Pwned). Record counts are as reported. Not legal advice.

Everything about PayAsUGym

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.