PayAsUGym hack exposes members' card details

PayAsUGym hack exposes members' card details

Fitness website PayAsUGym has admitted that members' financial details were stolen when one of its servers was hacked on Thursday.

The discovery was made by security experts who found partial card numbers and home addresses on a public website.

The company acknowledged there had been "confusion" over earlier claims that it did not hold any card details.

Security expert Troy Hunt advised customers to cancel their credit card if they think details have been stolen.

PayAsUGym, which sells passes for gyms around the UK, alerted its members to the security breach in an email on Friday which said "one of the company's IT servers was accessed by an unauthorised person".


While it said email addresses and passwords were accessed, it claimed "we do not hold any financial or credit card information".

The company said 300,000 customers details had been stolen.

He said the first six digits and last four digits of people's cards had been "dumped on a website, presumably by the perpetrator".

Mr Hunt explained that fraudsters can use computer algorithms to work out complete credit card details "within seconds".

"PayAsUGym has stated that there is no card data at risk, yet here we have a screen grab of a large amount of card data," he said. "There's some transparency lacking here."

PayAsUGym said it had started using new servers after speaking with cyber security professionals.

The website said it used a "tokenised system" for customer payments which, it says, means card details are stored at the payment gateway - not on its servers.

PayAsUGym's Mr Ward added: "We don't hold the full number for security reasons. The payment is then made using a tokenised system."

The company advised concerned customers to contact them.



Add Comment

all comments

  Other news

more
Burning boats

Burning boats..

26-Jul, 23:41

Outside Libyan waters, it has deployed military vessels to disrupt the...

Man arrested after live cobras found inside potato chip cans

Man arrested after live cobras found inside potato chip cans..

26-Jul, 15:20

A California man was arrested after a package addressed to him was found...

California independence 1 step closer as AG paves way for potential 2018 referendum

California independence 1 step closer as AG paves way for potential 2018 referendum..

26-Jul, 07:10

A new California independence campaign has got the go ahead to collect...

Ohio puts child killer to death with controversial lethal injection drug

Ohio puts child killer to death with controversial lethal injection drug..

26-Jul, 16:30

Ohio carried out its first execution in more than three years as child...

Trump's 'deportation force' begins to take shape

Trump's 'deportation force' begins to take shape..

14-Apr, 12:48

President Trump's campaign promise for more aggressive immigration...

New EPA head's emails indicate close ties to oil and gas producers

New EPA head's emails indicate close ties to oil and gas producers..

22-Feb, 18:02

More than 7,000 pages of emails from Environmental Protection Agency head...

Prince William, Princess Kate face off in rowing competition

Prince William, Princess Kate face off in rowing competition..

20-Jul, 16:11

Prince William won bragging rights today in Heidelberg, Germany, as his...

Stabbed London Bridge officer tells of fighting attackers

Stabbed London Bridge officer tells of fighting attackers..

28-Jun, 17:24

A British Transport Police officer who fought off three extremists in...