Were you recently affected by a data breach?

Harman Fitness Data Breach

Harman Fitness, a Baltimore-based fitness club operator, reported a data breach to the Texas Attorney General on October 6, 2026. The report lists 1,057 Texans affected, with Social Security numbers, financial and medical information involved.

Harman Fitness
Date of Breach: Not disclosed (reported to Texas AG October 6, 2026)
CAU logo

Who was affected:

Clients of Harman Fitness

Impacted Data:

Names, addresses, Social Security numbers, driver’s license and government ID numbers, financial information, medical information, health insurance information, dates of birth

Harman Fitness, a fitness club operator based in Baltimore, Maryland, has reported a data breach to the Texas Attorney General. The report lists 1,057 affected Texans and says Social Security numbers, financial details and medical information were among the data involved.

Harman Fitness’s Data Breach Investigation

Harman Fitness is a fitness club operator headquartered in Baltimore, Maryland. A law-firm notice page describes it as doing business as Crunch Fitness, and a threat-intelligence site describes it as a franchise operator of that gym brand. Businesses that run membership gyms keep a lot of personal information, including sign-up records, payment details, identification documents and, in some cases, health-related information supplied by members and employees.

On October 6, 2026, a data security breach report for Harman Fitness was published on the Texas Attorney General’s public breach reporting portal. The report lists 1,057 Texans as affected. It states that notice was provided to consumers by U.S. Mail. The Texas figure counts only Texas residents, so the total number of people affected nationwide may be higher, and the report as reviewed does not give a nationwide total.

According to the report, the types of information affected were names, addresses, Social Security number information, driver’s license numbers, other government-issued ID numbers such as passport or state ID numbers, financial information such as account or card numbers, medical information, health insurance information and dates of birth. The report does not say which of these categories applied to which individual, so people who receive a letter should check it to see what applies to them.

The report does not say how the incident happened, when it began, or when Harman Fitness discovered it. Separately, a threat-intelligence site reported that a ransomware group calling itself Netrunner claimed an attack on the company on April 3, 2026, and said the group threatened to release data. That claim comes from the attackers’ own posting. It is not confirmed by Harman Fitness, and the breach report does not link the two, so this page does not treat them as the same event.

The combination of data listed is a serious one. A name paired with a Social Security number, a date of birth and a government ID number is the core set of identifiers that criminals use to open credit accounts, file fraudulent tax returns, apply for loans or benefits, and take over existing accounts. Financial account details add the risk of direct fraud, while medical and insurance details can be used for medical identity theft and for convincing phishing messages that reference a real health plan.

Because the report says notice was sent by mail, people connected to Harman Fitness may already have received a letter. Notice letters typically explain what happened, list the information involved for the recipient, describe the steps taken in response, and often offer free credit monitoring or identity protection for a set period. Keep any letter you receive, and read it closely for enrollment deadlines and contact details.

Businesses that collect sensitive personal information are expected to protect it with reasonable safeguards such as access controls, encryption, staff training and monitoring for unusual activity. When those protections fail, regulators and the people affected look to the company for a clear account of what went wrong and what it is doing to prevent a repeat.

Companies with many locations and many staff members often rely on outside vendors for payroll, membership billing, marketing and IT support, which can spread sensitive records across several systems. Where a breach is confirmed, the company is generally responsible for working out whose information was involved, notifying those people and regulators, and explaining what is being done to reduce the chance of a repeat incident.

If you are a current or former member or employee of Harman Fitness, there is no need to assume your information was taken, but it is sensible to stay alert. Review your credit reports and bank and card statements, watch for suspicious calls, texts and emails that mention the company or this incident, and consider a fraud alert or credit freeze as a precaution. This page will be updated if the company or a regulator publishes more confirmed details.

When Did This Breach Occur?

The Texas Attorney General’s portal published the Harman Fitness report on October 6, 2026. The report as reviewed does not state when the incident began or when the company discovered it, so the full timeline remains unknown.

What Information Was Breached?

The Texas Attorney General’s report lists names, addresses, Social Security number information, driver’s license numbers, other government-issued ID numbers, financial information, medical information, health insurance information and dates of birth. The report does not break down which data applied to which individuals.

What You Can Do

If you may be connected to Harman Fitness, consider these steps:

  • Watch your mail for a notice from Harman Fitness and keep any letter you receive.
  • Check your credit reports for free at annualcreditreport.com, and consider a fraud alert or credit freeze with Equifax, Experian and TransUnion.
  • If you are offered credit monitoring or identity protection, read the terms and enroll before any stated deadline.
  • Review bank, card and insurance statements for charges or services you do not recognize, and consider replacing a card or account number if you shared one with the company.
  • Be cautious with unexpected calls, texts or emails that mention this incident, and confirm any request through a phone number you already trust.
  • Report suspected identity theft to the Federal Trade Commission at identitytheft.gov and to your state Attorney General.

File a Data Breach Lawsuit Against Harman Fitness

If you are a current or former Harman Fitness member or employee and received notice about this incident, or believe your information was exposed, you may have legal options. Companies are expected to safeguard the sensitive information they hold, and a class action can help hold them accountable when they fail to do so.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: June 3 - June 8, 2026
Date of Breach: Not disclosed (reported to Texas AG October 6, 2026)
Date of Breach: Not disclosed (reported to Texas AG October 6, 2026)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.