← All resources

Jims data breach: 150,000 members, IBANs exposed (29/09/2026)

Published October 1, 2026 · 7 min read · CyberNovaLabs.io

On 29 September 2026 Colruyt Group admitted it had underestimated the data breach at its Jims gym chain. The headline number is not the lesson. The ten-week gap between the first statement and the second one is — and so is what the GDPR expects of you during that time.

The short version

On 29 September 2026, Colruyt Group acknowledged that the data breach at its Jims gym chain was far larger than first stated: roughly 150,000 members are affected, across 31 of the 85 Belgian clubs[1][3]. The intrusion into the member management system took place between 13 and 20 July 2026[1][3]. The stolen records — name, address, date of birth, email address, membership data and, in some cases, the IBAN — are being offered for sale on the dark web[1][2].

What happened, and the date that actually matters

Two dates frame this case. On 20 July 2026 the unauthorised access ends. On 29 September 2026 the group publicly revises its estimate: what had first been described as a limited group of customers becomes some 150,000 members[1][3]. More than ten weeks separate the two.

Colruyt Group states that the Belgian Data Protection Authority was informed within the applicable timeframes, in accordance with its legal obligations, and that it has filed a complaint with the police[1][2]. No passwords and no health data were leaked[1][2]. Affected accounts were reset, fraudulent email addresses and domain names were blocked, and members were warned about phishing by email, text message and phone[1].

For the owner of a small company, the lesson is not in the number of victims. It is in the distance between the first announcement and the second.

What this changes for an SME

First lesson: the scope of a breach is almost always revised upwards. The GDPR anticipated this. Article 33(4) explicitly allows phased notification: you report what you know within 72 hours, then you complete the picture as the investigation progresses[9]. The mistake is not filing an incomplete scope. The mistake is waiting until you are certain before filing, or never updating what you filed.

Second lesson: the 72 hours start when you become aware of the breach, not on the day your IT provider hands you a report[9]. For a company without a security team, that has one very practical consequence: you must have decided in advance who pulls the trigger, and on how little information.

Third lesson: an exposed IBAN cannot be revoked. A password can be changed and a card can be reissued; an account number follows you. That is what keeps this kind of leak commercially useful to attackers long after the story has left the news.

The IBAN risk: three frauds to plan for

On that last point, this week's news answers itself. On 24 September 2026 the Dutch NCSC, the NCTV, the AIVD and the MIVD published a joint call to company leaders: artificial intelligence is accelerating and amplifying the threat, and action is needed now[8]. Their recommendations are deliberately basic — get the fundamentals in order, meaning reduce the attack surface and replace systems that no longer receive security updates; check whether your protection level is still adequate; take AI-related signals seriously[8]. Genuine personal data plus a language model is precisely the combination that turns crude phishing into a message people answer.

Your obligations, country by country

CyberNovaLabs.io works in the Netherlands, Belgium, France and Luxembourg. The deadline is identical in all four — it comes from the GDPR, not from national law — but the counter you file at is not.

CountryAuthorityDeadlineWhere to file
BelgiumAPD / GBA72 h after becoming awareThe APD portal; notifications sent by email are not processed[4]
FranceCNIL72 h after becoming awareThe CNIL online notification service[5]
NetherlandsAutoriteit Persoonsgegevens72 h after becoming awareThe AP data breach reporting desk[6]
LuxembourgCNPD72 h after becoming awareNotification to the CNPD, by form or dedicated address[7]

Two further duties sit on top of notifying the authority. Article 34 GDPR requires you to inform the individuals concerned, without undue delay, where the breach is likely to result in a high risk to their rights and freedoms[9]. Article 33(5) requires you to document every breach, including the ones you decide not to notify, together with the reasoning behind that decision[9]. That register is the first thing an authority asks to see during an inspection.

We explain how a regulator actually builds a fine in our article on the five-step method set out by the EDPB, and the product-side duties that increasingly reach smaller suppliers in the Cyber Resilience Act and what ANSSI expects from manufacturers.

To do this week

  1. Name in writing who decides to notify a breach, and who stands in for them. One line is enough.
  2. Open the breach register required by Article 33(5) GDPR, even if it stays empty.
  3. Create your account on your authority's portal now — APD, CNIL, AP or CNPD. On the day itself you will not have time.
  4. Write the dual-control rule for changes of bank details and send it to your finance team.
  5. Ask your IT provider, in writing, how quickly they commit to telling you about an incident. If it is more than 24 hours, your 72 hours are already running down.
  6. List the systems that no longer receive security updates. That is the first recommendation in the 24 September call[8].

No company is too small to be in scope

The GDPR sets no size threshold: the duty to notify applies to a four-person firm exactly as it applies to a retail group. The SMEs we work with in Brussels and across Belgium almost always hold more personal data than they assume — prospect lists, CRM records, direct debit mandates, HR files. The useful question is not whether you are a target. It is how long it would take you to establish what left the building. If the answer is more than three days, the GDPR deadline is out of reach.

If your company also falls under the NIS2 directive, incident reporting deadlines are different again and stack on top of the GDPR ones: our NIS2 guide for Belgium sets out which sectors are covered.

At CyberNovaLabs.io

We do not sell security audits. We make procedures executable: the automation that spots an abnormal access, alerts the right person and pre-fills the notification file, as part of our AI and automation for business offer. Counting the days between an intrusion and an accurate measurement of it is a job for tooling, not for memory. Let's go through your case in twenty minutes — quoted per project, with no minimum term.

Sources

  1. VRT NWS — Data breach at Colruyt's Jims fitness chain much larger than thought (29/09/2026)
  2. La Libre — La chaîne de salles de sport Jims victime d'une cyberattaque (29/09/2026)
  3. RetailDetail — Data breach at Jims underestimated: 150,000 members affected (29/09/2026)
  4. Autorité de protection des données (BE) — Notifier et gérer une violation de données
  5. CNIL (FR) — Notifier une violation de données personnelles
  6. Autoriteit Persoonsgegevens (NL) — Datalekken
  7. CNPD (LU) — Data breaches (General Data Protection Regulation)
  8. NCSC, NCTV, AIVD, MIVD (NL) — AI is accelerating and amplifying threats: immediate action is necessary (24/09/2026)
  9. Règlement (UE) 2016/679 (RGPD), articles 33 et 34 — EUR-Lex
CyberNovaLabs.io

Qualified meetings, no lock-in.

Criteria in writing before launch, pay per meeting or monthly, stop with a simple email.

→ Get meetings booked

Read next

Newsletter · CyberNovaLabs.io

Security Briefing

One email a month: a figure from our barometer, the NIS2 and CRA dates that matter in the Netherlands, Belgium and Luxembourg, and one practical guide. In English. Unsubscribe in one click.

→ Get meetings booked