An influencer’s fitness app has been implicated in a massive data breach likely to expose customers’ personal information and reveal photos.
Move With Us is an online fitness platform founded by Rachel Dillon, the Instagram star and three-time World Champion of Beauty & Fitness.
Previously known as Bodies By Rachel, the service provides multi-week fitness programs and nutrition guides and encourages users to take before and after photos to show their progress.
But the app suffered a massive data flaw on Tuesday afternoon that could potentially reveal users’ personal information and photos to others.
Users were logging into other people’s profiles when they opened the app, allowing them to access their personal information, including photos (often nude or in underwear), emails, full names, date of birth and address.
Every time a user logs out and tries to log in again, they are on someone else’s profile.
There have been cases of users logged into up to 10 different profiles where the issue has persisted for more than 2 hours.
Move With Us released users an explanation Wednesday, saying the breach affected “a very small number of users.”
“This error caused an incorrect user profile picture and user profile page to appear,” the statement read.
“We are also able to ensure that no misrepresentation or financial information is accessed. We can also confirm that this was not malicious intent by a third party to gain access to our users’ information.”
The Move With Us user, who wished to remain anonymous, was not sure if his personal data had been disclosed.
“I have no idea if my data has been shown to other people,” they told NCA NewsWire.
From others’ accounts, the information visible was an email address, date of birth, full name, and some account seeing progress photos.
“I haven’t logged into anyone else’s account myself.”
The Dillon and Move With Us support team responded to hundreds of angry and anxious customers on the app’s Facebook group page, which has more than 90,000 members.
Move With Us has told users it will investigate the issue and reach out to affected people.
She warned that this process would take time, but emphasized that no one’s photos had been accessed.
“We sincerely apologize for this issue and can confirm that this has now been resolved,” she said.
“Our app provider has also advised that progress images were not visible to others.”
NCA NewsWire heard and read conflicting reports from users who claimed that their photos were visible.
“The photos were definitely visible,” one user said.
Another replied: “The pictures were definitely visible, take some ownership please.”
The anonymous Move With Us user, who has been using the app “on and off” for about 18 months and described it as a “good service,” said the breach “should never be allowed to happen.”
To be honest, this is a huge breach of privacy. The application encourages you to upload your photos while browsing programs. They tell you that you get prompts to do so, and this is meant to encourage you.
“But it’s very personal. A lot of people are incredibly sensitive about their bodies, and having personal information like emails, names, and birthdays is bad enough — but thinking about a picture of you at a poor time in your underwear is all too easy for strangers. Reaching for it. It totally took me off the brand.”
Dillon, who has more than 1.4 million followers on Instagram, said she started working to help other women on their fitness journeys.
“Sharing my training and nutrition programs with like-minded women on their own journey to advancement is what brings me true happiness,” she said on the Move With Us website.
Regardless of your fitness level, my team of certified nutritionists and expert trainers are here to support and guide you.
“My fitness journey has changed all aspects of my life, and I hope to have the opportunity to see what you can achieve on your own journey.”
Dillon made waves in the fitness world earlier this year when it was announced that she was dating Kayla Itsins’ ex-fiancé Toby Pierce.
Move With Us has been contacted for comment.