On June 25, 2026, protein-bar maker Fitcrunch appeared on the leak site of the spacebears ransomware group. The company, known for its baked bars, wafers, and powders endorsed by Robert Irvine, may have had internal files stolen during a ransomware attack. Public reporting indicates the exposed material includes personal information of employees and clients as well as financial documents and other company files.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Fitcrunch
Get alerted the next time Fitcrunch files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Fitcrunch’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Available reporting describes the incident as a classic ransomware operation in which attackers gained access, exfiltrated data, and later listed Fitcrunch on their public leak site. The data exposed consists of internal documents rather than a single customer database. No exact victim count has been published, leaving both current and former employees, contractors, and customers uncertain whether their records were taken. The leak site entry appeared on June 25, 2026, and follows the group’s standard pattern of posting proof of compromise after negotiations fail.
Because the files contain mixed employee and client records, anyone who has ever purchased Fitcrunch products, worked for the company, or had their information stored in its systems could be affected.
Why This Matters for You and Your Family
When a company you buy from or work with loses control of personal information, the risk does not stop at spam or minor fraud. Names, addresses, dates of birth, and financial details can be combined with data from other breaches to build a complete profile. For families this often means children’s information surfaces alongside parents’ records, especially when shared billing addresses or family accounts are involved. Once that profile exists, it can be sold, used for identity theft, or leveraged to pressure you into paying to keep it private.