Comparison Overview

Virgin Active

VS

Purpose Brands, LLC

Virgin Active

26 Little Trinity Lane, London, undefined, EC4V2AR, GB
Last Update: 2025-12-09

Virgin Active is a globally recognised exercise brand with over 230 clubs in 8 countries and more than 1.2 million members. As part of the Virgin Group founded by Sir Richard Branson, Virgin Active disrupted the UK fitness industry in 1999 by creating large health clubs offering an unprecedented number of world-class health and fitness products and services all under one roof. We now operate 38 clubs in the UK with an unparalleled collection of iconic locations in London and around the UK. A global industry leader for two decades, Virgin Active UK continues to innovate by developing a more personalised gym, multi-boutique experience and purpose to inspire people to live an active life. We’re always on the hunt for unique individuals with bucket loads of talent. If you’ve got what it takes or want to share an idea you think could be great, we’re all ears.

NAICS: 71394
NAICS Definition: Fitness and Recreational Sports Centers
Employees: 7,465
Subsidiaries: 15
12-month incidents
0
Known data breaches
0
Attack type number
1

Purpose Brands, LLC

111 Weir Drive, None, Woodbury, MN, US, 55125
Last Update: 2025-12-09
Between 700 and 749

Purpose Brands, LLC provides fitness, nutrition and wellness support and services to more than 7,000 communities and millions of people around the world. We own and operate the world’s largest and most trusted portfolio of fitness, health and wellness franchise brands and services: Anytime Fitness, Orangetheory Fitness, Waxing the City, Basecamp Fitness/SUMHIIT Fitness, The Bar Method, Stronger U Nutrition, Healthy Contributions and Provision Security. Together, these brands generate USD$3.7 billion in revenue, operating across 50 countries on all seven continents with a combined 6 million members. We combine this portfolio with a world-class franchise operating model and suite of services that helps our brands and franchise owners accelerate growth and deliver exceptional member experiences. Above all, our culture, people and franchise owners share a commitment to personal wellness; a spirit of service to help those who seek to improve their own physical and mental wellbeing; tireless advocacy and innovation for fitness, health and wellness experiences; and a daily honor to earn the trust in our brands from our franchise owners and the people who help consumers on their personal wellness journeys.

NAICS: 71394
NAICS Definition: Fitness and Recreational Sports Centers
Employees: 28,436
Subsidiaries: 0
12-month incidents
0
Known data breaches
1
Attack type number
1

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/virgin-active.jpeg
Virgin Active
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/purpose-brands-llc.jpeg
Purpose Brands, LLC
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
Virgin Active
100%
Compliance Rate
0/4 Standards Verified
Purpose Brands, LLC
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Wellness and Fitness Services Industry Average (This Year)

No incidents recorded for Virgin Active in 2025.

Incidents vs Wellness and Fitness Services Industry Average (This Year)

No incidents recorded for Purpose Brands, LLC in 2025.

Incident History — Virgin Active (X = Date, Y = Severity)

Virgin Active cyber incidents detection timeline including parent company and subsidiaries

Incident History — Purpose Brands, LLC (X = Date, Y = Severity)

Purpose Brands, LLC cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/virgin-active.jpeg
Virgin Active
Incidents

Date Detected: 05/2021
Type:Cyber Attack
Blog: Blog
https://images.rankiteo.com/companyimages/purpose-brands-llc.jpeg
Purpose Brands, LLC
Incidents

Date Detected: 12/2023
Type:Breach
Blog: Blog

FAQ

Virgin Active company demonstrates a stronger AI Cybersecurity Score compared to Purpose Brands, LLC company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

Virgin Active and Purpose Brands, LLC have experienced a similar number of publicly disclosed cyber incidents.

In the current year, Purpose Brands, LLC company and Virgin Active company have not reported any cyber incidents.

Neither Purpose Brands, LLC company nor Virgin Active company has reported experiencing a ransomware attack publicly.

Purpose Brands, LLC company has disclosed at least one data breach, while Virgin Active company has not reported such incidents publicly.

Virgin Active company has reported targeted cyberattacks, while Purpose Brands, LLC company has not reported such incidents publicly.

Neither Virgin Active company nor Purpose Brands, LLC company has reported experiencing or disclosing vulnerabilities publicly.

Neither Virgin Active nor Purpose Brands, LLC holds any compliance certifications.

Neither company holds any compliance certifications.

Virgin Active company has more subsidiaries worldwide compared to Purpose Brands, LLC company.

Purpose Brands, LLC company employs more people globally than Virgin Active company, reflecting its scale as a Wellness and Fitness Services.

Neither Virgin Active nor Purpose Brands, LLC holds SOC 2 Type 1 certification.

Neither Virgin Active nor Purpose Brands, LLC holds SOC 2 Type 2 certification.

Neither Virgin Active nor Purpose Brands, LLC holds ISO 27001 certification.

Neither Virgin Active nor Purpose Brands, LLC holds PCI DSS certification.

Neither Virgin Active nor Purpose Brands, LLC holds HIPAA certification.

Neither Virgin Active nor Purpose Brands, LLC holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to versions 10.2.0.4, including 9.3.0.x and 8.3.x display the full server stack trace when encountering an error within the GetCdfResource servlet.

Risk Information
cvss3
Base: 5.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Description

Pentaho Data Integration and Analytics Community Dashboard Editor plugin versions before 10.2.0.4, including 9.3.0.x and 8.3.x, deserialize untrusted JSON data without constraining the parser to approved classes and methods.

Risk Information
cvss3
Base: 8.8
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description

A security flaw has been discovered in CTCMS Content Management System up to 2.1.2. The impacted element is an unknown function in the library /ctcms/libs/Ct_Config.php of the component Backend System Configuration Module. The manipulation of the argument Cj_Add/Cj_Edit results in code injection. The attack can be executed remotely. The exploit has been released to the public and may be exploited.

Risk Information
cvss2
Base: 5.8
Severity: LOW
AV:N/AC:L/Au:M/C:P/I:P/A:P
cvss3
Base: 4.7
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 5.1
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A vulnerability was identified in CTCMS Content Management System up to 2.1.2. The affected element is the function Save of the file /ctcms/libs/Ct_App.php of the component Backend App Configuration Module. The manipulation of the argument CT_App_Paytype leads to code injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

Risk Information
cvss2
Base: 5.8
Severity: LOW
AV:N/AC:L/Au:M/C:P/I:P/A:P
cvss3
Base: 4.7
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 5.1
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Weblate is a web based localization tool. In versions prior to 5.15, it was possible to accept an invitation opened by a different user. Version 5.15. contains a patch. As a workaround, avoid leaving one's Weblate sessions with an invitation opened unattended.

Risk Information
cvss4
Base: 1.0
Severity: HIGH
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X