TL;DR
A recent Ricardo data leak exposed the personal information of nearly 890,000 user accounts. Specifically, hackers accessed names, addresses, and phone numbers. Fortunately, the company patched the SMG security vulnerability shortly after detecting the breach.
What was exposed
The unauthorized access exposed specific contact details. For example, this included user names, postal addresses, and telephone numbers. Additionally, business users had their company names revealed. However, Ricardo confirmed that attackers did not access email addresses or passwords.
How it happened
According to reports, Ricardo noticed unusual activity on its servers on October 7, 2026. As a result, the technical team took immediate action to secure the systems. The company stated, “The security vulnerability that allowed this access has been fully resolved.”
Who is affected
Overall, the Ricardo data leak impacts approximately 890,000 user accounts on the Swiss platform. Consequently, the exposure affects both individual and business users.
What affected people should do
Therefore, users should monitor their mail and phones for suspicious messages. Often, scammers use names and phone numbers for phishing attacks. Meanwhile, remain alert for unexpected requests asking for passwords or financial data.
Company response
Currently, Ricardo is contacting the affected users directly about the exposure. They are explaining the implications and suggesting precautions. Furthermore, the platform notified the Swiss Federal Data Protection and Information Commissioner. Finally, they plan to file a police complaint and report the incident to the Swiss National Cyber Security Centre.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!