securityonline.info 9 Oct 2026, 16:26 UTC

Ricardo Swiss breach exposes personal details of 890,000 accounts

Ricardo Swiss breach exposes personal details of 890,000 accounts

A data breach on the Ricardo Swiss platform exposed the personal details of around 890,000 user accounts. Hackers were able to access names, postal addresses and telephone numbers, with business users’ company names also revealed. Ricardo has stated that email addresses and passwords were not accessed, and that the security vulnerability involved—referred to as the SMG security vulnerability—has now been fully resolved. The incident was detected after unusual activity on 7 October 2026, prompting immediate measures to secure the systems.

Ricardo’s response has included direct outreach to affected users to explain the implications and advise precautions. The company has also notified the Swiss Federal Data Protection and Information Commissioner and plans to file a police report as well as inform the Swiss National Cyber Security Centre. The breach is framed as affecting both individuals and business users on the Swiss platform, underscoring the potential risk of targeted phishing or social engineering using the exposed contact details.

Users are urged to monitor mail and phone communications for suspicious messages and to be vigilant about requests for passwords or financial information. The article emphasises that the exposed data excludes email addresses and passwords, but the practical risk from name, address and phone data remains relevant for attackers attempting social or phishing-based attacks.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline