Science & Tech · Cybersecurity · 2 days ago
Ricardo data breach affects about 890,000 user accounts
Ricardo, an online marketplace, says someone accessed personal data linked to about 890,000 user accounts.
The exposed information includes names, postal addresses and phone numbers; business accounts also had company names exposed.
Email addresses and passwords were not affected.
Ricardo detected suspicious activity on its servers on October 7 and says it closed the security gap.
The company says there have been no ransom demands or extortion so far.
Ricardo is contacting affected users and advising them to be cautious about unexpected messages or calls asking for sensitive financial details.
It has notified Switzerland’s data protection authority, plans to report the incident to the federal cybersecurity office and will file a police complaint; authorities will investigate who was responsible.
Unauthorised parties accessed personal data from about 890,000 Ricardo user accounts.
The exposed data included names, postal addresses and telephone numbers; email addresses and passwords were not affected.
Ricardo said it detected suspicious server activity on October 7 and closed the security vulnerability.
SMG said the incident had not led to extortion or ransom demands, and Ricardo plans to file a criminal complaint against unknown persons.
The reports differ on whether data linked to platform orders was accessed.
- Who
- Unauthorised parties accessed data from Ricardo user accounts.
- What
- Personal data from about 890,000 accounts was accessed, including names, postal addresses and telephone numbers.
- When
- Ricardo detected suspicious activity on October 7, 2026; reports about the incident were published on October 9.
- Where
- Ricardo, an online marketplace; the suspicious activity was detected on its servers.
- Why
- Not stated.
This story does not have two clearly opposing sides.
We advise you to be especially cautious with unexpected mail, calls and messages via SMS or WhatsApp asking you to provide sensitive data such as credit card details, bank or Twint logins.
Ricardo detected suspicious activity on its servers and took steps to secure its systems.
Ricardo closed the security vulnerability that had enabled the access.
Reports said about 890,000 accounts were affected and Ricardo was informing users.
- Affected accounts
- About 890,000
- Exposed data
- Names, postal addresses and telephone numbers
- Unaffected data
- Email addresses and passwords
- Detection date
- October 7, 2026
- Additional business-account data
- Company names











