2026 Ricardo — security vulnerability; ~890k accounts (names/addresses/phones)
Data compromised
Per SMG/Ricardo 9 Oct 2026 notice: names, postal addresses, telephone numbers for ~890,000 user accounts; business users also company names. Email addresses and passwords were not affected.
Technical writeup
Verified SMG Swiss Marketplace Group media release (9 Oct 2026). Ricardo detected suspicious server activity on 7 Oct 2026, secured systems, and fully resolved the vulnerability. Investigation established personal data for approximately 890,000 user accounts was exposed — limited to names, postal addresses, and telephone numbers (plus company names for business users). Emails and passwords not affected. Users notified directly; FDPIC (EDÖB) notified; criminal complaint planned; NCSC report planned. companyConfirmed true; recordsAffected 890000.
Root cause
Security vulnerability enabling unauthorized access to personal data linked to orders (detected 7 Oct 2026; vulnerability fixed)
References
- https://swissmarketplace.group/media-release/ricardo-fixes-security-vulnerability/
- https://swissmarketplace.group/wp-content/uploads/2026/10/261009_Ricardo_security_vulnerability.pdf
- https://www.nzz.ch/panorama/hacker-erbeuten-daten-von-890-000-ricardo-nutzerkonten-ld.10029294
- https://www.tagesanzeiger.ch/ricardo-datenleck-betrifft-890000-nutzerkonten-807756326522