Ricardo Addresses Security Vulnerability Exposing User Data
Article Content
- •Unauthorized access to data of approximately 890,000 users was detected.
- •Exposed data included names, addresses, and phone numbers, but not email addresses or passwords.
- •Ricardo has notified authorities and affected users about the incident.
On October 9, 2026, Ricardo, part of SMG Swiss Marketplace Group, announced it had fixed a security vulnerability that allowed unauthorized access to personal data linked to approximately 890,000 user accounts. The exposed data included names, postal addresses, and telephone numbers, but email addresses and passwords were not compromised. The suspicious activity was detected on October 7, prompting immediate technical measures to secure the systems. Ricardo has informed affected users and reported the incident to the Swiss Federal Data Protection and Information Commissioner (FDPIC) and the Swiss National Cyber Security Centre (NCSC). A criminal complaint will also be filed with the police. The vulnerability has been fully resolved, and no further exploitation has been reported.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Ricardo in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What type of data was exposed?
How many users were affected?
What actions has Ricardo taken in response?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…