Skip to content
ThreatCluster

Ricardo Addresses Security Vulnerability Exposing User Data

First seen 9 Oct 2026, 14:34 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 9, 2026 at 15:40 UTC
  • •Unauthorized access to data of approximately 890,000 users was detected.
  • •Exposed data included names, addresses, and phone numbers, but not email addresses or passwords.
  • •Ricardo has notified authorities and affected users about the incident.

On October 9, 2026, Ricardo, part of SMG Swiss Marketplace Group, announced it had fixed a security vulnerability that allowed unauthorized access to personal data linked to approximately 890,000 user accounts. The exposed data included names, postal addresses, and telephone numbers, but email addresses and passwords were not compromised. The suspicious activity was detected on October 7, prompting immediate technical measures to secure the systems. Ricardo has informed affected users and reported the incident to the Swiss Federal Data Protection and Information Commissioner (FDPIC) and the Swiss National Cyber Security Centre (NCSC). A criminal complaint will also be filed with the police. The vulnerability has been fully resolved, and no further exploitation has been reported.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-07
Suspicious activity detected
Ricardo identified unauthorized access to user data and began securing its systems.
Live.Deutsche-Boerse
2026-10-09
Vulnerability fixed and announced
Ricardo announced the resolution of the security vulnerability and the exposure of user data.
nwr.eqs-cockpit.com

More articles in this cluster (2)

Following this threat?

Track Ricardo in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What type of data was exposed?
The exposed data included names, postal addresses, and telephone numbers, but not email addresses or passwords.
How many users were affected?
Approximately 890,000 user accounts were affected by the data exposure.
What actions has Ricardo taken in response?
Ricardo has fixed the vulnerability, notified affected users, and reported the incident to relevant authorities.