Ricardo data breach exposes personal data of 890,000 Swiss marketplace accounts
Switzerland's Ricardo online marketplace disclosed that a security vulnerability exposed the names, postal addresses and phone numbers of about 890,000 user accounts.
- Victim
- Ricardo
- users
- 890.0K
On 9 October 2026, Ricardo β Switzerland's leading online marketplace, operated by SMG Swiss Marketplace Group β disclosed that a security vulnerability on its platform had exposed the personal data of approximately 890,000 user accounts. The company said it had detected suspicious activity on its servers on 7 October and patched the vulnerability immediately, but that unauthorized individuals had already been able to reach account data before the gap was closed.
According to Ricardo and its parent company, the exposed information comprised names, postal addresses and telephone numbers, along with company names for business accounts. Crucially, the company stated that email addresses and passwords were not affected, which limits the risk of account takeover but still leaves affected users exposed to targeted phishing, fraud and social-engineering attempts that lean on real contact details.
Response
Ricardo said it is contacting affected users directly to explain the incident, its possible consequences and precautionary measures they can take. The company has notified the Federal Data Protection and Information Commissioner (FDPIC) through the legally required channels and said it intends to report the incident to the Swiss National Cyber Security Centre (NCSC/BACS) and to file a criminal complaint with law enforcement.
No threat actor has been identified, and the company has not described the technical nature of the vulnerability or said how long the data was accessible. Ricardo has not reported any confirmed misuse of the exposed data.
Context
Ricardo is one of Switzerland's best-known consumer platforms, used by millions of people to buy and sell second-hand goods, and it sits within SMG Swiss Marketplace Group, a portfolio that also includes real-estate, automotive and general classifieds brands. A breach touching roughly 890,000 accounts therefore represents a meaningful slice of the country's online-marketplace user base.
The practical risk for affected users lies less in account compromise β passwords and email addresses were not exposed β than in the combination of a verified name, home address and phone number. That bundle is precisely what scammers use to make fraudulent calls, letters and messages look legitimate. Users are advised to treat any unexpected contact that references a Ricardo transaction with caution, and to avoid acting on links or payment requests that arrive out of the blue.
Timeline
Ricardo detects suspicious activity on its servers and moves to patch the underlying security vulnerability.
Parent company SMG Swiss Marketplace Group publicly discloses that personal data from about 890,000 Ricardo accounts was exposed.
Sources
- bluewin.chhttps://www.bluewin.ch/en/news/switzerland/personal-data-from-890-000-user-accounts-was-exposed-li.3629936
- webdisclosure.comhttps://www.webdisclosure.com/article/smg-swiss-marketplace-group-holding-ag-etr-ricardo-fixes-security-vulnerability-exposing-user-data-GLgWRmLeqmH