Skip to content
Data breachContained

Ricardo data breach exposes personal data of 890,000 Swiss marketplace accounts

Switzerland's Ricardo online marketplace disclosed that a security vulnerability exposed the names, postal addresses and phone numbers of about 890,000 user accounts.

Victim
Ricardo
users
890.0K

On 9 October 2026, Ricardo β€” Switzerland's leading online marketplace, operated by SMG Swiss Marketplace Group β€” disclosed that a security vulnerability on its platform had exposed the personal data of approximately 890,000 user accounts. The company said it had detected suspicious activity on its servers on 7 October and patched the vulnerability immediately, but that unauthorized individuals had already been able to reach account data before the gap was closed.

According to Ricardo and its parent company, the exposed information comprised names, postal addresses and telephone numbers, along with company names for business accounts. Crucially, the company stated that email addresses and passwords were not affected, which limits the risk of account takeover but still leaves affected users exposed to targeted phishing, fraud and social-engineering attempts that lean on real contact details.

Response

Ricardo said it is contacting affected users directly to explain the incident, its possible consequences and precautionary measures they can take. The company has notified the Federal Data Protection and Information Commissioner (FDPIC) through the legally required channels and said it intends to report the incident to the Swiss National Cyber Security Centre (NCSC/BACS) and to file a criminal complaint with law enforcement.

No threat actor has been identified, and the company has not described the technical nature of the vulnerability or said how long the data was accessible. Ricardo has not reported any confirmed misuse of the exposed data.

Context

Ricardo is one of Switzerland's best-known consumer platforms, used by millions of people to buy and sell second-hand goods, and it sits within SMG Swiss Marketplace Group, a portfolio that also includes real-estate, automotive and general classifieds brands. A breach touching roughly 890,000 accounts therefore represents a meaningful slice of the country's online-marketplace user base.

The practical risk for affected users lies less in account compromise β€” passwords and email addresses were not exposed β€” than in the combination of a verified name, home address and phone number. That bundle is precisely what scammers use to make fraudulent calls, letters and messages look legitimate. Users are advised to treat any unexpected contact that references a Ricardo transaction with caution, and to avoid acting on links or payment requests that arrive out of the blue.

Timeline

  1. Ricardo detects suspicious activity on its servers and moves to patch the underlying security vulnerability.

  2. Parent company SMG Swiss Marketplace Group publicly discloses that personal data from about 890,000 Ricardo accounts was exposed.

Sources

  1. bluewin.chhttps://www.bluewin.ch/en/news/switzerland/personal-data-from-890-000-user-accounts-was-exposed-li.3629936
  2. webdisclosure.comhttps://www.webdisclosure.com/article/smg-swiss-marketplace-group-holding-ag-etr-ricardo-fixes-security-vulnerability-exposing-user-data-GLgWRmLeqmH

Related incidents

Data breachResolved

Nulled.ch data breach (2020)

In May 2020, the hacking forum Nulled.ch was breached and the data published to a rival hacking forum. Over 43k records were compromised and included IP and email addresses, usernames and passwords stored as salted MD5 hashes alongside the private message history of the website's admin.

Victim
Nulled.ch
Records
43.5K
Data breachResolved

dvd-shop.ch data breach (2017)

In December 2017, the online Swiss DVD store known as dvd-shop.ch suffered a data breach. The incident led to the exposure of 68k email addresses and plain text passwords. The site has since been updated to indicate that it is currently closed.

Victim
dvd-shop.ch
Records
68.0K