
Ricardo data breach exposes personal details of 890,000 Swiss user accounts
Swiss online marketplace Ricardo says names, postal addresses and phone numbers of about 890,000 user accounts were exposed through a security flaw. Email addresses and passwords were not affected, according to parent company SMG Swiss Marketplace Group.
What was exposed
Swiss online marketplace Ricardo has disclosed a security flaw that made personal data of about 890,000 user accounts accessible, according to its parent company SMG Swiss Marketplace Group. The exposed data includes names, postal addresses and telephone numbers. According to the information available so far, company names of commercial users were also affected. The company said email addresses and passwords were not exposed.
How the incident unfolded
Ricardo detected suspicious activity on its servers on Wednesday 7 October and immediately started technical measures to secure its systems. The security vulnerability that enabled the access has since been completely fixed. A subsequent investigation established that personal data had been exposed. SMG announced the incident on Friday 9 October.
- Ricardo detects suspicious activity on its servers
- Vulnerability that enabled the access is completely fixed
- SMG announces that personal data of about 890,000 accounts was exposed
Notifications and next steps
Ricardo is informing affected users directly about the incident, its possible implications and the precautions they can take. In line with legal requirements, the platform has notified the federal data protection and information commissioner (FDPIC). Ricardo also plans to file a criminal complaint with the police. One report says the incident will be reported to the Federal Office for Cybersecurity (UFCS), while another names the National Cybersecurity Centre as the body to be informed.
