Swiss online marketplace Ricardo disclosed on October 9, 2026, that unauthorized parties accessed names, postal addresses and phone numbers tied to about 890,000 user accounts. The company spotted suspicious activity on its servers two days earlier and closed the hole it found.
What Happened?
- Ricardo says outsiders reached names, postal addresses and phone numbers linked to about 890,000 user accounts on its platform.
- Business accounts also had their company names exposed, while email addresses and passwords were not affected, according to Ricardo.
- SMG Swiss Marketplace Group, which owns Ricardo, says the security flaw behind the access has now been fully fixed.
- Ricardo has told the federal data protection commissioner and plans a police complaint plus a report to national cyber authorities.
The exposed records came from orders
Ricardo said in its official statement that the access touched personal data linked to orders on the platform. That explains the field list. A seller needs a name, a postal address and a phone number to ship a parcel, and those are the fields Ricardo named.
The marketplace belongs to SMG Swiss Marketplace Group (SIX: SMG), which runs several Swiss classifieds and auction sites. Ricardo said it started technical measures as soon as it detected the server activity, then fixed the vulnerability that allowed the access. Its follow-up investigation produced the account count.
“Email addresses and passwords were not affected,” Ricardo said. That matters for logins, since the exposed fields carry no credentials. It doesn’t make the data harmless.
Phone numbers and addresses carry the risk now
A real name, home address and mobile number let a scammer pose as a courier, a buyer or Ricardo support with uncomfortable accuracy. Marketplace users already expect texts about shipments and payments, so a fake one blends in. Exposed contact records can also resurface in fraud long after the original incident.
Ricardo users who think they may be affected can take a few steps now:
- Treat any call or SMS about a Ricardo order, delivery or payment with suspicion, and check the order inside the app instead.
- Don’t follow payment or “verification” links sent by text.
- Business sellers should warn staff who handle customer calls, because company names were exposed alongside contact details.
- A unique password plus any extra sign-in protection the account offers helps reduce risk, even though passwords were not part of this exposure.
What’s Next?
The disclosure leaves gaps. Ricardo has not explained how the vulnerability worked or which system held it. It also has not said how long the access ran before detection, or whether data left its servers. The statement does not say whether any other SMG platform was involved.
The Federal Data Protection and Information Commissioner (FDPIC), Switzerland’s data protection regulator, already has Ricardo’s notification. Two filings are still pending: a criminal complaint with the police and a report to the Federal Office for Cybersecurity (BACS). Ricardo’s English release calls that body the National Cyber Security Centre. For account holders, the next marker is Ricardo’s direct notice, which the company says will spell out the implications and the precautions to take.
































































