Ricardo data breach: what you risk and how to protect yourself
On Friday 9 October 2026 I too received Ricardo's email, as a user who sells on the platform: a security flaw had allowed someone unauthorised access to my name, postal address and phone number.
The same day SMG Swiss Marketplace Group, the company that owns Ricardo, issued an official statement: about 890,000 accounts are affected.
Data breaches are nothing new, but this one touches many people in Switzerland, and closely. This article explains what happened according to official sources, what a fraudster can do with that data, and what to do now.
What happened, according to official sources
Here are the facts as the company reported them, picked up by the Swiss press (RSI, Corriere del Ticino, Netzwoche):
| What | Detail |
|---|---|
| Detection | Wednesday 7 October 2026, suspicious activity on the servers |
| Cause | A security vulnerability, since closed |
| Accounts affected | About 890,000 |
| Data exposed | Names, postal addresses and phone numbers linked to orders; for business accounts, the company name too |
| Data not affected | Email addresses and passwords |
| Authorities | Notification to the Federal Data Protection and Information Commissioner (FDPIC), criminal complaint to the police, report to the Federal Office for Cybersecurity |
| Users | Informed directly by email |
There are also things we do not know. The statements do not explain how the vulnerability worked, who exploited it, or whether and where the data was copied or shared. Until that information arrives, the prudent choice is to act as if the data is already in the hands of someone who intends to use it.
In fairness, Ricardo's communication was quick and clear: two days from detection to the email to users, with a list of the data involved and concrete advice. That is not a given.
"It's only a name, address and phone number": why that is not little
The instinctive reaction is to think it is not serious. Your name is in the directory, the postman knows your address, and you have given your number to half the world.
The problem is not any single piece of data. It is the combination, plus one piece of information that is written nowhere but is implicit: whoever holds this data knows that you are a Ricardo user and have bought or sold something on the platform.
People in my line of work know this well: an OSINT investigation almost always starts from a few certain facts and cross-references them with other sources. With a name, address and phone number you can look for a social media profile, a business, a company page. That is how a generic message becomes a personalised one, and a personalised message is far more convincing.
For a fraudster the maths is simple: you bin an SMS that says "Dear customer". One that calls you by name, mentions Ricardo and perhaps your town makes you hesitate.
The scams to expect in the coming weeks
Nobody can predict with certainty how this data will be used. But the exposed data lends itself well to known fraud schemes, and those are where to raise your guard. It is also what Ricardo itself suggests in its message.
SMS and WhatsApp messages with links or QR codes
The most likely channel, since the phone number is one of the exposed items. Messages that appear to come from Ricardo, a payment service, the post office or a courier: "your payment is pending", "confirm your details to receive the money", "your parcel is held". The link leads to a page imitating the real one and asks for passwords, card details or confirmation codes.
Fake buyers
Sellers are especially exposed. A stranger poses as an interested buyer, often on WhatsApp, and offers to pay through a system that requires you to "click to receive the money" or enter your card details. You never need to enter your own card details to receive a payment.
Phone calls
A professional-sounding voice claims to be Ricardo support, a bank's security department or even the police: "there has been a data breach, we need to check your account". It uses the true news of the breach to make the false story credible. It may ask for codes received by SMS, for you to install a "remote support" app, or for a transfer to a "safe account".
Letters
With the postal address, paper fraud is also possible: fake invoices, payment demands, letters with QR codes leading to fraudulent sites. They seem more trustworthy precisely because they arrive in the letterbox.
What to do now
- Do not click links or scan QR codes received by SMS, WhatsApp or letter, even if they look like they come from Ricardo. To check your account, open the app yourself or type the website address.
- No serious company asks for passwords or SMS codes over the phone. If someone does, hang up. If in doubt, call back the official number, looked up independently.
- Be wary of urgency. "Within the hour", "or your account will be blocked": urgency is a fraudster's main tool, because it stops you thinking.
- Payments only through official channels. Do not move negotiations with unknown buyers or sellers to WhatsApp or email.
- Change reused passwords. Ricardo says its passwords are not affected. But if you use the same password elsewhere, now is a good time to change it and turn on two-factor authentication.
- Warn your family. Older people are a frequent target of phone scams, and a name and address are enough to build a believable story.
- Keep suspicious messages. Do not delete them straight away: they may be useful for a report or a complaint.
If you think you have already been scammed
- If you gave card or account details: call your bank or card issuer immediately to block them.
- If you entered a password: change it on every service where you use it.
- Keep evidence (screenshots, numbers, links) and file a complaint with the police.
- You can report the attempt to the Federal Office for Cybersecurity, which collects reports to identify ongoing campaigns.
Your rights
In Switzerland, data protection law requires anyone processing personal data to notify the FDPIC as soon as possible of any security breach likely to pose a high risk. Affected people must be informed when this is needed to protect them, in plain language: type of breach, consequences, measures taken and a contact. This is set out in the FDPIC's guide on article 24 of the Data Protection Act (Italian version).
In addition, everyone has the right to ask a company which personal data it processes about them. If you want to know exactly what Ricardo holds about you, you can ask.
The lesson for business owners
There is one aspect of this story that concerns every company, not just large platforms. A data breach does not end when the hole is closed. That is where the second phase begins, when the data is used against people: customers, employees, suppliers.
And that second phase is not fought with a firewall. It is fought with people who recognise a fake message, a carefully crafted phone call, an unusual payment request. It is the same principle that allowed the Enigma machine to be broken: technology holds, people's habits much less so.
That is why I offer cybersecurity awareness training for company staff, focused precisely on recognising modern scams. For more, the archive also has a guide to spotting crypto scams.
Article updated to 9 October 2026. If Ricardo or the authorities publish new information, I will update it.
Frequently asked questions
Do I need to change my Ricardo password?
According to Ricardo, no, because passwords and email addresses were not affected. If you use the same password on other services, though, now is a good time to change it and turn on two-factor authentication where possible.
What data was exposed in the Ricardo breach?
According to SMG Swiss Marketplace Group's statement of 9 October 2026, names, postal addresses and phone numbers linked to orders, for about 890,000 accounts. For business accounts, the company name too. Email addresses and passwords were not affected.
How do I know if my account is affected?
Ricardo is informing affected people directly by email. Be wary of any message asking you to click a link to 'check' whether you are affected: log in only by typing the website address yourself or using the official app. You can also ask Ricardo which data it holds about you, using the right of access under Swiss data protection law.
I clicked a suspicious link. What should I do?
Do not enter any more data. If you typed a password, change it at once on every service where you use it. If you gave card or account details, call your bank or card issuer immediately to block them. Then keep the messages and report the incident to the police.
Was Ricardo required to inform me?
Swiss data protection law requires breaches likely to pose a high risk to be reported to the FDPIC as soon as possible, and affected people to be informed when this is needed to protect them. Ricardo says it has notified the FDPIC and is informing users directly.
Are sellers on Ricardo at particular risk?
Sellers routinely receive messages from strangers as a normal part of trading, which makes them a natural target for fake purchase requests and fake payment links. The rule is the same: payments and communication only through the platform's official channels.