The Ryde Data Breach

The scale of the incident is notable as it affected Ryde’s entire user base of 4.5 million accounts. Users are located in Norway, Sweden, Finland, Germany and other Ryde markets. According to Swedish Television as many as 1.3 million of the affected accounts belonged to users in Sweden. [2]

Introduction to Malware Binary Triage (IMBT) Course

Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.

Ryde states that the exposed data included phone numbers, email addresses, dates of birth, partial card numbers and in some cases also payment history for ride purchase and fees. Journey history was not included in the affected data. [1]
Assessment

As of today, no threat actor has been publicly identified, and Ryde has not disclosed how the intruder gained access. The incident is however in line with the pattern of opportunistic cybercrime activity that Truesec has observed in the past. Cybercriminals often steal personal data and resell it to other criminals that use them to fuel more criminal activities, such as fraud and new breaches.

A breach affecting a widely used digital service creates cascading risks beyond the initial attack.

  • The primary victim can suffer severe reputational loss as they must inform their customers that they have failed to protect their customer’s personal data. This can also expose them to potential GDPR fines.
  • The customers may be exposed to various forms of cyber fraud attempts, as cybercriminals attempt to weaponize their stolen private data.
  • Consumer breaches could also affect the victim’s employers. Employees may use corporate email addresses for private services such as mobility apps, online shopping, travel, and subscriptions, and some may reuse the same or similar passwords across personal and work accounts. If a data breach leaks corporate email addresses, attackers could also use it for credential stuffing, phishing, or targeted social engineering against their employer’s environment.

Recommendations

Organizations that handle large customer databases must understand that this data is highly valuable and a prime target for cybercriminals, even if it doesn’t include full credit card information or other payment information. This data needs to be protected.

Organizations that may have had employee’s account information leaked should use the Ryde breach as an opportunity to review and strengthen relevant security controls.

Phishing and Smishing Risk

  • Warn employees and customers about phishing that uses leaked personal or payment related information.
  • Monitor for Ryde-themed phishing, fake support messages, SMS fraud, refund scams, and payment-related social engineering.

Corporate Email Usage

  • Identify whether employees used company email addresses for Ryde or similar private services.
  • If corporate addresses appear in breach data, treat those identities as higher risk for phishing and credential stuffing.

Password Reuse

  • Remind employees not to reuse passwords across personal and work accounts.
  • Monitor for failed sign-in spikes, password spraying, and credential stuffing against Microsoft 365, VPN, SSO, SaaS, and remote access services.
  • Consider risk-based authentication or targeted password resets where exposure is confirmed.

Affected users that have had their personal data stolen in this breach should follow the following guidelines

  • Be alert to unexpected emails, text messages, or phone calls.
  • Do not click unfamiliar links, particularly those asking you to update payment information.
  • Keep evidence of suspicious contacts.
  • Report attempted fraud to the police.
  • Never sign in through a link received by SMS or email. [3]

If you or your organization have concerns about the topic above or need support, please reach out to your Truesec contact for further assistance.

References

[1] https://www.ryde-technology.com/security-incident-2026-08-02
[2] https://www.svt.se/nyheter/lokalt/norrbotten/efter-dataintranget-hos-ryde-sa-manga-berors-i-sverige
[3] https://www.datatilsynet.no/aktuelt/aktuelle-nyheter-2026/vi-har-mottatt-avviksmelding-fra-ryde/

The post The Ryde Data Breach appeared first on Truesec.

Article Link: The Ryde Data Breach - Truesec