The Ricardo data leak phishing risk is the main concern for users of the Swiss online marketplace after a vulnerability exposed contact details belonging to roughly 890,000 people. SMG, the company behind the platform, says it has fixed the security flaw and confirmed that passwords were not affected. That is good news, but it does not mean affected users can relax. Contact details are exactly what scammers need to make fraudulent messages look convincing.

What the Ricardo leak exposed

According to the report, the incident exposed user contact details for around 890,000 Ricardo users. The source describes the cause as a security vulnerability, which SMG has since fixed. SMG also states that passwords remain safe, meaning account credentials were not part of the exposed data.

The source material is brief, so several specifics are not available to us. We do not have a full breakdown of which fields were exposed beyond "contact details," nor details on how long the vulnerability existed or whether anyone is known to have exploited it. We will stick to what has been confirmed and avoid guessing about the rest.

Why leaked contact details still matter

It is tempting to treat a leak without passwords as a minor event. In practice, names, email addresses, phone numbers, or similar contact information can be put to work quickly by criminals, even without access to an account.

The core risk is targeted phishing. A scammer who knows you use a particular marketplace can send a message that appears to come from that service: a warning about a suspended account, a problem with a payment, or a buyer asking you to confirm details through a link. Because the message references something real in your life, it feels more credible than a generic spam email.

Other risks include:

  • Smishing: fraudulent text messages that push you to tap a link or call a number.
  • Impersonation scams: messages pretending to be a buyer, seller, or support agent.
  • Data pairing: contact details can be combined with information from other leaks to build a fuller profile of a person.

None of this requires cracking a single password, which is why the "passwords are safe" reassurance only covers part of the picture.

How SMG responded and what remains unclear

SMG has fixed the vulnerability and says passwords were not compromised. Closing the hole quickly is the right first step. Still, several questions are not answered in the available reporting: exactly which data fields were involved, whether the data was accessed by malicious actors, and what direct notifications affected users will receive.

These gaps matter because they shape how worried an individual should be. Until more detail is published, the sensible approach is to assume that your contact information could be in circulation and act accordingly. Incidents like this also raise broader questions about how companies are held responsible for protecting personal data. For wider context on that topic, see how regulators have penalized data protection failures elsewhere, such as Brazil's ANPD fine against ByteDance.

What This Means For You

If you have or had a Ricardo account, treat yourself as a potential target for scam messages, even though your password was reportedly not exposed. You do not need to panic, but you should change how you handle unexpected communication that mentions the marketplace.

Steps to take now:

  1. Be skeptical of unexpected messages. Any email, text, or call that references Ricardo, your listings, or your account should be treated with suspicion, especially if it creates urgency.
  2. Do not click links in messages. Open the Ricardo app or type the website address yourself to check for any real notifications.
  3. Enable two-factor authentication (2FA) on your Ricardo account and on your email account, if available. This adds protection even if a scammer later obtains a password through other means.
  4. Use unique passwords. A password manager makes it practical to have a different password for every service, so one compromise never opens other doors.
  5. Never share codes or payment details with anyone who contacts you, even if they seem to know your details.
  6. Watch for follow-up notices from SMG and read them carefully, using only official channels to verify them.

Key takeaways

The Ricardo data leak phishing risk comes down to this: exposed contact details can make scams far more believable, even when passwords are untouched. SMG has patched the flaw, but many specifics remain unpublished. Treat unexpected Ricardo-related messages as suspicious, turn on 2FA, and keep your passwords unique. To understand how accountability for these failures is handled more broadly, read about the ANPD's enforcement action against ByteDance for context on what regulators expect from companies that hold your data.