4.5M Ryde accounts affected in latest data breach
All Ryde accounts in Norway and elsewhere have been affected.

Image by Cybernews.
- Ryde says an unknown attacker breached all 4.5 million accounts across Norway and other countries.
- Stolen data included phone numbers, emails, birth dates, partial card numbers, and payment history.
- Ryde says ride history and full card numbers were not exposed, and users don't need to block their cards.
- The company warns criminals may use real payment details to create more convincing phishing attacks.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Ryde, an electric scooter company operating in the Nordics, has announced that all of its account holders – around 4.5 million of them – have been affected by a data breach.
“An unauthorized party gained access to our systems and copied certain information relating to our customers. This affects everyone who has an account with us,” the company said in a press release.
The breach occurred on Sunday, August 2nd. The hacker's access to the systems was then blocked, but the crook managed to nab data from all customer accounts.
They stole information such as phone numbers, email addresses, dates of birth, and partial payment card numbers. Data about the customers’ payment history was also copied.
Has your password leaked?
In total, the company estimates that approximately 4.5 million accounts in Norway, Sweden, Finland, and Germany may have been affected by the data breach. Ryde admits it currently has no indication of who’s behind the attack.
Still, the company urges calm. In the press release, Ryde says, “Apart from the location where you created your account, no other location data has been extracted, such as your ride history. There are therefore no indications that data relating to where you have traveled has been affected.”
“You do not need to do anything with your account, and you do not need to block your card. Full card numbers are not held by us, but by our payment provider,” the company adds.
However, Ryde warns its customers that a party that has obtained information through a data breach may contact them and use it in a phishing attack, for instance, by referring to a payment they actually made.
Instead of sending random spam, criminals can personalize their attacks using details obtained from the breach.
“Never share your password, one-time banking codes, or BankID credentials with anyone who contacts you, regardless of how much they appear to know about you. Neither we nor your bank will ever ask for this information,” states the press release.
Indeed, databases containing personal details, account information, or communication records can become valuable resources for criminals operating phishing operations and fraud networks.
Instead of sending random spam, criminals can personalize their attacks using details obtained from the breach.
For example, they can end fake password reset emails, pretend to be customer support representatives, create fraudulent payment requests, attempt account recovery attacks, or combine leaked data with information obtained from older breach databases.