惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 三生石上(FineUI控件)
博客园 - 叶小钗
博客园 - 聂微东
博客园 - 司徒正美
Hugging Face - Blog
Hugging Face - Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Google DeepMind News
Google DeepMind News
Recent Announcements
Recent Announcements
IT之家
IT之家
J
Java Code Geeks
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
I
InfoQ
爱范儿
爱范儿
Vercel News
Vercel News
Apple Machine Learning Research
Apple Machine Learning Research
阮一峰的网络日志
阮一峰的网络日志
博客园 - Franky
U
Unit 42
酷 壳 – CoolShell
酷 壳 – CoolShell
腾讯CDC
F
Fortinet All Blogs
V
Visual Studio Blog
人人都是产品经理
人人都是产品经理

Truesec

CRA Reporting Starts on 11 September: What Businesses Need To Know - Truesec Privilege Escalation Vulnerability in Falcon Crowdstrike - Truesec SonicWall Vulnerabilities Exploited in the Wild - Truesec Privileged Access Management (PAM) Is No Longer Optional  - Truesec Australian Arrests Allegedly Disrupt TeamPCP, but the Shai-Hulud Threat Persists - Truesec DDoS Attacks Against Norwegian Government Sites - Truesec Critical Citrix NetScaler Memory-Overflow Vulnerability - Truesec Iranian Cyberattacks Against Critical Infrastructure - Truesec Russia Targets Businesses and Officials Behind Europe’s Ukraine Defense Supply Chain - Truesec The World Is Moving at Machine Speed. Are We Ready? - Truesec False CVE in Overwhelmed Verification System - Truesec LLMjacking Is a New Cyber Threat - Truesec Rogue AI Agent Allegedly Hack Hugging Face - Truesec Microsoft SharePoint Server Vulnerabilities Actively Exploited - Truesec Russian Intelligence Targets SOHO Routers - Truesec Cyber Warfare in the Iran War - Truesec Organized Cybercrime Merging with Other Crime - Truesec AI Used in Ransomware Attack The Fortibleed Campaign: Truesec's Experience Fortibleed: Truesec's Experience Supply Chain Attack Compromising Arch Linux AUR Packages with Infostealer and Rootkit - Truesec FortiNet SSO Vulnerability CVE-2025-59718 and CVE-2025-59719 Leading to Full System Compromise - Truesec Critical Vulnerabilities in Ivanti Sentry Allows Code Execution as Root (CVE-2026-10520 & CVE-2026-10523) Typosquatting: When Your Domain Is Used Against You AI in Cybersecurity: Separating Operational Reality from Speculation Compromised @redhat-Cloud-Services Npm Packages Distribute Credential-Stealing Worm GitHub Hacks Highlights Need for Repository Security Installation of a Syslog Log Collector Critical Cisco Secure Workload Vulnerability Allows Unauthenticated Site Admin Access (CVE-2026-20223) Securing IT, OT, and IoT When the Digital Meets the Physical
The Ryde Data Breach - Truesec
Hjalmar Desmond · 2026-09-16 · via Truesec

Threat Insight

In early August 2026, an unknown actor accessed the IT environment of the Norwegian company Ryde, and managed to copy customer data. Ryde is a large micromobility company and provides electric scooters and e-bikes to countries across Northern Europe. [1]

The scale of the incident is notable as it affected Ryde’s entire user base of 4.5 million accounts. Users are located in Norway, Sweden, Finland, Germany and other Ryde markets. According to Swedish Television as many as 1.3 million of the affected accounts belonged to users in Sweden. [2]

Ryde states that the exposed data included phone numbers, email addresses, dates of birth, partial card numbers and in some cases also payment history for ride purchase and fees. Journey history was not included in the affected data. [1]
Assessment

As of today, no threat actor has been publicly identified, and Ryde has not disclosed how the intruder gained access. The incident is however in line with the pattern of opportunistic cybercrime activity that Truesec has observed in the past. Cybercriminals often steal personal data and resell it to other criminals that use them to fuel more criminal activities, such as fraud and new breaches.

A breach affecting a widely used digital service creates cascading risks beyond the initial attack.

  • The primary victim can suffer severe reputational loss as they must inform their customers that they have failed to protect their customer’s personal data. This can also expose them to potential GDPR fines.
  • The customers may be exposed to various forms of cyber fraud attempts, as cybercriminals attempt to weaponize their stolen private data.
  • Consumer breaches could also affect the victim’s employers. Employees may use corporate email addresses for private services such as mobility apps, online shopping, travel, and subscriptions, and some may reuse the same or similar passwords across personal and work accounts. If a data breach leaks corporate email addresses, attackers could also use it for credential stuffing, phishing, or targeted social engineering against their employer’s environment.

Recommendations

Organizations that handle large customer databases must understand that this data is highly valuable and a prime target for cybercriminals, even if it doesn’t include full credit card information or other payment information. This data needs to be protected.

Organizations that may have had employee’s account information leaked should use the Ryde breach as an opportunity to review and strengthen relevant security controls.

Phishing and Smishing Risk

  • Warn employees and customers about phishing that uses leaked personal or payment related information.
  • Monitor for Ryde-themed phishing, fake support messages, SMS fraud, refund scams, and payment-related social engineering.

Corporate Email Usage

  • Identify whether employees used company email addresses for Ryde or similar private services.
  • If corporate addresses appear in breach data, treat those identities as higher risk for phishing and credential stuffing.

Password Reuse

  • Remind employees not to reuse passwords across personal and work accounts.
  • Monitor for failed sign-in spikes, password spraying, and credential stuffing against Microsoft 365, VPN, SSO, SaaS, and remote access services.
  • Consider risk-based authentication or targeted password resets where exposure is confirmed.

Affected users that have had their personal data stolen in this breach should follow the following guidelines

  • Be alert to unexpected emails, text messages, or phone calls.
  • Do not click unfamiliar links, particularly those asking you to update payment information.
  • Keep evidence of suspicious contacts.
  • Report attempted fraud to the police.
  • Never sign in through a link received by SMS or email. [3]

If you or your organization have concerns about the topic above or need support, please reach out to your Truesec contact for further assistance.

References

[1] https://www.ryde-technology.com/security-incident-2026-08-02
[2] https://www.svt.se/nyheter/lokalt/norrbotten/efter-dataintranget-hos-ryde-sa-manga-berors-i-sverige
[3] https://www.datatilsynet.no/aktuelt/aktuelle-nyheter-2026/vi-har-mottatt-avviksmelding-fra-ryde/

Stay ahead with cyber insights

Newsletter

Stay ahead in cybersecurity! Sign up for Truesec’s newsletter to receive the latest insights, expert tips, and industry news directly to your inbox. Join our community of professionals and stay informed about emerging threats, best practices, and exclusive updates from Truesec.

Latest Insights