An unidentified actor breached Norwegian micromobility provider Ryde's IT environment in early August and copied customer data affecting its entire reported user base of approximately 4.5 million accounts across Norway, Sweden, Finland, and Germany. Swedish Television reported that up to 1.3 million of the affected accounts belonged to users in Sweden. Ryde has not identified the attacker or disclosed the initial access method.
The exposed data includes phone numbers, email addresses, dates of birth, partial payment-card numbers, and, for some users, payment histories for rides and fees; journey histories were not affected. The data may enable Ryde-themed phishing and smishing, payment scams, credential stuffing, and targeted social engineering, particularly against organizations whose employees registered using corporate email addresses or reused passwords. Organizations should monitor for related phishing activity and credential-stuffing attempts against identity and remote-access services.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
In early August 2026, an unidentified actor accessed Norwegian micromobility company Ryde's IT environment and copied customer data. The breach affected Ryde's approximately 4.5 million-user customer base across its markets, including Norway, Sweden, Finland, and Germany.
Ryde said it closed identified access paths, rebuilt affected systems, and changed passwords and keys after the intrusion. The company also retained an independent security expert to review its security routines and processes while its investigation continued.
Norwegian data-protection authority Datatilsynet received a breach notification from Ryde concerning the incident.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
5 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcetruesec.com
Open sourcesvt.se
Open sourcedatatilsynet.no
Open sourceryde-technology.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.