Ryde data breach exposes details from all customer accounts

Thursday 6th August 2026 on 16:00 in Finland

data breach, Ryde, scams

Personal data from all Ryde customer accounts was stolen in a data breach on August 2, and affected customers are being warned to watch for scam messages, Yle reports.

Deputy Data Protection Ombudsman Heljä-Tuulia Pihamaa said criminals could use the stolen information to send convincing messages. Customers who respond and, for example, authenticate using their online banking credentials could face further problems.

Criminals might also try to carry out legal actions in someone else’s name using the stolen data, Pihamaa said.

Ryde told Yle that the breach affects all of its customer accounts. The company has about 900,000 accounts in Finland, although one person may have several accounts. Ryde has notified customers through its app.

The stolen information includes contact details, dates of birth and parts of payment card numbers. Some customers also had information about their payment history exposed.

According to Ryde, the only location information copied was the location where an account was created. Other location data, such as journey history, was not taken.

Ryde has also warned that criminals may contact customers using the stolen information. A scammer could appear credible by referring to details about a customer, a genuine previous payment and the last four digits of a payment card.

“We will never ask you for your password, payment card details or security codes. We will also never ask you to log in through a link in a text message or email,” Ryde said in a statement.

The company said it had strengthened its systems to prevent further crimes and filed a police report.

Pihamaa said Ryde appeared to have acted as required by law by notifying the authorities and informing the affected individuals. The law requires companies to notify the authorities within 72 hours of detecting a data security breach.

People affected by the breach may seek compensation from Ryde under the General Data Protection Regulation. However, compensation amounts in previous cases have generally been modest, according to Pihamaa.

Source 
(via Yle)