This is nasty, but an example of how to inform your customers properly (in the app, by text message, on the site), how to disclose and how to store payment methods (you store what you need and you fragment where credit card data is stored – nb it would have been better if they had fragmented the dob and address data as well into seperate databases and only retrieved it when necessary) and inform about the impact to customers.
[…] What happened?
During the night leading into Sunday, 2 August, we discovered that an unauthorized party had gained access to our systems and copied customer data. The unauthorized access was stopped shortly afterwards.
Our investigation is still ongoing, and the full scope of the incident has not yet been determined. We will update this page if additional information becomes available.
We have notified the Norwegian Data Protection Authority (Datatilsynet), reported the incident to the police, and are notifying affected customers.
What information was affected?
All customer accounts are affected. The specific information relating to you depends on what you have registered with us and may include your phone number, email address, date of birth, only the first six and last four digits of your payment card number, and, for a small number of customers, an unverified name and address, as well as your payment history for rides, purchases, and fees.
Apart from the location where you created your account, no other location data has been extracted, such as your ride history. There are therefore no indications that data relating to where you have travelled has been affected.
What should I do?
You do not need to take any action regarding your account, and you do not need to block your payment card. We do not store full payment card numbers; they are securely stored by our payment service provider.
The only thing we ask is that you remain vigilant. Anyone with access to the stolen information may contact you and appear credible by referring to a payment you actually made, including the correct amount, date, and the last four digits of your payment card.
Never share your password, one-time banking codes, or BankID credentials with anyone who contacts you, regardless of how much they appear to know about you. Neither we nor your bank will ever ask for this information.
If you are unsure, end the conversation and contact the company or your bank directly using a phone number you have obtained independently.
[…]
Source: Security Incident August 2026 | Ryde
Robin Edgar
Organisational Structures | Technology and Science | Military, IT and Lifestyle consultancy | Social, Broadcast & Cross Media | Flying aircraft

