Threat Intelligence Brief
Curated summary with source attribution
Source: ryde-technology.com
Threat Risk: Medium
Victim: Ryde Technology customers
Incident: Unauthorized access and exfiltration of customer PII and partial payment data.
Impact: Exposure of personal identity information and payment history for all registered users.
Attacker: Unidentified threat actors
Analysis: Threat actors successfully accessed Ryde’s systems to exfiltrate PII and partial payment data for all account holders. While full credit card numbers remain secure, the stolen payment history allows attackers to craft highly convincing social engineering lures. The company has responded by rotating keys and notifying Norwegian authorities.
Recommendations: Be wary of unsolicited communications referencing specific past payment details.; Avoid clicking links in SMS or emails claiming to be from Ryde.; Never share passwords or multi-factor authentication codes with any party.
Source: Ryde Technology
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source