The e-scooter company Ryde was hit by a data breach in the early hours of Sunday, August 2, 2026. All customer accounts are affected: around 4.5 million across four countries, including 1.6 million in Norway. Birth dates, phone numbers, email addresses, and payment histories have been compromised.

What happened in the Ryde data breach

Unauthorized parties gained access to Ryde's systems in the early hours of Sunday, August 2, and copied information for all customers. The breach was discovered the same morning, and access was closed shortly after.

Ryde rents e-scooters in Norway, Sweden, Finland, and Germany, and is one of the largest operators in Norway. If you ride such scooters, you should also know the rules for e-scooters in Norway.

The company says it has closed the breached systems, rebuilt the affected systems from scratch, and changed passwords and encryption keys. The incident has been reported to police and the Data Protection Authority (Datatilsynet), and customers have been notified directly. Chief Executive Tobias Balchen told news agency NTB that the company does not know who is behind the attack and that there have been no ransom demands or threats. However, Ryde cannot guarantee that the information has not been sold on.

What information has been compromised?

These are the pieces of information Ryde confirms were copied:

  • mobile number and email address
  • birth date
  • the first six and last four digits of payment cards
  • payment history for rides, purchases, and fees
  • name and address for a small number of customers (unverified information)

These are not compromised: full card numbers, which are held by an external payment provider and not by Ryde. The company also states there is no evidence that your ride history – where you have ridden – has been extracted. The only location information affected is where your account was created.

Why are "just a few digits" dangerous?

The danger lies in the combination, not in the card number alone. The first six digits show which bank issued the card. The last four digits are exactly the numbers banks and shops use to confirm your identity in a conversation.

Add a genuine payment history, and a scammer can call you, reference a ride you actually took – with the correct amount, date, and card digits – and sound completely credible. Ryde warns about this itself.

The rule that stops such attempts is the same, no matter how much the caller knows about you: neither Ryde, your bank, nor police ask for passwords, one-time codes, or BankID (your digital ID), and they never ask you to log in via a link in SMS or email. On SamfunnPrep you can find a guide to seven common scam tricks in Norway and a separate guide on BankID scams and phone pressure.

What should you do now?

  1. Don't click links in SMS or email that appear to come from Ryde or your bank. Open the app instead, or type the web address yourself.
  2. Hang up if someone calls asking for codes. Call your bank back using a number you find yourself.
  3. Review your bank statements over the coming months, and notify your bank immediately of any unfamiliar transactions.
  4. Consider a credit freeze. Birth date, name, and address are enough to attempt identity theft – see how you set up a credit freeze against identity theft.

You don't need to change your password in the Ryde app or freeze your bank card, according to the company itself.

What does the Data Protection Authority say?

The Data Protection Authority (Datatilsynet) has received a breach report from Ryde and is investigating the matter. "We have received a breach report from Ryde and are reviewing it," says Senior Adviser Eirik Gulbrandsen. The authority says it is primarily concerned with the follow-up of those affected, and then with what actually happened.

Under the General Data Protection Regulation (GDPR) Article 33, a business must report such breaches to the Data Protection Authority "without undue delay and, where possible, no later than 72 hours" after the breach is discovered. Article 34 requires that those affected are notified directly when the risk is high. The notification must describe the breach, the likely consequences, and the measures being taken.

As someone affected, you have two specific rights: access to see what information Ryde holds about you, and the right to file a complaint with the Data Protection Authority. The complaint form requires login with ID-porten; if you don't have that, you can send your complaint by letter to the Data Protection Authority, Postboks 458 Sentrum, 0105 Oslo. Processing time is on average around one year. SamfunnPrep has a separate article on access, correction, and deletion under GDPR.