Rituals, the Netherlands-based cosmetics retailer, confirmed that attackers accessed and downloaded data from its My Rituals membership database, exposing customer records across Europe, the United Kingdom, and some customers in the United States. The company said the stolen information may include full names, dates of birth, gender, postal and email addresses, phone numbers, preferred store, and account type, while stating that passwords and payment data were not accessed.
Rituals said it detected the unauthorized downloads in April, blocked the attackers' access, notified relevant authorities, and opened a forensic investigation. The company has not disclosed how the intrusion occurred, how many people were affected, or whether any ransom demand was made, though the loyalty program reportedly has more than 41 million members. Rituals also said it has not found evidence that the stolen data has been leaked online and has not attributed the breach to a known threat actor.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On or before April 22, 2026, Rituals publicly disclosed a breach affecting its customer membership records. The company said customers in Europe, the United Kingdom, and some in the United States were affected, but it did not reveal the total number of impacted individuals or attribute the attack to a threat actor.
After discovering the intrusion in April 2026, Rituals said it blocked the attackers' access, notified relevant authorities, and launched a forensic investigation. The company has not disclosed how the breach occurred and said its investigation remains ongoing.
Earlier in April 2026, Rituals discovered that attackers had conducted unauthorized downloads of customer data from its My Rituals membership database. The company said the compromised data included personal and account-related details, but not passwords or payment information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcebleepingcomputer.com
Open sourcetechcrunch.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.