2026 Rituals — My Rituals membership database (names, contact, DOB, preferences; Apr)
Data compromised
Names, DOB, gender, contact details, store preferences, account type metadata—no payment credentials per company
Technical writeup
Dutch cosmetics and home-fragrance retailer Rituals confirmed unauthorized access to or download of data from its “My Rituals” loyalty and membership system in late April 2026, with media coverage (TechCrunch, BleepingComputer, SecurityWeek, and others) citing exposure of profile-oriented fields: full names, email addresses, phone numbers, dates of birth, gender, postal and home addresses, and store or preference-style metadata. Rituals publicly stated that passwords and payment-card data were not involved and described containment and member-notification steps; the firm did not always publish a single authoritative count of unique affected individuals in initial English-language summaries, while some outlets and social summaries floated figures on the order of ~41 million members for discussion—treat such headline numbers as unverified until regional regulators publish final totals. Affected or notified regions were described as spanning multiple European markets, the United Kingdom, and the United States—confirm per regional notices for definitive scope.
Root cause
Unauthorized access to / exfiltration of membership database (detailed intrusion chain not fully public in first press wave)
References
- https://techcrunch.com/2026/04/22/cosmetics-giant-rituals-confirms-data-breach-of-customer-membership-records/
- https://www.bleepingcomputer.com/news/security/cosmetics-giant-rituals-discloses-data-breach-affecting-customers/
- https://www.securityweek.com/luxury-cosmetics-giant-rituals-discloses-data-breach/
- https://www.rituals.com/en-gb/faq/data/