Skip to content
Rituals Cosmetics Confirms Data Breach of Customer Membership Information

Rituals Cosmetics Confirms Data Breach of Customer Membership Information

First seen 24 Apr 2026, 07:55 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •April 25, 2026 at 07:48 UTC
  • •Rituals confirmed a data breach affecting its My Rituals loyalty program members.
  • •Compromised data includes names, email addresses, and phone numbers, but not payment info.
  • •The breach was discovered in April 2026, with no attribution to specific threat actors.

Rituals, a Dutch cosmetics company, has confirmed a data breach affecting its 'My Rituals' membership database. The breach was discovered in April 2026, when unauthorized downloads of customer data were detected. The compromised information includes full names, email addresses, phone numbers, dates of birth, gender, and postal addresses. While the company has not disclosed the number of affected customers, its membership program has over 41 million members, indicating a potentially large impact. No passwords or payment information were accessed during the breach. Rituals has initiated a forensic investigation and notified relevant authorities. The exact nature of the cyberattack remains undisclosed, and no group has claimed responsibility for the incident. Some affected customers are located in the United States, alongside those in Europe and the UK.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 168d ago How this analysis works

Timeline

2026-04-01
Unauthorized downloads of member data detected.
2026-04-22
Rituals confirms data breach to customers.
2026-04-23
Rituals publicly discloses breach details.

More articles in this cluster (3)

Following this threat?

Track Rituals in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed