Bleepingcomputer Rituals Cosmetics Confirms Data Breach of Customer Membership Information
Article Content
- •Rituals confirmed a data breach affecting its My Rituals loyalty program members.
- •Compromised data includes names, email addresses, and phone numbers, but not payment info.
- •The breach was discovered in April 2026, with no attribution to specific threat actors.
Rituals, a Dutch cosmetics company, has confirmed a data breach affecting its 'My Rituals' membership database. The breach was discovered in April 2026, when unauthorized downloads of customer data were detected. The compromised information includes full names, email addresses, phone numbers, dates of birth, gender, and postal addresses. While the company has not disclosed the number of affected customers, its membership program has over 41 million members, indicating a potentially large impact. No passwords or payment information were accessed during the breach. Rituals has initiated a forensic investigation and notified relevant authorities. The exact nature of the cyberattack remains undisclosed, and no group has claimed responsibility for the incident. Some affected customers are located in the United States, alongside those in Europe and the UK.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Rituals in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…