Monday, August 3, 2026

Markets & Business

Rituals confirms data breach of customer membership records

Cosmetics giant Rituals has confirmed a data breach involving an unauthorized download of membership data, affecting customers across Europe, the U.K., and the U.S.

Rituals confirms data breach of customer membership records
Photo: Rituals press kit

Netherlands-based cosmetics giant Rituals has confirmed a data breach affecting its customers’ personal information. The company disclosed the breach on Wednesday, following an incident in which hackers stole reams of data from the Rituals membership database. According to the company, Rituals identified an unauthorized download of members’ data in April. The downloaded data contained customers’ full names, dates of birth, gender, postal and email addresses, and phone numbers, as well as their preferred Rituals store and account type. Rituals spokesperson Eline van Malssen confirmed that the incident affects customers across Europe, the United Kingdom, and the United States.

The geographic scope of the breach was clarified in stages. Spokesperson Eline van Malssen initially stated that the hacker stole membership data about customers in Europe and the United Kingdom. However, after it was learned that some customers notified by Rituals are based in the United States, the spokesperson confirmed that the incident also affects some U.S. customers, expanding the known impact of the unauthorized download.

Rituals has over 41 million customers in its membership database. The Netherlands-based cosmetics giant reported €2.4 billion ($2.8 billion) in revenue in 2025. Customer records can be attractive targets for hackers who steal the data and extort the company for a ransom in exchange for not publishing the information online. The company has not disclosed the exact number of affected members from its database.

When questioned about the specifics of the cyberattack, Rituals declined to provide details on the nature of the attack or potential ransom demands. Spokesperson Eline van Malssen cited “security reasons” for the company’s decision to withhold further information, including a precise timeline of the breach or the exact number of affected members. The company has stated that its investigation is currently underway to understand how the data breach happened, though it declined to share a more precise timeline of the breach. The incident mirrors recent data thefts at other major retailers, as Rituals is the latest company to have customer membership data stolen in the past year, following a string of intrusions at U.K. grocery and shopping chain Co-op and Marks & Spencer, among others.

Why it matters

Rituals is the latest major retailer to suffer a membership data breach, highlighting a persistent trend of cyberattacks targeting customer databases at large shopping chains like Co-op and Marks & Spencer.