Skip to main content
Back to overview
Medium

Rituals Cosmetics Confirms Data Breach of 'My Rituals' Membership Database

Dutch luxury cosmetics brand Rituals confirmed a data breach affecting its 'My Rituals' membership program.

Key points

  • Unauthorized download of customer membership records from 'My Rituals' database in April 2026.
  • Exposed data includes names, email addresses, phone numbers, dates of birth, gender, home addresses, and account details.
  • No passwords or payment information were compromised.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Confidentiality impact

Threat source not confirmed

03

Potential impact

Data Exposure

Confidentiality

Published
Apr 29, 2026
Updated
Jun 29, 2026
Confidence
Medium
Evidence
3 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch exposure paths that could affect data, operations or third-party trust.

Business impact

Potential data exposure
Impact area
Confidentiality
Likely asset
User or customer data, Server or cloud data store

Mentioned entities

RitualsData DisclosureMy RitualsRitualsAutoriteit PersoonsgegevensUnauthorizedExposed

Quick context

Questions about this signal

What happened in this signal?

Dutch luxury cosmetics brand Rituals confirmed a data breach affecting its 'My Rituals' membership program. An unauthorized party downloaded a portion of customer membership records in April 2026. The exposed data includes full names, email addresses, phone numbers, dates of birth, gender, home addresses, preferred store locations, and account types. Rituals emphasized that no passwords or payment information were compromised. The company detected and contained the incident, notified affected customers, and reported it to relevant authorities, including the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

When was this signal reported?

Shadow Tier lists Apr 29, 2026 as the signal date.

Which organization is connected to this signal?

Rituals is the organization connected to this public signal.

Explore Rituals
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence