Cosmetics giant Rituals confirms data breach of customer membership records

4 hours ago 1
The logo of the Rituals company, taken astatine  a Douglas store   connected  Jungfernstieg.Image Credits:Daniel Reinhardt / dpa / Getty Images

8:38 AM PDT · April 22, 2026

Netherlands-based cosmetics elephantine Rituals has confirmed a information breach affecting customers’ idiosyncratic accusation aft hackers stole reams of information from its rank database.

The institution disclosed the breach connected Wednesday, according to an email sent to customers that TechCrunch has viewed and verified. 

Rituals said it identified an “unauthorized download” of members’ information successful April that contained customers’ afloat name, day of birth, gender, postal and email address, and telephone fig arsenic good arsenic their preferred Rituals store, and relationship type.

When reached by TechCrunch, Rituals spokesperson Eline van Malssen said the hacker stole rank information astir customers successful Europe and the United Kingdom.

TechCrunch has learned that immoderate customers notified by Rituals are based successful the United States. The spokesperson confirmed the incidental besides affects immoderate U.S. customers.

Rituals did not picture the quality of the cyberattack and the institution said its probe was underway to recognize however the information breach happened. 

The cosmetics elephantine is the latest retailer to person lawsuit rank information stolen successful the past year, pursuing a drawstring of intrusions astatine U.K. market and buying chains Co-op and Marks & Spencer, among others. Customer records tin beryllium charismatic targets for hackers who bargain the information and extort the institution for a ransom successful speech for not publishing the accusation online.

When reached with questions astir the incident, a Rituals spokesperson declined to remark connected whether the institution received immoderate connection from the hackers, to stock a much precise timeline of the breach, oregon to supply the nonstop fig of affected members, citing unspecified “security reasons.”

According to its website, Rituals has implicit 41 cardinal customers successful its rank database. The retail elephantine made €2.4 cardinal euros ($2.8 billion) successful gross successful 2025.

When you acquisition done links successful our articles, we whitethorn gain a tiny commission. This doesn’t impact our editorial independence.

Zack Whittaker is the information exertion astatine TechCrunch. He besides authors the play cybersecurity newsletter, this week successful security.

He tin beryllium reached via encrypted connection astatine zackwhittaker.1337 connected Signal. You tin besides interaction him by email, oregon to verify outreach, astatine zack.whittaker@techcrunch.com.

Read Entire Article