Description

Rituals has disclosed a data breach involving its “My Rituals” membership database, where attackers accessed and exfiltrated customer information. The incident was identified earlier this month after the company detected unauthorized downloads of member data. Following detection, Rituals promptly took action to contain the breach by blocking further access and initiating response procedures. The company stated that the compromised data may include personal details such as full names, email addresses, phone numbers, dates of birth, gender, and home addresses, depending on the information provided by users. However, Rituals confirmed that no passwords or payment-related information were accessed during the breach. At this stage, there is no evidence indicating that the stolen data has been publicly leaked or misused. Rituals has launched a comprehensive forensic investigation to determine the root cause of the incident and to strengthen its security posture. The organization has also notified relevant regulatory authorities and is directly informing affected customers. Due to security considerations, the company has not disclosed further technical details about the attack or any potential attribution, and no threat actor has claimed responsibility so far. The breach impacts members of the “My Rituals” loyalty program, which offers rewards, exclusive promotions, and special benefits. While the exact number of affected individuals remains unknown, the program has over 41 million members globally, suggesting a potentially large scope. Founded in 2000 in Amsterdam, Rituals operates in 33 countries with thousands of retail locations and reported €2.4 billion in revenue in 2025.