Rituals Member Data Downloaded in Breach

Downloaded member profiles are enough to turn a retail breach into a targeting list. Names, addresses, phone numbers, email addresses, dates of birth, and gender can be used for phishing, SIM swap attempts, and identity fraud even when passwords and payment data were not taken. Rituals says unauthorized access led to the download of some My Rituals member records earlier this month. The company says it contained the incident, notified affected members, and reported it to authorities; it would not confirm the number of people impacted, but My Rituals has more than 40 million members. The immediate risk is not account takeover at Rituals. It is downstream abuse of the stolen personal data against members, and that risk persists after containment because the exposed dataset is already useful on its own.

Part of the PlainSec briefing for 2026-04-24

Sources