Breaches · 145 days ago
Downloaded member profiles are enough to turn a retail breach into a targeting list. Names, addresses, phone numbers, email addresses, dates of birth, and gender can be used for phishing, SIM swap attempts, and identity fraud even when passwords and payment data were not taken.
Rituals says unauthorized access led to the download of some My Rituals member records earlier this month. The company says it contained the incident, notified affected members, and reported it to authorities; it would not confirm the number of people impacted, but My Rituals has more than 40 million members.
The immediate risk is not account takeover at Rituals. It is downstream abuse of the stolen personal data against members, and that risk persists after containment because the exposed dataset is already useful on its own.
3 sources covering this story
Luxury Cosmetics Giant Rituals Discloses Data Breach
The company is notifying My Rituals members that hackers downloaded part of their data, including names and addresses.
Cosmetics giant Rituals discloses data breach affecting customers
Dutch cosmetics giant Rituals disclosed a data breach after attackers stole the personal information of an undisclosed number of customers from its "My Rituals" membership database.
Cosmetics giant Rituals confirms data breach of customer membership records | TechCrunch
The cosmetics retailer, which counts 41 million customers in its membership data, declined to provide an accurate total number of customers affected.
Part of the PlainSec briefing for 2026-04-24