Cosmetics giant Rituals confirms data breach of customer membership records
The cosmetics retailer, which counts 41 million customers in its membership data, declined to provide an accurate total number of customers affected.

Netherlands-based cosmetics giant Rituals has confirmed a data breach affecting customers’ personal information after hackers stole reams of data from its membership database.
Rituals said it identified an “unauthorized download” of members’ data in April that contained customers’ full name, date of birth, gender, postal and email address, and phone number, as well as their preferred Rituals store and account type.
Rituals did not describe the nature of the cyberattack and the company said its investigation was underway to understand how the data breach happened.
The cosmetics giant is the latest retailer to have customer membership data stolen in the past year, following a string of intrusions at U.K. grocery and shopping chain Co-op and Marks & Spencer, among others. Customer records can be attractive targets for hackers who steal the data and extort the company for a ransom in exchange for not publishing the information online.
When reached with questions about the incident, a Rituals spokesperson declined to comment on whether the company received any communication from the hackers, to share a more precise timeline of the breach, or to provide the exact number of affected members, citing unspecified “security reasons.”
According to its website, Rituals has over 41 million customers in its membership database. The retail giant made €2.4 billion euros ($2.8 billion) in revenue in 2025.



