[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f4erTOnHcEPHolHxQ9XkvyH6BPpHg5gB29vWdaICAmWo":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":25,"source":26,"isVerified":4,"isSpamList":27,"isSensitive":27,"severity":28,"processingStatus":29,"logoUrl":30,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a6689037c2e981a36be98ef","Rituals2026","Rituals 2026 Data Breach","rituals-2026","rituals.com",{"name":12,"sector":13,"country":14,"website":10},"Rituals Cosmetics","Retail","Netherlands","2026-04-22T00:00:00.000Z","2026-07-26T22:24:03.286Z",0,[19,20,21,22,23,24],"Names","Physical addresses","Phone numbers","Email addresses","Dates of birth","Gender","\u003Cp>\u003Cstrong>The Rituals 2026 data breach\u003C\u002Fstrong> involved unauthorized access to the cosmetics company's My Rituals membership system and the download of some customer data. Rituals directly confirmed to SecurityWeek and TechCrunch that it detected and stopped the April 2026 access, contained the situation, and was informing affected members individually.\u003C\u002Fp>\n\u003Cp>The company did not publish an affected-person count, and the total size of the My Rituals program cannot be used as the breach scope. LeakData therefore shows the count as unknown. A zero value does not mean that nobody was affected; it means no verified total has been released.\u003C\u002Fp>\n\u003Ch2>Confirmed Types of Data\u003C\u002Fh2>\n\u003Cp>Potentially downloaded information included names, physical addresses, phone numbers, email addresses, dates of birth, and gender. Fields may differ by member, and the company did not say that every person had every item involved. The data classes in this record are limited to these six types named by Rituals.\u003C\u002Fp>\n\u003Cp>Rituals expressly stated that passwords and payment information were not compromised during the intrusion. Passwords, payment cards, and bank-account details are therefore excluded from the data classes. The combination of identity and contact details can still help an attacker write personalized messages that appear consistent with a membership profile.\u003C\u002Fp>\n\u003Ch2>Why My Rituals Members May Be Targeted\u003C\u002Fh2>\n\u003Cp>Loyalty programs can combine contact information, a birth date, and preferences in one profile. Although the confirmed Rituals scope contains no payment data, a real name, address, and phone number can make an impersonator appear credible. Messages about birthday gifts, member benefits, or free products may become especially convincing.\u003C\u002Fp>\n\u003Cp>The incident does not establish that every online-store customer or all of Rituals' more than forty million memberships were stolen. The company said only that some My Rituals members had data downloaded and that affected people would be contacted directly. People without a notice should not treat the program's total size as evidence that their own record was involved.\u003C\u002Fp>\n\u003Ch2>Company Response and Investigation\u003C\u002Fh2>\n\u003Cp>Rituals said it stopped the unauthorized access immediately after discovery and contained the situation. It began an in-depth forensic investigation to understand how the event happened and what controls were needed to prevent a recurrence. The company also reported the incident to the relevant data-protection authorities.\u003C\u002Fp>\n\u003Cp>At the time of disclosure, Rituals was not aware that the stolen information had been made public, and no known ransomware or extortion group had claimed responsibility. That does not identify the actor or remove the possibility of later misuse. This record does not add an unverified group name, leak count, or intrusion method.\u003C\u002Fp>\n\u003Ch2>Phishing and Fraudulent Promotions\u003C\u002Fh2>\n\u003Cp>Rituals users should watch for fraudulent messages about a “free gift,” “expiring loyalty points,” “birthday reward,” or “breach compensation.” Open rituals.com yourself instead of following the message link. Do not enter a password, payment card, bank information, or one-time code into a form reached through an unsolicited message.\u003C\u002Fp>\n\u003Cp>A sender who knows your real name, phone number, or birth date is not automatically Rituals. Inspect lookalike characters in the domain, avoid unexpected attachments, and verify an urgent payment request through a separate official channel. Report suspicious messages to official customer support with a screenshot and sender details.\u003C\u002Fp>\n\u003Ch2>Steps to Secure the Account\u003C\u002Fh2>\n\u003Cp>Because the company said passwords were not accessed, the event is not directly a password leak. If you entered a password on a fraudulent page using the breach as a lure, change the My Rituals password through the official site and create unique values on every other account that reused it. Review the account for unfamiliar changes to email, phone, or delivery addresses.\u003C\u002Fp>\n\u003Cp>Enable multi-factor authentication on email and phone accounts, and add a separate PIN to the mobile-carrier account to make number-porting fraud harder. If you receive an unexpected package, membership change, or profile-update notice, inspect account history without using its link. Since payment information was not affected here, seek verified risk guidance from the bank before unnecessarily replacing a card.\u003C\u002Fp>\n\u003Ch2>How to Interpret This LeakData Record\u003C\u002Fh2>\n\u003Cp>The zero shown for this record reflects the absence of a verified affected-person or row count from Rituals; it does not mean there was no impact. No My Rituals member rows were imported into LeakData, so the lack of an email-search result cannot override a direct company notice. Members who receive a notification should apply the published security guidance.\u003C\u002Fp>\n\u003Cp>This entry covers only the My Rituals membership-data incident disclosed in April 2026. The total size of the loyalty program is not used as the breach count, and passwords and payment information remain marked as unaffected. If Rituals later publishes a precise person count, incident date, intrusion method, or additional data type, the record should be revised only to match that verified information.\u003C\u002Fp>","Website hack",false,"Low","completed","\u002Fuploads\u002Flogo\u002Frituals_com.svg"]