Rituals Data Breach: MyRituals Loyalty Records Stolen, Cards Safe

Rituals confirmed attackers downloaded MyRituals loyalty records — names, birth dates, addresses, phones — while passwords and card data stayed segmented. The lesson: a retailer's least-protected database is a ready-made phishing kit, and it sits in a year-long wave on European retail.

Share
A white perfume bottle icon with a neon purple data leak on a sand-colored background.

Rituals told its customers what was not taken almost before it told them what was: no passwords, no payment cards. That reassurance is true, and it is also the tell. The Dutch cosmetics chain has confirmed that attackers downloaded personal records from its MyRituals loyalty database, and the fields they got — full name, date of birth, home address, phone number, email, even your favourite store — are worth more to a competent scammer than a card number that a bank can cancel in a minute. This is the loyalty-data problem in one incident: the least-protected database in most retailers is a phishing kit waiting to be assembled.

What Rituals Actually Confirmed

Rituals disclosed the breach on 22 April 2026 in an email to affected members, after detecting an unauthorised download of loyalty data earlier that month. According to TechCrunch and BleepingComputer, the stolen records included full names, dates of birth, gender, postal and email addresses, phone numbers, plus each member's preferred Rituals store and account type. The company was explicit that no passwords and no payment or card details were accessed, saying those sit in a separate, more hardened environment.

What Rituals would not say is nearly as important as what it did. The MyRituals programme has more than 41 million members worldwide, and the company declined to give the number of people actually affected or a precise list of countries, citing security reasons. Reporting places the impact across Europe and the UK, with some US customers notified as well. Rituals says it has found no evidence yet that the data has appeared online, and that it has reported the incident to the relevant data-protection authorities.

  WHY A “HARMLESS” LOYALTY LEAK STILL HURTS
No card numbers were taken — but the record that was is a ready-made phishing toolkit.
WHAT LEFT THE DATABASE
Full name, date of birth, gender, home and email address, phone number, preferred store and account type.
PERFECT PERSONALIZATION FUEL
A real birth date, address and favourite store let an attacker write a message indistinguishable from a genuine Rituals email.
TARGETED PHISHING & SMISHING
“Birthday gift,” delivery or loyalty-points lures that quote true personal details to earn a click.
ACCOUNT TAKEOVER & FRAUD
Harvested logins and reused passwords open accounts elsewhere — no stolen card needed to monetise the victim.
Source: Rituals customer notification; TechCrunch and BleepingComputer reporting, April 2026.

No Attacker, No Vector — Yet

Two things the original wave of coverage did not establish, and neither has since: who did it, and how. No ransomware crew or extortion group has claimed the intrusion, and Rituals has declined to share attribution “for security reasons.” The entry point — a compromised credential, an exposed API, a third-party integration — has not been disclosed. Anyone telling you this was a specific gang systematically hunting Dutch brands is guessing; the honest status is unattributed and under investigation. That matters, because the defensive lessons here do not depend on knowing the culprit.

A Sector Under Sustained Fire

Rituals lands in the middle of a year-long run on European retail. In spring 2025, Marks & Spencer and Co-op in the UK lost customer membership records to ransom-motivated intruders; Harrods disclosed the theft of around 430,000 customer records in September 2025 and blamed a third-party supplier; and Adidas confirmed customer contact data was taken through a hacked third-party customer-service provider. The through-line is not a single actor. It is a business model: consumer-facing brands hold enormous, loosely governed piles of customer PII, and that PII has a liquid resale and fraud value even when no card data is involved.

My Read

Retail has quietly become one of the most reliably targeted sectors in Europe, and loyalty programmes are why. They are built by marketing to maximise reach — millions of records, wide internal access, long retention, light encryption — precisely the opposite of how you would design a system holding sensitive PII. Rituals did the hard part right: card data and passwords were segmented and survived. But the “soft” fields that leaked are the raw material for the attacks that actually hit consumers. A birth date and a home address do not enable a chargeback; they enable a convincing birthday-gift email or a fake delivery notice that a careful person will click. The 41-million-member headline also flatters the defender: a database that large is a strategic asset for an attacker, not a rounding error, and it should carry security controls to match.

The other half of my read is the supply chain. Rituals has not named a third party, but Harrods and Adidas both traced their 2025 breaches to vendors — and most retail loyalty stacks run on a sprawl of outsourced email, CRM, analytics and fulfilment platforms. If you are a retail CISO, the uncomfortable question is not only “is our database secure” but “which of our dozen marketing vendors could leak it for us.”

What Retail Defenders Should Do

The controls that would have blunted this incident are unglamorous and well understood:

  • Treat loyalty PII like the crown jewels it is. Apply the same encryption-at-rest, tight access control and monitoring to the marketing database that you already apply to the payment environment. The attacker went where the guard was lightest.
  • Minimise and expire the data you hold. You almost certainly do not need every member's date of birth, and you certainly do not need it forever. Every field you delete is a field that cannot leak.
  • Map and monitor your marketing vendors. Email, CRM, analytics and fulfilment partners hold copies of your customer list; inventory them, contract for breach notification, and watch their access the way you watch your own.
  • Make customer accounts phishing-resistant. Offer and encourage passkeys or MFA on loyalty logins, and alert on credential-stuffing, because reused passwords are how a PII leak becomes an account takeover.
  • Pre-write the customer warning. Tell members exactly which lures to expect — “birthday gift,” delivery, loyalty-points scams that quote real details — before the fraud starts, not after. Rituals did this, and it is the right move.

Open Questions

How many of the 41 million members were actually caught, and in which markets, is still undisclosed — as is the entry vector and whether any third-party platform was involved. It is also unresolved whether this was straightforward data theft or a failed extortion attempt that never went public. Until the data-protection authorities' findings or a criminal claim surface, treat the scale and the motive as open, and judge the response on the segmentation that worked rather than on numbers Rituals has chosen not to give.

Primary Documents