Rows of cosmetics bottles and skincare products arranged on shelves
Photo via Unsplash

TL;DR: Rituals, the Netherlands-based luxury cosmetics brand operating in 33 countries, confirmed on April 22, 2026 that hackers "unlawfully downloaded" personal data from its My Rituals membership database. The stolen data includes full names, home addresses, email addresses, phone numbers, dates of birth, and gender. Rituals says passwords and payment data weren't compromised. The company has 41 million members in its loyalty program but refuses to say how many were actually affected, citing "security reasons." Customers in at least five countries (the Netherlands, Belgium, England, France, and Germany) received breach notifications. This is the fourth major data breach hitting a Dutch company in three months, following Odido (6.2 million customers), Booking.com, and Basic-Fit.

What Rituals Confirmed

On April 22, Rituals started emailing members about what it called an "unauthorized download" of customer data from its My Rituals loyalty program database [1].

Here's what hackers got:

  • Full names
  • Home addresses
  • Email addresses
  • Phone numbers
  • Dates of birth
  • Gender
  • Account type and preferred store information

Rituals insists no passwords or payment information were accessed. The company says it "acted immediately to stop the access" once the breach was discovered [2].

But here's the part that should make you pay attention: Rituals has 41 million members in its My Rituals program. When asked how many were actually affected, the company said: "For security reasons, we are not currently making any statements about the numbers of members involved" [3].

That's corporate for "we either don't know or don't want to tell you."

Notifications Hit Five Countries

Breach notification emails went out to customers in at least five countries: the Netherlands, Belgium, England, France, and Germany [4]. Rituals operates in 33 countries across Europe, Asia, the Middle East, and the Americas, so the total scope could be wider.

The company reported the breach to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), as required under GDPR [3]. Rituals hasn't disclosed when the breach actually occurred or how long hackers had access before detection.

Rituals is also working with "external specialists" to monitor the dark web for any signs the stolen data has been published. So far, no cybercrime group has claimed responsibility, and the data hasn't appeared online [4].

That's the one piece of good news. The bad news is that dates of birth combined with home addresses, phone numbers, and email addresses make for a very effective phishing kit.

The Netherlands Has a Data Breach Problem

Rituals isn't an isolated incident. It's the fourth major breach hitting a Dutch company since January 2026:

  • Odido (January 2026): The Dutch telecom giant leaked personal data of 6.2 million customers, roughly a third of the Netherlands' population [3].
  • Booking.com (April 2026): Amsterdam-based travel platform confirmed hackers accessed reservation data including names, emails, booking details, and private guest-hotel messages. Scammers immediately weaponized the stolen data [5].
  • Basic-Fit (April 2026): Europe's largest gym chain, headquartered in Hoofddorp, exposed data of 200,000 Dutch members including bank account details. Total European impact hit 1 million members [3].
  • Rituals (April 2026): Up to 41 million loyalty members across 33 countries.

That's four Dutch-headquartered companies breached in three months. The Autoriteit Persoonsgegevens is going to be busy.

What Attackers Can Do With This Data

Rituals keeps saying passwords and payment details are safe. That matters less than they think.

With your full name, date of birth, home address, phone number, and email, attackers can:

  • Build convincing phishing attacks: An email mentioning your real name, birthday, and local Rituals store is far more believable than a generic "Dear Customer" blast
  • Attempt account takeover elsewhere: Date of birth is a common security question answer. Combined with your email and name, it's a password reset starter kit
  • Commit identity fraud: In many European countries, name + date of birth + address is enough to open utility accounts, apply for credit, or pass basic identity verification
  • Phone-based scams: Vishing (voice phishing) attacks that reference your name, birthday, and address are effective because they "prove" the caller is legitimate

Rituals warned customers to "remain vigilant against potential phishing attempts" [2]. That's good advice, but it puts the burden entirely on the people whose data Rituals failed to protect.

What to Do If You're a My Rituals Member

Assume Your Data Was Taken

Rituals won't say who's affected. If you have a My Rituals account in any of the 33 countries where Rituals operates, treat your data as compromised. Don't wait for a notification that may never come.

Watch for Targeted Phishing

Expect emails, texts, or calls that reference Rituals, your name, or your birthday. Real Rituals communications won't ask for payment details, passwords, or identity documents. When in doubt, contact Rituals directly through their website, not through any link in a message.

Change Passwords if You Reuse

Rituals says passwords weren't compromised. But if you used the same email and password combo on other sites, change those now. Use a password manager.

Monitor Your Identity

Your date of birth plus address is a powerful combo for identity fraud. Set up fraud alerts with your bank. In the Netherlands, check your credit report at BKR. In the UK, use the three credit agencies (Equifax, Experian, TransUnion). Watch for unexpected account openings or credit applications.

Questions Rituals Hasn't Answered

The company's disclosure is thin. Here's what we still don't know:

  • How many people were affected? "For security reasons" isn't an answer. Under GDPR, affected individuals have the right to know.
  • When did the breach happen? Rituals hasn't disclosed the timeline between initial compromise and discovery. That gap matters: it tells you how long attackers had access.
  • How did attackers get in? Was it a supply chain compromise? A credential theft? An unpatched vulnerability? Rituals hasn't said a word.
  • Was the data encrypted? If not, why was a 41-million-member database stored without encryption?
  • Were all 41 million members affected, or a subset? The company could narrow the scope without compromising security. They're choosing not to.

The Dutch Data Protection Authority now has the case. Given the scale (potentially tens of millions across the EU), this could trigger enforcement action, especially if Rituals delayed notification or stored data improperly.

References

  1. TechCrunch: Cosmetics giant Rituals confirms data breach of customer membership records (April 22, 2026)
  2. Bitdefender: Rituals cosmetics data breach 2026
  3. DutchNews.nl: Cosmetics chain Rituals hit in latest Dutch cyber attack (April 22, 2026)
  4. RetailDetail: Hackers steal customer data from Rituals (April 2026)
  5. BleepingComputer: Cosmetics giant Rituals discloses data breach affecting customers (April 2026)