Rituals Confirms European Customer Data Breach, Withholds Impact Numbers
Rituals says attackers accessed names, addresses, emails, birth dates and gender of European customers but has not disclosed how many were affected.

TL;DR Rituals confirmed a cyberattack that exposed personal data of some European customers, though it has not released the number of affected individuals.
Context
Rituals, headquartered in Amsterdam, operates over 1,500 stores in 33 countries and reported €2.4 billion turnover in 2025. The company recently detected unauthorized access to its systems, leading to a data exposure affecting customers across multiple European nations.
Key Facts
Attackers obtained names, physical addresses, phone numbers, email addresses, birth dates, and gender. Information linked to the MyRituals loyalty program—such as store preferences and account traits—was also taken. Rituals stated that passwords and payment card data were not compromised. The firm has not disclosed the scale of the breach, citing operational security.
What It Means
The stolen personal details are valuable for highly targeted phishing and social‑engineering campaigns, increasing the risk of credential theft and fraud. While financial data appears safe, the behavioral data enables attackers to craft convincing messages that reference recent purchases or store visits.
What Defenders Should Do
- Enable multi‑factor authentication on all customer‑facing accounts and monitor for anomalous login attempts (MITRE ATT&CK T1078). - Review web‑application logs for signs of credential stuffing or session hijacking (T1110). - Deploy email‑gateway rules that flag messages containing leaked personal details (T1566.002). - Advise customers to scrutinize unexpected communications requesting additional information or containing links, and to report suspected phishing.
Watch for any official update on the total number of affected records and for signs of the data appearing on underground markets.
Continue reading
More in this thread
NSW Government Declares Cyber Incident After Alleged Treasury Data Exfiltration
Peter Olaleru
NSW Government Confirms Treasury Data Breach, Police Recover Alleged Stolen Files
Peter Olaleru
Thai Police Arrest Indonesian Suspect in $10 Million Romance Scam Targeting Americans
Peter Olaleru
Conversation
Reader notes
Loading comments...