:

RITUALS CONFIRMS DATA BREACH OF CUSTOMER RECORDS

SECURITY DESK1 MIN READ
WED, APR 22, 2026

■ AI-SUMMARIZED FROM 2 SOURCES ▸ TIMELINE

Cosmetics retailer Rituals has confirmed a data breach affecting its customer membership database. The company, which maintains records for 41 million customers, has not disclosed the exact number of individuals impacted.

Rituals disclosed the security incident involving its membership data, though specifics remain limited. The company declined to provide an accurate total of affected customers, citing ongoing investigation into the breach. With 41 million customer records in its membership system, the potential scale of exposure is significant. The retailer has not detailed what information was accessed, whether it includes personal details, purchase history, or payment data. The cosmetics giant has not announced specific remediation steps or notification timelines for affected customers. Security experts typically expect breached companies to offer credit monitoring and identity theft protection services. Rituals operates across multiple markets with a substantial customer base. This incident adds to a growing list of retail data breaches in recent years, highlighting ongoing security challenges in the e-commerce sector.

■ SOURCES

Bleeping ComputerTechCrunch

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Cybercriminals have transformed DDoS attacks into a polished, commercialized service complete with pricing tiers, customer support, and reseller programs. The DDoS-as-a-Service market has evolved from basic tools into sophisticated attack platforms.

YESTERDAYIndustry Desk

Microsoft faced backlash after threatening a security researcher with criminal investigation, reigniting debate over software vulnerability disclosure practices and corporate responsibility.

YESTERDAYSecurity Desk

Google is deploying Device Bound Session Credentials (DBSC) to all Chrome users, a security feature designed to prevent account takeovers by protecting session cookies from theft.

YESTERDAYIndustry Desk

Dutch authorities have dismantled a major botnet comprising 17 million infected devices and seized over 200 servers hosting the operation at a local provider.

YESTERDAYSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.