Observed Signal · Apr 22, 2026 · Data Breach · Source: techcrunch · Impact: 3/5 · Sentiment: Negative
Rituals confirms membership database data breach
Netherlands-based cosmetics retailer Rituals disclosed an unauthorized download of its membership database in April 2026, confirming a data breach that exposed customers’ personal information. The company said the stolen fields included full name, date of birth, gender, postal and email addresses, phone numbers, preferred Rituals store and account type. Rituals told TechCrunch the breach affects customers in Europe and the U.K., and confirmed some U.S. customers were also impacted. Rituals declined to provide a precise count of affected members or technical details of the attack while an investigation is ongoing. The company’s public materials state it holds over 41 million membership records and reported €2.4 billion in revenue for 2025.
A major retailer’s membership database compromise threatens first‑party customer data used for marketing and loyalty programs; it raises privacy, compliance and trust issues for retailers, MarTech vendors, and advertisers reliant on member data.
Track Co-op Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Rituals identified an unauthorized download of membership data in April 2026.
- Compromised data fields include full name, date of birth, gender, postal and email address, phone number, preferred store and account type.
- Rituals confirmed the breach affects customers in Europe, the U.K., and some customers in the United States.
- Rituals declined to disclose the exact number of affected members or the technical nature of the attack.
- Rituals reports over 41 million customers in its membership database and €2.4 billion revenue in 2025.
Connected Companies & Entities
1 Entity mappedRelated Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Series of Cyberattacks Hits European Retailers
A wave of cyberattacks has affected several European retailers, highlighting growing risks in digitally connected supply chains. Reported incidents include logistics disruptions at Dutch department store De Bijenkorf after an attack on an external logistics partner; a data breach at French group Intermarché affecting about 300,000 Click-&-Collect users (names, emails and contact details exposed; payment data and passwords reportedly not affected); and a compromise at Polish convenience chain Żabka via a third-party service account, giving attackers access to internal systems while store operations and payment systems remained functional. The cases underscore an increase in supply-chain attacks that exploit third-party vendors to bypass core defenses, prompting calls for broader security strategies across retailers and their supplier ecosystems.
Tenga: Hacker Stole Customer Information
Japanese sex-toys maker Tenga notified customers that an unauthorized party accessed a professional email account of one of its employees, exposing the inbox contents and potentially customer names, email addresses and historical correspondence — which may include order details or customer-service inquiries. TechCrunch obtained the notification email, which said the intruder also sent spam to the compromised account’s contacts. A forensic review communicated to TechCrunch found the breach affected approximately 600 people in the United States; it is unclear whether customers outside the U.S. were impacted. Tenga said it reset the employee’s credentials and enabled multi-factor authentication across its systems, and recommended customers change passwords and watch for suspicious emails. The company noted it has shipped over 162 million products worldwide. The report was first published Feb. 13 and updated with a Tenga spokesperson’s comment.
Revolut Data Breach Via Fake Government Requests
Revolut, Europe's largest neobank, suffered a data breach after attackers, using a stolen government email address, submitted fraudulent data requests. The company complied, exposing sensitive data of at least 700 customers, including a low double-digit number in Germany. Leaked information includes identity documents, contact details, account numbers, transaction histories, account statements, verification photos, and Bitcoin activities, posing identity theft risks. The attackers are demanding a ransom and have published some documents, threatening further leaks. High-profile victims include tennis player Alexander Shevchenko and entrepreneur Felix Römer. Revolut stated its systems and customer funds were unaffected and has alerted regulators. The UK Information Commissioner's Office (ICO) has opened an investigation. This follows a 2022 breach affecting 50,150 customers, underscoring ongoing security concerns. Revolut has over 80 million customers and a $115 billion valuation.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
