Master of Malt customer data exposed in BigCommerce app breach

Ribon app compromise gave attackers access to names, addresses, phone numbers and emails over four days

By LineZotpaper
Published
Read Time2 min
Online liquor retailer Master of Malt is notifying customers that their personal information—including names, addresses, phone numbers and email addresses—was stolen after a third-party app connected to its BigCommerce store was compromised. The breach, which occurred between September 13 and 17, did not expose passwords or payment details.

Master of Malt began alerting customers this week after learning that Ribon, an application integrated with its BigCommerce-powered online store, had been hacked. In an email seen by The Register, the retailer's founder Justin Petszaft stated that attackers obtained a BigCommerce application key held by Ribon and used it to access customer data over a four-day window.

The compromised information includes names, email addresses, phone numbers, and physical addresses. However, Master of Malt confirmed that passwords, credit card details, and other payment information were stored in a separate system that was not affected by the breach.

Ribon is owned and operated by Be A Part Of, which Master of Malt described as a Fastr brand. BigCommerce alerted Master of Malt to the incident, informing the retailer that Ribon had been compromised. According to the notification, BigCommerce's security team uninstalled the affected app on the same day and assured the retailer that "there is no ongoing compromise and no further customer data can be accessed."

The Register has reached out to BigCommerce for additional details regarding the number of merchants and customers impacted, the specific access the compromised key provided, the method of theft, and whether other third-party applications were affected. No response has been received as of publication.

Master of Malt is cautioning affected customers to remain vigilant against potential phishing emails, spam, and scam phone calls that could exploit the stolen data. The retailer emphasized that it will never request passwords or payment details via email or phone and urged customers to report any suspicious requests directly. A dedicated page has been set up for further technical details and updates, rather than sending repeated emails.

§

Analysis

Why This Matters

  • Affected customers face heightened risk of targeted phishing, spam calls, and identity theft using their personal details.
  • Highlights the supply-chain vulnerability introduced by third-party apps connected to e-commerce platforms like BigCommerce.
  • Raises questions about the security practices of app developers and the oversight provided by e-commerce platforms.

Background

Master of Malt is a UK-based online retailer specializing in alcoholic beverages, including whisky, gin, and rum. The company operates its store on the BigCommerce platform, a leading e-commerce service used by thousands of merchants worldwide. Third-party apps, such as Ribon, are commonly integrated to extend store functionality but can become attack vectors if their security is compromised. The breach occurred when an application key—a credential used to authenticate the app with BigCommerce—was stolen, granting attackers access to customer data.

Key Perspectives

Master of Malt / Justin Petszaft: The company acted promptly after being notified by BigCommerce, uninstalled the compromised app, and is transparently notifying affected customers while warning them about potential follow-on scams. BigCommerce: The platform alerted the merchant and uninstalled the affected app, but its response to further inquiries will determine how much responsibility it takes for third-party app security. Affected Customers: They are left with the burden of monitoring for phishing attacks and identity theft, with no indication of compensation or additional protective measures beyond vigilance.

What to Watch

  • BigCommerce's response regarding the scope of the breach and whether other merchants were affected.
  • Whether Master of Malt or affected customers face any resultant fraud or data misuse.
  • Potential regulatory scrutiny from UK data protection authorities (ICO) if the breach is found to involve inadequate security measures.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.