
BigCommerce app breach exposes Master of Malt customer data for four days
A compromised third-party app called Ribon gave attackers a BigCommerce application key and four days of access to the names, addresses, phone numbers and emails of Master of Malt customers.
Master of Malt, the online spirits retailer, has begun notifying customers after a compromised third-party app connected to its BigCommerce store let attackers reach customer records for four days. According to an email sent to customers and seen by The Register, the intruders obtained a BigCommerce application key held by Ribon, an app installed on the retailer's store, and used it to access personal data between September 13 and 17.
Four days of access to customer records
Master of Malt said BigCommerce alerted it to the incident and told the retailer that Ribon had been hacked. In that notification, BigCommerce said the attackers had compromised an application key held by Ribon and were then able to use it to gain access to customer data. The retailer says BigCommerce's security team uninstalled the affected app the same day and "assured us there is no ongoing compromise and no further customer data can be accessed."
"I'm sorry to say that the attackers had access to your name, email address, phone number, and address," founder Justin Petszaft told customers in the notification.
What was taken, and what was not
Passwords, credit card details and other payment information were not exposed. Master of Malt says those records are held in a separate system that was not compromised in the incident. The company has not said how many customers are affected. The Register asked BigCommerce how many merchants and customers were involved, what access the compromised Ribon key provided, how the key was stolen and whether any other third-party applications were affected; BigCommerce has not yet responded.
The third-party app problem
Ribon is owned, managed and operated by Be A Part Of, which Master of Malt describes as a Fastr brand. The case illustrates a familiar risk in ecommerce: a storefront platform can be secure while an app installed on top of it holds keys that unlock customer data. Once such a key leaks, the app's permissions become the attacker's permissions.
What customers are being told
Master of Malt is warning that the stolen information could be used for phishing emails, spam and scam phone calls. "Please be extra vigilant against potential phone calls, spam and phishing attacks targeting you using the stolen data, and question anyone asking you to click a link or share data," Petszaft said. The retailer says it will not ask for passwords or payment details by email or phone, and that anyone receiving such a request should treat it with suspicion and contact the company directly. It has also set up a page for further technical details and updates instead of emailing affected customers repeatedly.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.