Third-Party App Compromise Exposes Master of Malt Customer Data

AI-generated image · US National Wire
A security breach involving a BigCommerce application key allowed attackers to access personal information for customers of the online spirits retailer.
Online alcohol retailer Master of Malt has notified its customers of a data breach, as first reported by The Register, after attackers spent four days accessing personal information through a compromised ecommerce application. According to the report, the breach occurred between September 13 and September 17.
The incident centered on Ribon, an app connected to Master of Malt's BigCommerce store. Master of Malt stated that BigCommerce alerted the retailer to the event, explaining that attackers had compromised an application key held by Ribon. This key allowed the unauthorized party to access customer names, email addresses, phone numbers, and physical addresses.
Master of Malt founder Justin Petszaft informed customers that while personal contact details were stolen, payment information—including credit card details and passwords—remained secure because they are stored in a separate, unaffected system.
Regarding the corporate structure of the compromised app, Master of Malt noted that Ribon is operated, managed, and owned by Be A Part Of, which describes itself as a Fastr brand. BigCommerce's security team reportedly uninstalled the Ribon application on the same day the retailer was notified and provided assurances that no further customer data could be accessed and that there is no ongoing compromise.
Master of Malt is currently advising affected customers to remain vigilant against potential scams, phishing emails, and spam phone calls that may utilize the stolen data. Justin Petszaft warned customers to be suspicious of any requests to share data or click links, noting that the company will not request payment details or passwords via phone or email. The retailer has established a dedicated page to provide further technical updates to those affected.
The Register has reached out to BigCommerce for clarification on the total number of affected merchants and customers, the specific nature of the access provided by the compromised key, how the key was stolen, and whether other third-party applications were impacted, but the company has not yet responded.

