Skip to content
Unlisted Report logoUnlisted ReportSubscribe
Data Breaches

BigCommerce app breach exposes Master of Malt shoppers

Attackers stole a key for the Ribon BigCommerce app and accessed shopper names, emails, phone numbers and addresses at Master of Malt and other stores.

By · Published · Updated · 4 min read

BigCommerce app breach exposes Master of Malt shoppers

Shoppers at online spirits retailer Master of Malt and possibly hundreds of other stores have had their details exposed after attackers compromised a third-party app on the BigCommerce e-commerce platform, Mozbot reports.

What happened

  • Attackers stole an application key belonging to Ribon, which makes BigCommerce add-on apps.
  • Between 13 and 17 September, they used it to access shopper data and inject malicious scripts into storefronts.
  • BigCommerce confirmed the compromise on 17 September, uninstalled the Ribon apps and began notifying merchants on 18 September.

What was exposed

Full names, email addresses, phone numbers and shipping addresses. Passwords and payment cards were not exposed, because BigCommerce stores them separately. Master of Malt has reported the incident to the UK Information Commissioner's Office.

Why it matters

Online shops rely on dozens of plug-ins, each with its own keys to customer data. As WhiskeyPulse notes, the shop itself did nothing wrong — the weak link was software it trusted.

What shoppers should do

  • Expect phishing emails about orders or deliveries that use your real name and address.
  • Do not click links in unexpected "order problem" messages; log in directly instead.

Sources

Read next