Hackers Abuse Stolen BigCommerce App Key to Steal Master of Malt Customer Data
Attackers used a stolen Ribon BigCommerce app key to access Master of Malt customer contact data.
Master of Malt said attackers used a stolen application key for Ribon, a third-party BigCommerce app owned by Fastr and managed by Be A Part Of, to read customer records. Access ran from 17:21 BST on September 13 to 21:12 BST on September 17, 2026, when the key was revoked; BigCommerce notified the retailer on September 18. Exposed data included names, email addresses, phone numbers, and physical addresses, but not passwords or payment details. The company reported the incident to the UK ICO under reference IC-569770-Y1R9 and said Ribon, used across many stores, appeared to be the primary target.
- A stolen Ribon app key accessed BigCommerce data from September 13 to 17, 2026.
- Exposed data included names, emails, phone numbers, and physical addresses.
- Passwords and payment card details were not accessed.
- Master of Malt notified the UK ICO under case reference IC-569770-Y1R9.
- The retailer says Ribon, used by many stores, was the likely primary target.
Full article597 words · extracted from gbhackers.com · click to collapse
Master of Malt reported a customer data breach after attackers allegedly compromised an application key linked to Ribon, a third-party BigCommerce app managed by Be A Part Of that identifies itself as a Fastr brand.
BigCommerce notified the retailer of the incident on September 18, 2026, prompting Master of Malt to reach out to affected customers within hours.
The company said attackers used the stolen Ribon application credential to access customer information stored in BigCommerce from 17:21 BST on September 13 to 21:12 BST on September 17, when the compromised key was revoked.
BigCommerce App Key Exploited
The exposed information included customers’ names, email addresses, telephone numbers, and physical addresses. Master of Malt confirmed that attackers did not access passwords, card details, or other payment information, as that data is stored in a separate, unbreached system.
“Attackers managed to compromise a BigCommerce application key held by Ribon, which they used to gain access to customer data in their system,” said Justin, the founder of Master of Malt, in a notification to customers.
BigCommerce removed the affected application on September 17, and the company assured Master of Malt that the compromise was no longer active. Master of Malt then conducted a full audit of its systems. He worked to identify all potentially affected customers before issuing their notification.
In a follow-up communication, the retailer clarified that it did not believe Master of Malt was the primary target. Instead, the incident appeared to target Ribon, which is installed across many BigCommerce stores.
Once the attackers obtained the app’s access key, they could query customer data in BigCommerce through the application’s authorized access. This incident underscores the risks of third-party e-commerce integrations, where a single application credential can grant broad access across multiple merchant environments.
Master of Malt reported that it received its first direct confirmation from Fastr, the owner of Ribon, at 18:55 BST on September 18. At the time of disclosure, the retailer said it had not seen public breach announcements from other potentially affected businesses.
Master of Malt plans to work with BigCommerce to advocate for more stringent API authorization controls. The company believes no third-party application should be able to access customer records this way, especially since compromising one app key could expose numerous stores.
The breach highlights the importance of SaaS platforms and their customers tightly controlling third-party integrations. Regularly review application scopes, rotate API credentials, and revoke unnecessary permissions. App credentials should be limited to the minimum data and actions necessary for their function, and unusual API activity should be monitored for signs of abuse.
Master of Malt has reported the incident to the UK Information Commissioner’s Office (ICO), which issued case reference IC-569770-Y1R9 on September 19.
Although payment data was not exposed, the stolen contact information could facilitate convincing phishing, spam, and phone-based social engineering campaigns. Attackers may impersonate Master of Malt, delivery providers, banks, or BigCommerce-related services, using customers’ addresses or order-related context to boost credibility.
Master of Malt has advised affected individuals to treat unsolicited requests for passwords, payment details, or link clicks as suspicious. The company emphasized that it will not ask customers to provide payment information or passwords via email or telephone.
They urged customers to use contact information found on the official Master of Malt website instead of replying directly to unexpected messages.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.