Whisky merchant Master of Malt confirms customer data spilt
Attackers had four days to drink in names, addresses, emails and phone numbers
Hackers breached Master of Malt's customer database after a compromised ecommerce app granted them access for four days. The online booze retailer notified customers this week after discovering the Ribon app, connected to its BigCommerce store, had been compromised. Attackers obtained a BigCommerce application key used by Ribon to access customer data between September 13 and 17.
Master of Malt founder Justin Petszaft apologized, informing customers their name, email, phone number, and address were compromised. Passwords, credit card info, and other payment details remained secure. The attackers used the stolen key to access customer data, which BigCommerce promptly addressed. They uninstalled the affected app and assured there was no ongoing compromise.
Master of Malt warns customers against potential phishing, spam, and scam calls using stolen data, advising suspicion of any requests for passwords or payment details. The retailer has established a page for further updates, replacing repetitive emails. BigCommerce confirmed the API credentials of third-party apps Ribon and Ribon 1.5, operated by "Be A Part Of," were compromised due to a larger Fastr system breach.
The attackers used the compromised credentials to inject malicious scripts into a few merchant storefronts, not affecting the BigCommerce platform.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.