Master of Malt Confirms Customer Data Breach in Supply-Chain Attack on BigCommerce
One of the most trusted names in online spirits retail has been caught in the crossfire of a sophisticated supply-chain cyberattack. Online spirits retailer Master of Malt suffered a supply-chain breach after its e-commerce provider BigCommerce was compromised through a vendor-side attack on Ribon Applications. For the hundreds of thousands of whisky enthusiasts, bourbon collectors, and spirits aficionados who rely on the Kent-based company to stock their shelves, the news lands with an uncomfortable thud — not because their credit cards were compromised, but because the attack illustrates just how exposed everyday consumers can be when the software running their favorite online store is itself the weak link.
Headquartered in Tonbridge, Kent, Master of Malt is an online spirits retailer and independent bottler specializing in whisky, gin, rum, and other fine spirits. The company has built a global following over decades by offering an exhaustive catalog of single malts, rare bourbons, craft gins, and proprietary bottlings under its own label. Its customer base skews toward the enthusiast — the guy who has a dedicated whisky shelf, who trades notes on online forums, who orders direct from the source. That demographic trusts Master of Malt with their personal details and, until this week, had little reason to think twice about it.
How the Attack Unfolded: A Stolen Key Opens Multiple Doors
The mechanics of the breach are worth understanding carefully, because they speak to a much broader vulnerability baked into how modern e-commerce functions. Master of Malt has disclosed a customer-data breach after attackers compromised an application key associated with Ribon, a third-party BigCommerce application operated by Be A Part Of, a company describing itself as a Fastr brand. To the uninitiated, that sentence is dense. Unpacked, it means that the attack never touched Master of Malt's own systems directly — instead, it exploited the trusted relationship between the retailer's storefront and a third-party software product that the retailer had integrated into its platform.
Modern e-commerce platforms rely heavily on third-party applications to provide specialized functionalities, from loyalty programs to advanced marketing analytics. To operate, these applications require API keys or access tokens that grant them permission to interact with a merchant's storefront and backend database. Ribon is — or was — one such application. Attackers obtained API credentials belonging to Ribon, a shopping experience optimization app, and used them to query customer data stored inside BigCommerce merchant accounts. Once they had that key, the door to customer records swung open without any further hacking required.
The Precise Window of Exposure
The timeline Master of Malt has disclosed is striking in its specificity. The company said attackers used the stolen Ribon application credential to access customer information stored in BigCommerce from 17:21 BST on September 13 to 21:12 BST on September 17, when the compromised key was revoked. That is nearly four full days of unauthorized access — a window long enough to methodically harvest records at scale. The clock, in other words, was not in the victims' favor.
BigCommerce notified the retailer of the incident on September 18, 2026, prompting Master of Malt to reach out to affected customers within hours. In an email sent to affected customers at 17:45 BST on September 18, founder Justin said BigCommerce notified the retailer earlier that day that Ribon had been hacked. The speed of Master of Malt's customer notification — the same day it received the alert — stands out as a point of genuine credit in a landscape where breached companies routinely delay disclosures for weeks or months. Master of Malt said it sent notifications within hours of BigCommerce informing it about the issue. The company said its staff immediately began auditing internal systems and identifying customers whose information might have been exposed, a process that took several hours.
What Was — and Was Not — Taken
The exposed information included customers' names, email addresses, telephone numbers, and physical addresses. On its face, that might sound like a limited haul. No passwords. No credit card numbers. No payment data. Master of Malt confirmed that attackers did not access passwords, card details, or other payment information, as that data is stored in a separate, unbreached system.
But security professionals — and anyone who has spent time thinking about how criminals actually operate — know that contact data is far from harmless. Having your name, address, email, and phone number could help a scammer build a much more convincing picture of who you are. A fraudulent email or phone call that already knows your name and address can be harder to spot than a generic scam. For Master of Malt's customer base specifically, that contextual richness makes the data especially valuable to bad actors. A phishing email that references a recent bottle purchase, addresses the recipient by name, and includes their correct home address is the kind of thing that fools even careful people.
The retailer clarified that the breach predominantly affected customers who had signed up for specific promotional campaigns managed through the compromised application. That detail matters: it suggests the breach may not cover every person who has ever purchased from the site, but rather those who interacted with Ribon-driven features — a subset that could nonetheless run into the tens of thousands.
The Ribon Connection: A Third-Party App at the Center of a Multi-Merchant Storm
The most alarming dimension of this incident is not what happened to Master of Malt specifically, but what the Ribon compromise may mean for the wider ecosystem. The disclosure suggests a potential multi-tenant supply-chain breach affecting other merchants using Ribon. Master of Malt said it had not yet seen public breach notifications from other potentially affected companies, despite the application reportedly being deployed on hundreds of stores.
That is a significant gap. If Ribon held a single application key capable of querying customer data across every storefront on which it was installed, then the theft of that key is not a single-retailer problem — it is a sector-wide exposure event. Once the attackers obtained the app's access key, they could query customer data in BigCommerce through the application's authorized access. This incident underscores the risks of third-party e-commerce integrations, where a single application credential can grant broad access across multiple merchant environments.
Master of Malt reported that it received its first direct confirmation from Fastr, the owner of Ribon, at 18:55 BST on September 18. At the time of disclosure, the retailer said it had not seen public breach announcements from other potentially affected businesses. Neither Be A Part Of nor Fastr had publicly acknowledged the incident when SecurityWeek and BleepingComputer published. The silence from Ribon's parent company — while one of its customers was actively sending breach notifications and filing regulatory reports — is a stark contrast that speaks for itself.
BigCommerce: Platform Infrastructure Under Scrutiny
BigCommerce is an e-commerce platform relatively similar to Shopify. Businesses use it to build and operate online stores without needing to develop the entire commerce infrastructure themselves. It offers features like storefronts, shopping carts, integrations with different payment providers, product inventories, SEO and marketing tools, and more. For merchants of Master of Malt's size and specialty, BigCommerce represents the practical backbone of the entire business — the system through which every order is processed, every customer record is maintained, and every integration is managed.
BigCommerce says account passwords and payment card information are stored separately and were not exposed, and that its own platform was not breached. That defense is technically defensible — BigCommerce's core infrastructure held up, and the attack exploited a third-party application's credentials rather than any native vulnerability in the platform itself. But the distinction may ring hollow to merchants and customers who reasonably expected the platform's app ecosystem to meet minimum security standards before gaining access to live customer data.
Master of Malt has made clear it intends to push BigCommerce to do better. According to information shared by BigCommerce, Ribon suffered a security breach between September 13 and 17 after threat actors used a compromised application key. "We will be working with BigCommerce to ensure that they implement more granular access control via their API, as no 3rd party application should have been able to access customer data in this way," Master of Malt added. The company believes no third-party application should be able to access customer records this way, especially since compromising one app key could expose numerous stores.
The API Permissions Problem
The technical argument Master of Malt is making is a familiar one in cybersecurity circles: the principle of least privilege. Every third-party application that connects to a platform should only hold permissions for the specific data it actually needs to do its job. Each unused app with a customer scope is dormant liability. Review scopes on the apps you keep. An app that only needs to read product data should not hold customer access. When a marketing optimization tool like Ribon is granted broad access to full customer profiles — names, addresses, phone numbers — the permission model has almost certainly exceeded what the application's core function demands.
This is not a new argument, but it is one that the e-commerce industry has been slow to act on. Platform operators have a commercial incentive to make app installation as frictionless as possible. Security friction — narrowing scopes, requiring justification for elevated permissions, auditing third-party credential hygiene — costs adoption. The bill for that trade-off is now being sent to Master of Malt's customers.
Regulatory Response and Legal Exposure
Master of Malt moved quickly on the regulatory front as well as the customer notification side. The retailer confirmed that it reported the incident to the UK Information Commissioner's Office. It received the ICO case reference IC-569770-Y1R9 on September 19. Under UK GDPR — which remains in force post-Brexit through the Data Protection Act 2018 — companies are required to notify the ICO within 72 hours of becoming aware of a breach that poses a risk to individuals. Master of Malt's report, filed the day after notification, appears to fall within that window.
The legal machinery is already beginning to turn. Law firm Emery Reddy is calling for potential claimants to the incidents, saying that "several retailers" are currently notifying customers about data exposure related to the same underlying breach. The framing around "several retailers" is significant — it suggests that attorneys tracking the situation already have reason to believe the Ribon compromise extends well beyond Master of Malt's storefront alone, even if other companies have not yet gone public.
What Affected Customers Should Do Right Now
For anyone who has shopped at Master of Malt and received a breach notification — or suspects they might be affected — the practical guidance is straightforward but worth stating plainly. The combination of personal information that was exposed could potentially be used to make phishing emails, texts, or phone calls appear more convincing. Criminals armed with a victim's real name, home address, email, and phone number can construct targeted lures that would fool most people on a busy day.
Master of Malt urges customers to stay vigilant about unexpected calls, spam, and phishing attempts. That advice applies across channels: email, SMS, and voice calls alike. A message claiming to be from Master of Malt, a shipping carrier, or even a bank that references specific personal details should be treated with heightened skepticism. Do not click links in unsolicited messages. Do not confirm personal information over the phone in response to an inbound call. Navigate directly to the retailer's website if there is any doubt about the legitimacy of a communication.
In the meantime, Master of Malt also said BigCommerce notified it that the attack had been stopped and that there was no further risk of compromise. Master of Malt says the breach has been contained and there is no ongoing access to customer data. Those assurances cover the present state of the system. They do not, of course, undo the four days during which records were available to whoever was on the other end of that compromised credential.
The Bigger Picture: Supply-Chain Risk in the Spirits Industry
Master of Malt sits at an interesting intersection: it is a consumer brand beloved by serious enthusiasts, and it is also a digitally native retailer that has built its entire business model around an online storefront. That model has been spectacularly successful — the company's catalog depth, same-day dispatch, and competitive pricing have made it a genuine first-stop destination for spirits buyers across the English-speaking world. But it also means that the company's relationship with its customers is mediated almost entirely through technology, which is where the exposure lives.
The spirits and beverage retail sector, like most specialty retail, has accelerated its adoption of e-commerce infrastructure over the past several years. Third-party app ecosystems have grown alongside that shift, offering merchants everything from personalization engines to loyalty platforms to inventory management tools. Master of Malt plans to work with BigCommerce to advocate for more stringent API authorization controls. If successful, that advocacy could have ripple effects across every merchant on the platform — not just spirits retailers, but anyone who has integrated a third-party app and assumed, perhaps too casually, that the platform's app marketplace had done the security vetting for them.
The broader lesson is uncomfortable but clear. A compromised third-party application key has allowed hackers to access the customer databases of BigCommerce merchants, including UK spirits retailer Master of Malt, highlighting the persistent vulnerabilities of e-commerce supply chains. Every app installed on a merchant storefront is a potential vector. Every API credential that touches customer data is a target. And every retailer — from a sprawling global marketplace to a specialist whisky shop in Kent — is only as secure as its least-scrutinized integration.
A Note on Transparency
In the landscape of corporate data breach disclosures, Master of Malt's handling of this incident is notable for its candor and speed. In an email sent to affected customers at 17:45 BST on September 18, founder Justin said BigCommerce notified the retailer earlier that day that Ribon had been hacked. A founder sending a personal disclosure email — same-day, by name — is not the behavior of a company trying to minimize or bury an incident. It is the behavior of a company that understands its relationship with its customers is built on trust and is willing to absorb the reputational short-term pain of transparency to preserve that trust over the long term.
That stands in sharp contrast to the silence from Ribon's parent company. Master of Malt reported the incident to the UK Information Commissioner's Office and says Ribon was installed on hundreds of BigCommerce stores. With a footprint that large, the absence of any public acknowledgment from Be A Part Of or its Fastr brand is not an oversight — it is a choice, and one that the ICO and potentially the courts may have something to say about in the weeks ahead.
What This Means Going Forward
For whisky drinkers and bourbon enthusiasts who shop online — whether at Master of Malt or any number of comparable specialty retailers — this incident is a useful reminder that data hygiene is a two-way street. Retailers bear primary responsibility for vetting the tools they use and pushing platforms to enforce tighter access controls. But consumers can also take steps: using unique email aliases per retailer, being alert to unexpected contact that references real personal details, and knowing where to report suspicious activity.
For the broader e-commerce industry, the Ribon breach is another data point in an increasingly urgent argument about how SaaS platforms manage their app ecosystems. The breach highlights the importance of SaaS platforms and their customers tightly controlling third-party integrations. The model of open app marketplaces with broad permission scopes has served growth metrics well. It has served security less well. Master of Malt's experience — and the potentially hundreds of other affected merchants who have yet to speak publicly — may finally give that argument the weight it has long deserved.
The bottles on the shelf are fine. The single malts are undisturbed. But the data that connects a retailer to the people who buy those bottles is more fragile than anyone in the industry would like to admit, and the cost of that fragility is now landing in customer inboxes across the country.