BigCommerce app breach spills Master of Malt customer data
Attackers had four days to drink in names, addresses, emails and phone numbers
Hackers have raided Master of Malt's customer database after a compromised ecommerce app gave them four days to help themselves to names, addresses, phone numbers, and email addresses.
The online booze retailer began notifying customers this week after learning that Ribon, an app connected to its BigCommerce store, had been compromised.
According to an email sent to customers, seen by The Register, attackers got hold of a BigCommerce application key held by Ribon and used it to access customer data between September 13 and 17.
REG AD
"I'm sorry to say that the attackers had access to your name, email address, phone number, and address," Master of Malt founder Justin Petszaft told customers.
REG AD
Passwords, credit card details, and other payment information escaped the raid, with Master of Malt saying they are stored in a separate system that was not compromised.
Ribon is owned, managed, and operated by Be A Part Of, which Master of Malt says describes itself as a Fastr brand, a corporate family tree best tackled before the whisky.
Master of Malt said BigCommerce alerted it to the incident, telling the retailer that Ribon had been hacked. According to the notification, the attackers compromised an application key held by Ribon and were then able to use it to gain access to customer data.
Master of Malt said BigCommerce's security team uninstalled the affected app the same day and "assured us there is no ongoing compromise and no further customer data can be accessed."
The Register has asked BigCommerce how many merchants and customers were affected, what access the compromised Ribon key provided, how it was stolen, and whether any other third-party applications were affected. We have not yet received a response.
Master of Malt is now warning customers that the stolen information could be put to use in phishing emails, spam, and scam phone calls.
"Please be extra vigilant against potential phone calls, spam and phishing attacks targeting you using the stolen data, and question anyone asking you to click a link or share data," Petszaft said.
Master of Malt says it won't ask for passwords or payment details over email or phone, so anyone receiving such a request should treat it with suspicion and contact the retailer directly instead.
REG AD
Master of Malt has also set up a page where it says it will publish additional technical details and further updates rather than repeatedly emailing affected customers.
For anyone caught up in the breach, the whisky might now be the least dangerous thing arriving from Master of Malt. ®
KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.