CSIDB logo
Incident

Master of Malt

Incident posture

Attack window
Sep 2026
Location
United Kingdom
Status
Resolved
CIA posture
Available to members
Updated
2026-09-25 07:17

Linked entities

Victim
Master of Malt
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Sep 2026
Discovered
Undetermined
Disclosed
Undetermined
Resolved
Sep 2026

Summary

Master of Malt experienced a supply chain breach when threat actors exploited a compromised application key in the third‑party Ribon service integrated with its BigCommerce platform, gaining access to customer names, email addresses, phone numbers and physical addresses for roughly 100 hours. The company confirmed that passwords, payment card details and other financial data remained secure as they are stored separately, and it reported the incident to the UK Information Commissioner’s Office while noting that the attack was not directed specifically at it but resulted from a broader compromise of Ribon across multiple BigCommerce stores.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

Master of Malt, an online spirits retailer headquartered in Tonbridge, Kent, relies on the BigCommerce cloud e‑commerce platform for its online operations. In late September 2026 the company received an email from BigCommerce informing it that the third‑party application Ribon, owned and operated by Be A Part Of (which describes itself as a Fastr brand), had experienced a data security incident. According to BigCommerce, threat actors used a compromised Ribon access key to gain entry to stored customer data between September 13 and September 17, 2026. The unauthorized access persisted for approximately one hundred hours before BigCommerce’s engineering and security teams disabled the compromised credential.

The data that was exposed included customers’ names, email addresses, phone numbers and postal addresses, but Master of Malt confirmed that passwords, credit card details and other payment information remained secure because they are stored in a separate system that was not affected. Master of Malt published a data security incident notice on its website and reported the breach to the UK Information Commissioner’s Office. In the notice the company urged recipients to be extra vigilant against potential phone calls, spam and phishing attacks that might use the stolen data and to question anyone asking them to click a link or share information. The notice also stated that Master of Malt would never contact customers to request payment details or passwords over email or phone and that any such communication should be treated as suspect.

Master of Malt stated that BigCommerce confirmed the attack was no longer ongoing and that the company itself had not been specifically targeted. The attackers had focused on Ribon, a third‑party application installed on hundreds of BigCommerce stores, and used the compromised access key to reach data within BigCommerce’s environment. As a response, Master of Malt said it would work with BigCommerce to implement more granular access controls via the API to prevent similar third‑party applications from accessing customer data in the future. The company indicated that it would continue to monitor the situation and cooperate with regulators and its e‑commerce provider.

Sources

Sources available to members: 1 source.

CSIDB