Whisky merchant Master of Malt confirms customer data spilt

Attackers had four days to drink in names, addresses, emails and phone numbers 

Hackers have raided Master of Malt's customer database after a compromised ecommerce app gave them four days to help themselves to names, addresses, phone numbers, and email addresses.

The online booze retailer began notifying customers this week after learning that Ribon, an app connected to its BigCommerce store, had been compromised.

According to an email sent to customers, seen by , attackers got hold of a BigCommerce application key held by Ribon and used it to access customer data between September 13 and 17.

"I'm sorry to say that the attackers had access to your name, email address, phone number, and address," Master of Malt founder Justin Petszaft told customers.

Passwords, credit card details, and other payment information escaped the raid, with Master of Malt saying they are stored in a separate system that was not compromised.

Ribon is owned, managed, and operated by Be A Part Of, which Master of Malt says describes itself as a Fastr brand, a corporate family tree best tackled before the whisky.

Master of Malt said BigCommerce alerted it to the incident, telling the retailer that Ribon had been hacked. According to the notification, the attackers compromised an application key held by Ribon and were then able to use it to gain access to customer data.

Master of Malt said BigCommerce's security team uninstalled the affected app the same day and "assured us there is no ongoing compromise and no further customer data can be accessed."

has asked BigCommerce how many merchants and customers were affected, what access the compromised Ribon key provided, how it was stolen, and whether any other third-party applications were affected. We have not yet received a response.  

Master of Malt is now warning customers that the stolen information could be put to use in phishing emails, spam, and scam phone calls.

"Please be extra vigilant against potential phone calls, spam and phishing attacks targeting you using the stolen data, and question anyone asking you to click a link or share data," Petszaft said.

Master of Malt says it won't ask for passwords or payment details over email or phone, so anyone receiving such a request should treat it with suspicion and contact the retailer directly instead.

Master of Malt has also set up a page where it says it will publish additional technical details and further updates rather than repeatedly emailing affected customers.

For anyone caught up in the breach, the whisky might now be the least dangerous thing arriving from Master of Malt. ®

Updated at 11.21 UTC on September 23, 2026, to add:

A spokesperson at Big Commerce made contact after this article was published to say:

"On September 17, 2026, Commerce confirmed that API credentials belonging to third-party applications Ribon and Ribon 1.5, owned and operated by “Be A Part Of,” a Fastr company, had been compromised due to a Fastr system compromise.

"The credentials were used to inject malicious scripts into a small number of merchant storefronts. This was not a breach of Commerce systems or the BigCommerce platform. While the Ribon applications are third-party apps independently installed by the merchant where the relationship occurs between the merchant and the third-party application, Commerce acted in the best interest of our customers and their shoppers by uninstalling the application from affected stores to revoke the attacker’s access and limit harm, notifying affected merchants directly, and providing log data to support the developer’s own investigation."

Original source Whisky merchant Master of Malt confirms customer data spilt

Back to home