Looks like you're in the United StatesSet this as your default delivery country?
BigCommerce / Ribon Data Breach · September 2026 · times are UK time (BST)

What happened: a technical explanation

On Friday 18 September we emailed affected customers about a data breach at one of the companies whose software is connected to our front end. This page gives some technical details for anyone who wants them: what happened, when, exactly what information was involved and what wasn't, and what we have changed.

In short

  • Our front end runs on BigCommerce. Like most retailers, it has third-party apps installed, and each app is given an access key that lets it read or change data in BigCommerce.
  • An access key belonging to one of those apps, Ribon (made by "Be A Part Of", which describes itself as "a Fastr brand"), was stolen. On the evening of Sunday 13 September, the attackers subsequently used it to access personal information related to some of our customers.
  • No passwords and no card numbers were taken. Our front end does not store card numbers, and the stolen key could not reach passwords.
  • The key was revoked on Thursday 17 September. We found out about the breach from BigCommerce at 9:52am on Friday 18 September. We emailed customers and reported it to the Information Commissioner's Office (ICO) the same day.
  • We don't yet know how the key was stolen. The app's developer is continuing to investigate.

Timeline

  1. Sun 13 Sep, 6:21pm → 10:48pmSomeone used Ribon's stolen access key to download customers' personal data, working through them page by page.
  2. Wed 16 Sep, by 8:45pmThe app's developer became aware that Ribon's key had been misused. We were not told at this point.
  3. Thu 17 Sep, 10:12pmThe app's developer and BigCommerce switched off the stolen key and removed the Ribon app's access to our front end. The key has not worked since.
  4. Fri 18 Sep, 1:30amBigCommerce contacted us by email to inform us of the breach. The email was not marked as high priority and no effort was made to call us.
  5. Fri 18 Sep, 9:52amWe opened the email from BigCommerce and immediately started our own investigation of our front end access logs.
  6. Fri 18 Sep, 5:45pmWe began to email affected customers, and published masterofmalt.com/sorry to share future updates.
  7. Fri 18 Sep, before 6:55pmWe reported the breach to the ICO.
  8. Sat 19 SepWe tightened our own systems further (see What we have done to address this so far).

Why did it take several days for us to become aware of the breach?

The key that was stolen belonged to the Ribon app, not to us. Only the app's developer or BigCommerce could see that it was being misused, or switch it off. No alert reached us while the download was happening, between 6:21pm and 10:48pm on Sunday 13 September.

The app's developer was aware by 8:45pm on Wednesday 16 September, and the key was switched off at 10:12pm on Thursday 17 September. We were not aware of the breach until 9:52am on Friday 18 September, after the key had already been disabled. We emailed you and reported the breach to the ICO that same day.

We have asked the app's developer why the key was not switched off sooner, and why we were not told earlier. Our own new alerts (see below) mean that we would be alerted within minutes were ever any similar attempt in the future.

How was the key stolen?

We don't yet know how Ribon's key was stolen. The app's developer is investigating and has said it will share its findings. We'll update this page when we know more.

What information was taken

The key was used to download personal customer information, which included the following (depending on what was entered by that customer):

Customer personal information

  • name
  • email address
  • phone number, if you gave one
  • address

What was NOT taken

  • Passwords. The key had no access to them.
  • Card numbers, expiry dates or security codes, as we do not store these. We only store payment method tokens for our payments platform, Braintree.
  • The list of products in each order. Those are held separately and were not downloaded.
  • Delivery addresses, where they were not the same as the billing address, were not accessed.

Card payments

We do not store card details, so they could not be downloaded. When you pay by card, your card details go directly to our payment provider, Braintree, through a secure form on our checkout that is separate from our website.

If you notice a card payment you don't recognise, please contact your bank as you normally would. A large number of people receive fraudulent card attempts for reasons unrelated to any one website.

What this means for you

The main risk from the information taken is convincing scam emails, texts or calls that use your name, phone number or address.

  • We will never ask for your password or card details by email, text or phone.
  • Be wary of any message that asks you to click a link, "confirm" details or make a payment.
  • If in doubt, contact us using the details on masterofmalt.com/contact-us rather than replying to the message itself.

What we have done to address this so far

Some of these are already done and some are in progress:

  1. Ribon removed. The Ribon app has been uninstalled from our front end.
  2. Every other app. We are now auditing every other app with access to BigCommerce to assess and restrict their permission scope.
  3. Alerts on unusual access. We've implemented a system to alert us when there is unusual access. We now get an immediate alert if any key attempts to download customer data in bulk, is used from a new network, or attempts to make changes to the website's content or settings. We also get an alert when the website's admin area is used from an unusual location or a new app is opened or installed.
  4. Script changes. We've added automated auditing and alerting if anyone attempts to add or change any scripts.