Hackers gained unauthorized access to a third-party application, leading to the exposure of customer data, including personal information such as names, emails, phone numbers, and addresses. The breach involved BigCommerce, an e-commerce platform similar to Shopify, and a third-party app called Ribon, which helps improve online shopping experiences. The attack occurred between September 13 and September 17, 2026, and affected multiple online retailers, including Master of Malt, a UK-based spirits retailer. The UK Information Commissioner’s Office (ICO), which oversees data protection laws, was informed of the breach, and a law firm has warned of potential phishing attempts targeting affected businesses and their customers. BigCommerce allows merchants to use third-party apps like Ribon to enhance their online stores. According to Master of Malt, the breach happened when cybercriminals gained access to a BigCommerce application key held by Ribon. This key was used to access customer data stored on the BigCommerce platform. The company confirmed that credentials for Ribon and a related version, Ribon 1.5, were compromised. These credentials were managed by "Be A Part Of," a subsidiary of Fastr, the company that owns Ribon. The attackers used the stolen credentials to inject malicious scripts into the online stores of a limited number of merchants. Master of Malt clarified that the attack specifically targeted Ribon, which is used by hundreds of BigCommerce stores. The hackers accessed customer data by exploiting a compromised access key from Ribon. However, the company emphasized that sensitive financial data such as passwords, credit card numbers, and other payment details were not exposed. These details are stored separately on BigCommerce’s system, which was not compromised in the attack. BigCommerce has taken steps to mitigate the breach by removing the Ribon application from affected stores to prevent further access by the attackers. The company also informed the affected merchants directly and provided them with log data to assist in the investigation. Master of Malt was notified that the breach had been contained, and there is no ongoing risk of further data exposure. A law firm, Emery Reddy, is now reaching out to potential affected parties, as several retailers are informing their customers about the data breach. The firm has also issued a warning about the possibility of phishing and scam attempts targeting individuals whose data may have been exposed.