Last updated: 14:45 Sunday September 19th 2026
17:45 Friday September 18th 2026, email sent to all affected customers:
Hi,
Earlier today we received an email from BigCommerce (our eCommerce platform provider) advising us that one of their third party applications “Ribon” which is owned, managed, and operated by "Be A Part Of" which in turn describes itself as a “Fastr” brand had been hacked.
It looks like hackers were able to compromise a BigCommerce Application key held by Ribon, which they were able to use to gain access to customer data held on their system.
The breach occurred between Sunday September 13th 17:21 BST and Thursday September 17th 21:12 BST when the stolen access key was revoked.
I’m sorry to say that the attackers had access to your name, email address, phone number, and address. However they were not able to access your password, credit card or other payment information as they are held in a separate system which was never compromised.
The security team at Big Commerce uninstalled the affected app yesterday (Thursday September 17th) and have assured us there is no ongoing compromise and no further customer data can be accessed.
I am so sorry that this has happened.
Please be extra vigilant against potential phone calls, SPAM and phishing attacks targeting you using the stolen data, and question anyone asking you to click a link or share data. We will never contact you to ask for any payment details or passwords over email or phone so please treat any email or phone call which claims to be from us asking for these details as suspect.
If you’re in doubt, email or call us using details from masterofmalt.com/contact-us/ - don’t hit reply; create a fresh email so you know it’s going to us.
I don’t want to bombard you with updates about this so we’ve set up a page at masterofmalt.com/sorry where we’ll post technical details and updates as they become available.
In the meantime, please let me know if you have questions, and I’ll do my best to come back to you as soon as I possibly can.
I apologise unreservedly.
Justin
Founder
17:50 Friday September 18th 2026
Just to confirm, as a number of people have asked - yes, we've already reported this to the ICO.
They've promised to get back to us within 7 days with a case reference number.
18:47 Friday September 18th 2026
We've received quite a few questions asking us why we took so long to address the issue, so I want to be super clear: we emailed everyone affected within hours of being notified of the breach by BigCommerce.
We did not sit on this for days.
The initial communication from BigCommerce made it clear that the attack was not ongoing, and there was no further risk, but we immediately undertook a full system audit and began identifying every customer that could have been affected.
Absolutely everyone was focussed on nothing but this, but even with the entire team it took several hours.
We got the email out to everyone as soon as we possibly could.
18:55 Friday September 18th 2026
We've finally received an email from the CEO of Fastr (who own Ribon) confirming they were compromised (our first contact from them).
11:32 Saturday September 19th 2026
We received a case reference number from the ICO: IC-569770-Y1R9
12:51 Sunday September 19th 2026
It’s now clear that we weren’t the target of the attack. The attack was against Ribon, which was installed on hundreds of BigCommerce stores. Once the attackers compromised an access key from Ribon, they used it to access data held inside BigCommerce.
We will be working with BigCommerce to ensure that they implement more granular access control via their API, as no 3rd party application should have been able to access customer data in this way.
None of this excuses what happened, and I feel absolutely terrible about it, but it does seem we were caught up in a much wider attack against BigCommerce using the application key stolen from Ribon.
So far, despite the fact that there must have been hundreds of companies affected by this, we haven’t seen any announcements from other companies that were affected.
14:45 Sunday September 19th 2026
We've published the technical details of our investigation into the BigCommerce / Ribon data breach at masterofmalt.com/sorry/technical/
