What is confirmed
According to Master of Malt's customer notice reviewed by The Register, attackers used an application key held by Ribon to access data between 13 and 17 September.
For that retailer, exposed fields include name, email, phone and address; it says passwords and payment details were stored separately. BigCommerce removed the affected app access.
What it means
Compromise of access granted to a third-party app does not establish that BigCommerce's core platform or every merchant store was breached.
Genuine purchase contact details can make fake delivery updates or payment requests more convincing.
What to do
If your store notified you, watch for order-related messages and open its account area by typing its address yourself.
Merchants: inventory third-party apps, revoke unused access and contact BigCommerce if you used Ribon or Ribon 1.5.
Use the related SecurCheck tool, then confirm important decisions with an official source.



