ELSEIF
Your brief EB
442 stories from 214 feeds 1269 clusters Refreshed 4 minutes ago next pull 13:13

SECURITY Signal 449

BigCommerce app breach reportedly exposes Master of Malt customer data

Attackers accessed names, addresses, emails, and phone numbers of Master of Malt customers.

WHY IT MATTERS

This breach highlights vulnerabilities in third-party applications integrated into e-commerce platforms. Companies must ensure stringent security measures are in place to protect sensitive customer data. The incident also raises concerns about phishing risks for affected customers.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

Attackers had access to customer data for four days before the breach was discovered.

02

Sensitive information such as passwords and credit card details remained secure in a separate system.

03

Master of Malt is advising customers to be vigilant against potential phishing attempts using the stolen data.

THE READ

What the cluster adds up to.

ORIGINAL ANALYSIS

The breach involved attackers exploiting a compromised application key held by Ribon, an app connected to the BigCommerce platform. The unauthorized access lasted from September 13 to 17, during which personal information, including names, addresses, emails, and phone numbers, was accessed.

While the breach compromised customer data, sensitive financial information such as passwords and credit card details were not affected, as they are stored in a different, secure system. This separation of data storage is a critical aspect of data security that helped mitigate the impact of this incident.

Master of Malt has taken steps to notify affected customers and is actively advising them to be cautious of potential phishing emails and scam calls that may arise from the leaked information. The retailer's communication strategy includes setting up a dedicated page for updates, rather than relying solely on email notifications.

The incident underscores the necessity for e-commerce platforms and their third-party applications to maintain stringent security protocols. Companies need to regularly audit their integrations and ensure that sensitive data access is tightly controlled to prevent similar breaches in the future.

BigCommerce's quick action to uninstall the affected app indicates a responsive security posture, but the lack of information regarding the scale of the breach raises concerns. Understanding how the application key was compromised and whether other applications are at risk is crucial for restoring customer trust.

Written by elseif from the cluster below · checked for specifics the sources never contained

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
www.theregister.com - Articles BigCommerce app breach spills Master of Malt customer data Open ↗