BigCommerce alerts merchants of data breach linked to Ribon apps

· Original article ↗

Summary

BigCommerce disclosed that compromised credentials for the third-party Ribon and Ribon 1.5 applications were used to inject malicious scripts into a small number of merchant storefronts and access shopper data between September 13 and September 17, 2026. Master of Malt said exposed information included customer names, email addresses, phone numbers, and shipping postal addresses. BigCommerce said its platform was not breached and that account passwords and payment card data were not exposed.

Key points

  • Attackers compromised credentials and an application key associated with the third-party Ribon applications operated by Be A Part Of, a Fastr company.
  • The credentials were used to access customer records in BigCommerce environments and inject malicious scripts into some merchant storefronts.
  • Master of Malt confirmed exposure of full names, email addresses, phone numbers, and shipping postal addresses.
  • BigCommerce said account passwords and payment card information were stored separately and were not exposed.
  • BigCommerce removed the affected applications on September 17, notified affected merchants, and provided log data for the developer’s investigation.
  • Master of Malt reported the incident to the UK Information Commissioner’s Office and said the impact could extend to hundreds of other stores.
  • Be A Part Of and Fastr had not responded to BleepingComputer by publication time; legal representatives were seeking potential claimants.

Tags

Data BreachThird-Party RiskCredential CompromiseWeb Application SecurityE-commerce

Vendors

Products

Countries

Industries