BigCommerce Warns Merchants of Data Breach Linked to Ribon App Credentials
BigCommerce has warned multiple merchants about a data breach involving compromised credentials for the third-party Ribon application. Attackers used the credentials to access shopper information and inject malicious scripts into a small number of online stores.
The cloud-based software-as-a-service (SaaS) e-commerce platform confirmed the credential breach on September 17, 2026, and immediately removed the affected application from customer stores to block the attackers’ access.
Master of Malt says customer information was accessed
UK-based online spirits retailer Master of Malt was among the BigCommerce customers notified about the incident. The company said attackers accessed shopper data in the BigCommerce environment between September 13 and September 17.
According to Master of Malt, affected customer information may include:
- Names
- Email addresses
- Phone numbers
- Shipping addresses
“It appears that hackers were able to compromise the BigCommerce application key held by Ribon and used it to access customer data held on the system,” Master of Malt said.
BigCommerce says passwords and payment data were not compromised
BigCommerce supports more than 1,200 third-party applications and integrations, including Ribon. The application is operated by Be A Part Of, a brand operated by Fastr that focuses on optimizing online shopping experiences.
BigCommerce said that account passwords and payment card information are stored separately and were not compromised in this incident.
In a statement to BleepingComputer, BigCommerce said attackers compromised credentials for the Ribon and Ribon 1.5 applications.
“On September 17, 2026, Commerce confirmed that credentials belonging to third-party applications Ribon and Ribon 1.5, owned and operated by Fastr’s ‘Be A Part Of’, were compromised and used to inject malicious scripts into a small number of retail storefronts.”
The company emphasized that neither its systems nor the BigCommerce platform itself were compromised.
“In the best interest of our customers and their shoppers, we are disabling the attacker’s access by uninstalling the application from affected stores, directly notifying those merchants, and providing log data to support the developer’s investigation,” the company told BleepingComputer.
Retailer reports incident to UK privacy regulator
Master of Malt reported the incident to the UK Information Commissioner’s Office (ICO). The retailer said the breach could affect customers across hundreds of other stores using the Ribon application.
The law firm Emery Reddy is seeking potential claimants in connection with the incident. The firm said several retailers are currently notifying customers about data breaches related to the theft of the Ribon application key, but it did not identify those companies.
BleepingComputer contacted Be A Part Of and Fastr for additional information but had not received a response by the time of publication.
BigCommerce app breach resembles 2024 ZAGG incident
The incident is similar to a 2024 breach involving electronics accessories manufacturer ZAGG. In that case, attackers compromised a third-party FreshClick BigCommerce application and inserted payment-skimming code into the retailer’s online store.
BigCommerce said at the time that its platform was not compromised and that it had removed the affected applications from customer stores.
However, the two incidents involved different types of exposure. In the ZAGG breach, attackers obtained payment information entered by customers during checkout. In the Ribon incident, attackers used compromised application keys to access existing customer records through BigCommerce.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



