BigCommerce alerts merchants of data breach linked to Ribon apps
Attackers used stolen Ribon app keys to access BigCommerce shopper data and inject storefront scripts.
BigCommerce said credentials for third-party Ribon and Ribon 1.5 apps, operated by Be A Part Of (a Fastr brand), were compromised and used from September 13 to 17, 2026. Attackers accessed existing shopper records and injected malicious scripts into a small number of merchant storefronts. UK retailer Master of Malt said exposed data included names, email addresses, phone numbers, and shipping addresses, while passwords and payment cards were not affected. BigCommerce uninstalled the apps, notified merchants, and reported the incident may extend to other stores.
66