BigCommerce Data Stolen via Ribon Apps Hack
Attackers stole BigCommerce shopper data by abusing compromised Ribon application API credentials.
BigCommerce notified merchants that customer data was stolen after attackers compromised an application key for Ribon, a storefront app owned by Fastr company Be A Part Of. The key was used from September 13 to September 17, 2026, to download names, email addresses, phone numbers, and addresses until it was revoked. BigCommerce said credentials for Ribon and Ribon 1.5 were abused after a Fastr system compromise and that malicious scripts were injected into a small number of storefronts. The company said its own platform was not breached, uninstalled the apps from affected stores, and began merchant notifications on September 18.