BigCommerce Data Stolen via Ribon Apps Hack
Attackers stole BigCommerce shopper data by abusing compromised Ribon application API credentials.
BigCommerce notified merchants that customer data was stolen after attackers compromised an application key for Ribon, a storefront app owned by Fastr company Be A Part Of. The key was used from September 13 to September 17, 2026, to download names, email addresses, phone numbers, and addresses until it was revoked. BigCommerce said credentials for Ribon and Ribon 1.5 were abused after a Fastr system compromise and that malicious scripts were injected into a small number of storefronts. The company said its own platform was not breached, uninstalled the apps from affected stores, and began merchant notifications on September 18.
- Attackers used a compromised Ribon API key from September 13 to 17, 2026.
- Stolen data included customer names, emails, phone numbers, and addresses.
- Ribon was installed on hundreds of BigCommerce stores.
- Malicious scripts were injected into a small number of merchant storefronts.
- BigCommerce says its platform was not breached and uninstalled the apps.
Full article447 words · extracted from securityweek.com · click to collapse
Enterprise eCommerce platform BigCommerce fell victim to a supply chain attack that led to customer data theft.
BigCommerce is a SaaS provider that enables merchants to build and manage online stores. It hosts the stores, provides backend tools, and handles server security.
Late last week, the company started notifying merchants that customer data was stolen after hackers compromised a BigCommerce application key held by Ribon, a storefront and shopping experience optimization app developed by Fastr-owned Be A Part Of.
The hackers used the key between September 13 and September 17 to access customer data, including names, email addresses, phone numbers, and addresses, UK spirits vendor Master of Malt notes in a technical write-up.
According to Master of Malt, the hackers downloaded customer data working ‘page by page’ until the compromised key was revoked on September 17, one day after the Ribon developers became aware of its misuse.
BigCommerce started notifying merchants of the incident on September 18, after the key had been disabled and the targeted Ribon applications uninstalled.
Advertisement. Scroll to continue reading.
“The attack was against Ribon, which was installed on hundreds of BigCommerce stores. Once the attackers compromised an access key from Ribon, they used it to access data held inside BigCommerce,” Master of Malt said.
BigCommerce, which provides support for over 1,200 third-party applications, has confirmed that the hackers compromised the Ribon application credentials.
“On September 17, 2026, Commerce confirmed that API credentials belonging to third-party applications Ribon and Ribon 1.5, owned and operated by “Be A Part Of,” a Fastr company, had been compromised due to a Fastr system compromise. The credentials were used to inject malicious scripts into a small number of merchant storefronts. This was not a breach of Commerce systems or the BigCommerce platform,” BigCommerce told SecurityWeek.
“While the Ribon applications are third-party apps independently installed by the merchant where the relationship occurs between the merchant and the third-party application, Commerce acted in the best interest of our customers and their shoppers by uninstalling the application from affected stores to revoke the attacker’s access and limit harm, notifying affected merchants directly, and providing log data to support the developer’s own investigation,” the company added.
It is unclear how Ribon was compromised and whether other entities were also affected, as neither Be A Part Of nor Fastr have publicly acknowledged the incident.
SecurityWeek has emailed both companies for additional information and will update this article if they respond.
Related: CrowdSec Confirms Source Code Stolen in Supply Chain Attack
Related: 23 Million User Records Compromised in Gyazo Data Breach
Related: Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
Related: First Agentic AI Data Breach Reported to Spanish Regulator