BigCommerce shopper data stolen via compromised Ribon app credentials
Attackers abused a stolen Ribon application key from September 13 to 17, 2026, to download customer contact data from BigCommerce stores and inject malicious storefront scripts; BigCommerce says its own platform was not breached.
BigCommerce notified merchants that customer data was stolen after attackers compromised an application key for the third-party storefront apps Ribon and Ribon 1.5 following a compromise of a Fastr system. The key was used from 17:21 BST on September 13, 2026, until it was revoked at 21:12 BST on September 17, 2026, to read existing shopper records. Stolen data included names, email addresses, phone numbers, and shipping/physical addresses; passwords and payment card details were not accessed. Malicious scripts were also injected into a small number of merchant storefronts, and Ribon was installed on hundreds of BigCommerce stores, with the impact possibly extending to other stores. BigCommerce uninstalled the apps on September 17, began notifying merchants on September 18, and stated its own platform was not breached. Affected UK retailer Master of Malt reported the incident to the UK ICO under reference IC-569770-Y1R9 and said Ribon, used across many stores, appeared to be the primary target. Reports disagree on the corporate relationship behind the apps: BleepingComputer says they are operated by Be A Part Of (a Fastr brand), GBHackers says Ribon is owned by Fastr and managed by Be A Part Of, and SecurityWeek says it is owned by Fastr company Be A Part Of.
- Compromised credentials for the third-party Ribon and Ribon 1.5 BigCommerce apps were abused after a compromise of a Fastr system.
- The stolen application key was active from 17:21 BST on September 13, 2026, until it was revoked at 21:12 BST on September 17, 2026.
- Stolen data included names, email addresses, phone numbers, and shipping/physical addresses; passwords and payment card data were not accessed.
- Malicious scripts were injected into a small number of merchant storefronts.
- Ribon was installed on hundreds of BigCommerce stores, and the impact may extend to other stores.
- BigCommerce uninstalled the apps on September 17, 2026, and began merchant notifications on September 18, 2026.
- Master of Malt reported the incident to the UK ICO under reference IC-569770-Y1R9.
- Master of Malt said Ribon, used across many stores, appeared to be the primary target.
Coverage timelineoldest first · each row is one article
- · 5d agoBigCommerce alerts merchants of data breach linked to Ribon apps
BleepingComputer· 66
Attackers used stolen Ribon app keys to access BigCommerce shopper data and inject storefront scripts.
- · 4d agoHackers Abuse Stolen BigCommerce App Key to Steal Master of Malt Customer Data
GBHackers· 56
Attackers used a stolen Ribon BigCommerce app key to access Master of Malt customer contact data.
- · 4d agoBigCommerce Data Stolen via Ribon Apps Hack
SecurityWeek· 74
Attackers stole BigCommerce shopper data by abusing compromised Ribon application API credentials.