An extensive data breach has impacted numerous merchants operating on the BigCommerce e-commerce platform, following the compromise of credentials for third-party applications developed by Ribon. Attackers exploited these compromised credentials to inject malicious scripts into online stores, gaining unauthorized access to sensitive shopper information. The incident, which came to light on September 17, has raised significant concerns about the security of third-party integrations within major SaaS e-commerce ecosystems and highlights the persistent threat of supply chain attacks.
The cloud-based Software-as-a-Service (SaaS) giant BigCommerce confirmed the credential compromise and swiftly acted to mitigate further damage by removing the affected Ribon applications from merchant storefronts. This proactive measure aimed to revoke the attackers’ access and protect customers from continued exploitation. However, the breach had already occurred, leading to the exposure of various shopper details for a period between September 13 and September 17.
One of the prominently affected businesses is Master of Malt, a UK-based online retailer specializing in spirits. The company confirmed it received notification from BigCommerce about the breach and subsequently informed its customers about the compromised data. According to Master of Malt, the exposed shopper details include full names, email addresses, phone numbers, and shipping postal addresses. The retailer explicitly stated, "It looks like hackers were able to compromise a BigCommerce Application key held by Ribon, which they were able to use to gain access to customer data held on their system." This statement underscores the critical reliance on secure API keys and application permissions in the interconnected world of e-commerce.
BigCommerce, a platform that supports over 1,200 third-party applications and integrations, relies on a robust ecosystem to provide merchants with diverse functionalities. Ribon, the application at the center of this incident, is operated by Be A Part Of, a brand under Fastr, and is known for its focus on shopping experience optimization. The incident raises questions about the vetting processes and ongoing security audits of third-party applications integrated into major e-commerce platforms.
Crucially, BigCommerce has stated that account passwords and payment card information were not exposed in this incident. The platform maintains that it stores these sensitive data types separately, and the nature of the attack did not involve access to this particularly critical information. This distinction is important, as payment data breaches often carry more severe financial and reputational consequences.
Timeline of the Incident
The timeline of the Ribon app breach provides critical context for understanding the progression of the attack and the response:
- Early September (Approx. September 13): Attackers gain access to compromised credentials for Ribon and Ribon 1.5 applications. This is the earliest point in time indicated for the exploitation of shopper data.
- September 13 – September 17: Attackers actively use the compromised credentials to access shopper data within BigCommerce environments. During this period, malicious scripts are injected into a "small number" of merchant storefronts.
- September 17: BigCommerce confirms the credential compromise and identifies the affected third-party applications (Ribon and Ribon 1.5). The company immediately takes action by removing the applications from affected merchant stores to revoke the attackers’ access.
- September 17 onwards: BigCommerce begins notifying affected merchants directly about the data breach.
- Post-Notification: Affected merchants, such as Master of Malt, start informing their customer base about the incident and the types of data that may have been accessed.
- Reporting to Authorities: Master of Malt reports the incident to the UK Information Commissioner’s Office (ICO), indicating a potential widespread impact beyond its own customer base.
- Legal Action: Law firm Emery Reddy begins seeking potential claimants, acknowledging that multiple retailers are notifying customers about data exposure linked to the Ribon app key theft.
- Ongoing Investigation: BigCommerce provides log data to support the developer’s investigation into the incident. Efforts are made to obtain comment from Be A Part Of and Fastr.
Nature of the Attack and Compromised Data
The attackers’ methodology involved exploiting a vulnerability in the trust relationship between BigCommerce and its third-party application developers. By compromising the Application key for Ribon, a mechanism that grants specific permissions for applications to interact with BigCommerce store data, the attackers were able to bypass standard security protocols. This allowed them to inject malicious scripts.
These scripts, once embedded in a merchant’s storefront, could then be used to extract data that shoppers voluntarily provided during their online interactions. The specific data compromised, as reported by Master of Malt, includes:
- Full Names: Essential for personal identification and communication.
- Email Addresses: Often used for marketing, order confirmations, and customer service.
- Phone Numbers: Used for direct communication, shipping updates, and customer support.
- Shipping Postal Addresses: Critical for order fulfillment and delivery.
While the attackers did not gain access to payment card details or account passwords, the compromised personal and shipping information still poses significant risks. This data can be used for various malicious purposes, including:
- Phishing Attacks: Using personal details to craft more convincing and targeted phishing emails.
- Identity Theft: Combining compromised information with other data to impersonate individuals.
- Social Engineering: Leveraging personal details to manipulate individuals into divulging more sensitive information.
- Spam and Unwanted Marketing: Bombarding individuals with unsolicited communications.
The fact that BigCommerce systems themselves were not breached is a crucial point emphasized by the company. This indicates that the vulnerability lay within the security of a third-party application and its integration with the platform, rather than a fundamental flaw in BigCommerce’s core infrastructure.
Official Responses and Statements
BigCommerce has maintained a transparent approach in its communication regarding the incident. In a statement provided to BleepingComputer, the company articulated its response and commitment to customer security:
"On September 17, 2026, Commerce confirmed that credentials belonging to third-party applications Ribon and Ribon 1.5, owned and operated by ‘Be A Part Of,’ a Fastr company, had been compromised and used to inject malicious scripts into a small number of merchant storefronts. Acting in the best interest of our customers and their shoppers, we uninstalled the application from affected stores to revoke the attacker’s access, notified those merchants directly, and are providing log data to support the developer’s investigation."

This statement highlights several key actions: immediate identification and confirmation, rapid mitigation through application uninstallation, direct notification of affected merchants, and cooperation with the third-party developer’s investigation. The year "2026" in the statement appears to be a typographical error in the original source material, and it is highly probable that it refers to the current or a recent year.
Master of Malt, as an affected merchant, has also been proactive in communicating with its customers and regulatory bodies. Their decision to report the incident to the UK Information Commissioner’s Office (ICO) signals a commitment to data privacy compliance and suggests a broad understanding of the potential reach of the breach.
The law firm Emery Reddy’s initiative to identify potential claimants points to the growing trend of class-action lawsuits following data breaches. This highlights the significant financial and legal ramifications that can arise from such incidents for both the platform provider and the affected merchants.
As of the publication of this article, BleepingComputer had not received a response from Be A Part Of and Fastr, the entities responsible for the Ribon applications. Their perspective and internal security measures leading up to the compromise are crucial for a complete understanding of the event.
Broader Impact and Implications
The BigCommerce-Ribon data breach is not an isolated incident but rather part of a larger trend of supply chain attacks targeting e-commerce platforms and their integrated third-party applications. This type of attack exploits the interconnected nature of modern digital ecosystems, where a vulnerability in one component can have cascading effects.
Supply Chain Security: The incident underscores the critical importance of robust security measures for third-party applications. E-commerce platforms must implement stringent vetting processes, regular security audits, and clear guidelines for their app partners. Merchants, in turn, need to exercise due diligence when selecting and integrating third-party tools, understanding the potential risks associated with each.
Credential Management: The compromise of Application keys highlights the vulnerability associated with how credentials are managed and stored. Secure storage, regular rotation of keys, and the principle of least privilege (granting applications only the necessary permissions) are paramount.
Impact on Merchant Trust: Data breaches can severely erode customer trust in both individual merchants and the platforms they use. For businesses that have experienced data exposure, rebuilding that trust can be a long and challenging process, potentially impacting sales and customer loyalty.
Regulatory Scrutiny: The involvement of regulatory bodies like the UK ICO indicates increasing scrutiny of data protection practices. Companies operating in the e-commerce space must ensure compliance with relevant data privacy regulations, such as GDPR, CCPA, and others, which mandate prompt notification of breaches and robust data protection measures.
Comparison to Previous Incidents: This breach bears resemblance to a 2024 incident involving electronics accessory maker ZAGG. In that case, attackers compromised a different third-party BigCommerce app, FreshClick, and injected payment-skimming code. While both incidents involved compromised third-party apps on the BigCommerce platform, the Ribon breach’s focus on accessing existing customer records, rather than intercepting live payment transactions, represents a different attack vector. The common thread, however, is the exploitation of third-party integrations as an entry point.
Mitigation and Future Prevention: Moving forward, BigCommerce and other e-commerce platforms will likely enhance their security protocols. This could include:
- More rigorous vetting of third-party apps: Implementing stricter security assessments and ongoing monitoring.
- Improved credential management systems: Offering more secure ways for developers to manage API keys and tokens.
- Enhanced monitoring for malicious script injection: Developing advanced threat detection capabilities to identify and flag suspicious code.
- Clearer communication protocols: Establishing rapid and effective communication channels with merchants and developers during security incidents.
Merchants themselves will need to remain vigilant, regularly reviewing the permissions granted to their integrated applications and staying informed about potential security threats. The BigCommerce-Ribon incident serves as a stark reminder that in the interconnected digital economy, security is a shared responsibility, and the weakest link in the chain can have far-reaching consequences. The full extent of the breach and its long-term impact on affected businesses and their customers will continue to unfold as investigations progress and more information becomes available.








