Skip to content
Supply chainContained

BigCommerce merchant stores hit via compromised Ribon apps

Ecommerce platform BigCommerce warned merchants that attackers had compromised credentials for the third-party Ribon and Ribon 1.5 apps, used them to inject malicious scripts into storefronts and accessed shopper names, emails, phone numbers and shipping addresses.

Victim
BigCommerce merchants (Ribon apps)

On 21 September 2026, it emerged that ecommerce platform BigCommerce had alerted multiple merchants to data breaches caused by a compromise of the third-party Ribon and Ribon 1.5 applications, shopping-experience optimization tools operated by Be A Part Of, a Fastr company. Attackers obtained the credentials those apps used to connect to merchant stores and used them to inject malicious scripts into storefronts and access shopper data between 13 and 17 September 2026.

BigCommerce said it confirmed the compromise on 17 September, uninstalled the applications from affected stores to cut off the attackers' access, notified the merchants directly and shared log data with the app developer's investigation. The company stressed that its own platform was not breached.

What was exposed

Affected shoppers' full names, email addresses, phone numbers and shipping addresses were exposed. BigCommerce said passwords and payment card data are stored separately and were not affected. UK online spirits retailer Master of Malt was among the merchants that notified customers, and a law firm reported that several other retailers were sending notices; the total number of affected stores and shoppers was not disclosed.

Why it matters

Marketplace apps installed on hosted ecommerce stores typically hold persistent API credentials and the ability to add scripts to checkout and product pages. A single compromised app vendor can therefore reach many independent merchants at once, in a pattern similar to earlier Magecart-style supply-chain attacks.

Timeline

  1. Unauthorized access to shopper data through the compromised Ribon apps begins.

  2. BigCommerce confirms the compromise, uninstalls the apps from affected stores and notifies merchants.

  3. The incident is publicly reported as merchants, including Master of Malt, notify their customers.

Sources

  1. bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/bigcommerce-alerts-merchants-of-data-breach-linked-to-ribon-apps/
  2. privacyguides.orghttps://www.privacyguides.org/news/2026/09/25/data-breach-roundup-sep-18-24-2026/

Related incidents