BigCommerce Reports Data Breach After Compromised Ribon App Credentials Were Used to Inject Malicious Scripts into Online Stores

Views: 44 views

BigCommerce, a cloud-based SaaS e-commerce platform, has notified multiple merchants of a data breach after attackers compromised credentials belonging to the third-party applications Ribon and Ribon 1.5, developed by Be A Part Of, a subsidiary of Fastr. The attackers then used those credentials to inject malicious scripts into merchants’ online storefronts. BigCommerce confirmed the incident on September 17, 2026, and immediately uninstalled the affected applications from impacted stores to revoke the attackers’ access and protect customers.

One of the merchants notified was Master of Malt, a UK-based online alcohol retailer, which stated that attackers were able to access customer information within the BigCommerce environment between September 13 and 17. The affected customer data included full names, email addresses, phone numbers, and shipping addresses. BigCommerce stated that account passwords and payment card information were stored separately from the affected data and were not impacted by the incident. The company emphasized that its core systems and platform were not compromised, and that the incident involved the misuse of credentials belonging to a third-party application.

BigCommerce stated that it directly notified affected merchants and provided log data to support the application developer’s investigation. Master of Malt has also reported the incident to the UK Information Commissioner’s Office (ICO) and indicated that a larger number of other merchants may have been affected. In addition, law firm Emery Reddy is reportedly gathering information from individuals who may have been impacted, noting that several retailers have begun notifying customers about data exposure linked to the theft of the Ribon app key. The incident is similar to the 2024 ZAGG case, in which attackers compromised a third-party application on BigCommerce and injected data-stealing code into an online store. However, based on the information currently available, this incident has only been confirmed to involve access to customer information through compromised Ribon credentials, with no confirmation that payment card data was exposed.

Source: https://www.bleepingcomputer.com/news/security/bigcommerce-alerts-merchants-of-data-breach-linked-to-ribon-apps/