Skip to content
Tech News
← Back to articles

BigCommerce alerts merchants of data breach linked to Ribon apps

read original get YubiKey 5C NFC Security Key → more articles
Why This Matters

This breach highlights the growing risk posed by third-party app integrations in ecommerce ecosystems, where compromising a single vendor's credentials can expose customer data across many storefronts. It underscores the importance of supply-chain security for SaaS platforms like BigCommerce that rely on extensive app marketplaces, and serves as a reminder to consumers that even trusted retailers can be compromised through vendors they don't directly control.

Key Takeaways
Worth a Look

YubiKey 5C NFC Security Key — Breaches like this one often trace back to compromised credentials, and a hardware security key like the YubiKey 5C NFC adds a strong layer of protection beyond passwords alone. It's a simple way for both merchants and shoppers to guard important accounts against exactly this kind of credential theft. Plug-and-play support for major platforms makes it easy to start using right away.

See YubiKey 5C NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Ecommerce platform BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores.

The cloud-based Software-as-a-Service (SaaS) ecommerce platform confirmed the credential compromise on September 17 and immediately removed the apps to protect its customers.

UK-based online spirits vendor Master of Malt is one of the BigCommerce customers that received the notification. The retailer said the attacker accessed shopper information.

The hacker used the compromised credentials to access shopper data in BigCommerce environments between September 13 and September 17, the company said.

In updates on the incident, Master of Malt says impacted shopper details include full names, email addresses, phone numbers, and shipping postal addresses.

“It looks like hackers were able to compromise a BigCommerce Application key held by Ribon, which they were able to use to gain access to customer data held on their system,” Master of Malt stated.

BigCommerce supports over 1,200 third-party applications and integrations, including Ribon, an application operated by Be A Part Of, a brand operated by Fastr, specialized in shopping experience optimization.

The e-commerce platform says it stores account passwords and payment card information separately and that this type of data was not exposed.

In a statement for BleepingComputer, BigCommerce said that the attacker compromised credentials for Ribon and Ribon 1.5 applications.

"On September 17, 2026, Commerce confirmed that credentials belonging to third-party applications Ribon and Ribon 1.5, owned and operated by 'Be A Part Of,' a Fastr company, had been compromised and used to inject malicious scripts into a small number of merchant storefronts."

... continue reading