Download Privacy Needle App

Type to search

Data Breaches

Ribon App Compromise Leads to Data Theft on BigCommerce Stores

Share

A supply chain attack targeting the Ribon storefront optimisation app has led to the theft of customer data from multiple BigCommerce-hosted online stores.

The attackers gained access to sensitive information by using a compromised BigCommerce application key held by Ribon. The breach took place between 13 September and 17 September 2026.

According to technical details provided by the UK spirits vendor Master of Malt, the hackers downloaded customer data “page by page” until the compromised key was revoked on 17 September.

Data Exposed in Ribon Compromise

The stolen data includes customer names, email addresses, phone numbers, and physical addresses. While the exact number of affected merchants and customers has not been fully disclosed, the incident involved the Ribon and Ribon 1.5 applications.

BigCommerce, a software-as-a-service (SaaS) provider that enables merchants to manage online stores, confirmed that the API credentials belonging to the Ribon applications were compromised. The company noted that the vulnerability originated from a system compromise at Fastr, the parent company of Be A Part Of, which develops the Ribon apps.

BigCommerce clarified that the breach was not a compromise of the core BigCommerce platform or its internal systems. Instead, the attackers used the third-party application credentials to access data within the merchant stores where Ribon was installed. In some instances, the credentials were also used to inject malicious scripts into a small number of merchant storefronts.

Response and Mitigation

BigCommerce began notifying affected merchants on 18 September, one day after the developers became aware of the misuse. To limit further harm, the company uninstalled the compromised Ribon applications from affected storefronts and revoked the attacker’s access.

The company has provided log data to support investigations by the developers. Neither Be A Part Of nor Fastr has publicly acknowledged the specific details of the underlying system compromise at this time.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.