Ribon App Compromise Leads to Data Theft on BigCommerce Stores
Share
A supply chain attack targeting the Ribon storefront optimisation app has led to the theft of customer data from multiple BigCommerce-hosted online stores.
The attackers gained access to sensitive information by using a compromised BigCommerce application key held by Ribon. The breach took place between 13 September and 17 September 2026.
According to technical details provided by the UK spirits vendor Master of Malt, the hackers downloaded customer data “page by page” until the compromised key was revoked on 17 September.
Data Exposed in Ribon Compromise
The stolen data includes customer names, email addresses, phone numbers, and physical addresses. While the exact number of affected merchants and customers has not been fully disclosed, the incident involved the Ribon and Ribon 1.5 applications.
BigCommerce, a software-as-a-service (SaaS) provider that enables merchants to manage online stores, confirmed that the API credentials belonging to the Ribon applications were compromised. The company noted that the vulnerability originated from a system compromise at Fastr, the parent company of Be A Part Of, which develops the Ribon apps.
BigCommerce clarified that the breach was not a compromise of the core BigCommerce platform or its internal systems. Instead, the attackers used the third-party application credentials to access data within the merchant stores where Ribon was installed. In some instances, the credentials were also used to inject malicious scripts into a small number of merchant storefronts.
Response and Mitigation
BigCommerce began notifying affected merchants on 18 September, one day after the developers became aware of the misuse. To limit further harm, the company uninstalled the compromised Ribon applications from affected storefronts and revoked the attacker’s access.
The company has provided log data to support investigations by the developers. Neither Be A Part Of nor Fastr has publicly acknowledged the specific details of the underlying system compromise at this time.




Leave a Reply