Primary company quote is in BleepingComputer (Bill Toulas, Sep 21) and restated to SecurityWeek (Ionut Arghire, Sep 22). BigCommerce: this was not a breach of Commerce systems or the BigCommerce platform. The relationship is merchant-to-third-party-app; Commerce uninstalled Ribon from affected stores, notified merchants, and is providing logs for the developer investigation.
UK spirits retailer Master of Malt is one named merchant. It says Ribon was installed on hundreds of BigCommerce stores, and that attackers used a compromised BigCommerce application key held by Ribon to pull customer records page by page until the key was revoked on Sep 17 (one day after Ribon developers became aware of misuse). Exposed fields per Master of Malt: full name, email, phone, shipping postal address. Password and payment data sit in a separate system that was not compromised.
Scope language to keep straight: BigCommerce says scripts hit a small number of storefronts; Master of Malt frames the target as Ribon across hundreds of installs. How Fastr / Be A Part Of was initially compromised, and whether other apps or platforms were hit: Undisclosed — neither has publicly acknowledged the incident as of the SecurityWeek / BleepingComputer writeups. Master of Malt reported to the UK ICO. Law firm Emery Reddy says several retailers are notifying customers; victim tally: Undisclosed.
Context: similar pattern to the 2024 FreshClick / ZAGG Magento-style skimmer on BigCommerce, except Ribon attackers used the app key against existing customer records rather than capturing checkout card entry. POV: treat as a confirmed third-party supply-chain credential theft with named platform response, per BigCommerce’s Sep 17 confirmation and Master of Malt’s field list; headcounts and Fastr root cause remain Undisclosed until a primary posts them.
