BREACH

BigCommerce merchants hit via Ribon app key compromise. Platform says it was not breached.

BigCommerce confirmed on Sep 17 that API credentials for third-party apps Ribon and Ribon 1.5 — owned by Be A Part Of, a Fastr company — were compromised and used to inject malicious scripts into a small number of merchant storefronts. Shopper PII (names, emails, phones, addresses) was accessed between Sep 13–17 per merchant notices. Passwords and payment cards: not exposed, per the company and Master of Malt. Total merchants and shoppers: Undisclosed.

Sep 22, 2026 · 3 min read

Primary company quote is in BleepingComputer (Bill Toulas, Sep 21) and restated to SecurityWeek (Ionut Arghire, Sep 22). BigCommerce: this was not a breach of Commerce systems or the BigCommerce platform. The relationship is merchant-to-third-party-app; Commerce uninstalled Ribon from affected stores, notified merchants, and is providing logs for the developer investigation.

UK spirits retailer Master of Malt is one named merchant. It says Ribon was installed on hundreds of BigCommerce stores, and that attackers used a compromised BigCommerce application key held by Ribon to pull customer records page by page until the key was revoked on Sep 17 (one day after Ribon developers became aware of misuse). Exposed fields per Master of Malt: full name, email, phone, shipping postal address. Password and payment data sit in a separate system that was not compromised.

Scope language to keep straight: BigCommerce says scripts hit a small number of storefronts; Master of Malt frames the target as Ribon across hundreds of installs. How Fastr / Be A Part Of was initially compromised, and whether other apps or platforms were hit: Undisclosed — neither has publicly acknowledged the incident as of the SecurityWeek / BleepingComputer writeups. Master of Malt reported to the UK ICO. Law firm Emery Reddy says several retailers are notifying customers; victim tally: Undisclosed.

Context: similar pattern to the 2024 FreshClick / ZAGG Magento-style skimmer on BigCommerce, except Ribon attackers used the app key against existing customer records rather than capturing checkout card entry. POV: treat as a confirmed third-party supply-chain credential theft with named platform response, per BigCommerce’s Sep 17 confirmation and Master of Malt’s field list; headcounts and Fastr root cause remain Undisclosed until a primary posts them.

Sources