BigCommerce Confirms Data Breach Linked to Ribon App Credentials
At a glance
- BigCommerce confirmed Ribon app credentials were compromised on September 17, 2026.
- Attackers injected malicious scripts into some merchant storefronts.
- Master of Malt reported customer data, including contact details, was accessed.
BigCommerce reported a security incident involving third-party applications Ribon and Ribon 1.5, which resulted in unauthorized access to certain merchant storefronts. The event has prompted affected retailers to notify customers and report the breach to relevant authorities.
On September 17, 2026, BigCommerce stated that credentials for the Ribon and Ribon 1.5 applications, operated by Be A Part Of (a Fastr company), had been compromised. The company confirmed that attackers used these credentials between September 13 and September 17 to introduce malicious scripts into a limited number of merchant storefronts.
Following the discovery, BigCommerce removed the Ribon applications from the affected stores to block further unauthorized access. The company also stated that its own systems and core platform were not breached during the incident.
Master of Malt, a retailer based in the United Kingdom, reported that the data accessed included customer names, email addresses, phone numbers, and shipping postal addresses. The retailer submitted a report about the breach to the UK Information Commissioner’s Office (ICO) as part of its response process.
What the numbers show
- Compromised credentials were used between September 13 and September 17, 2026.
- BigCommerce confirmed the breach on September 17, 2026.
- Customer data accessed included full names, email addresses, phone numbers, and postal addresses.
Law firm Emery Reddy announced it is seeking potential claimants in connection with the breach. According to the firm, several retailers have begun notifying customers about data exposure resulting from the compromised Ribon app keys.
The breach has been compared to a 2024 incident involving the FreshClick app, where attackers injected payment-skimming code. In the current case, attackers accessed existing customer records by exploiting the compromised app key, rather than injecting payment-skimming code.
Industry reaction
BigCommerce stated that its systems and core platform remained secure and were not affected by the breach. The company responded by removing the compromised applications from affected storefronts to prevent further unauthorized activity.
Master of Malt reported the incident to the UK Information Commissioner’s Office and informed customers about the data that had been accessed. Emery Reddy stated that it is assisting individuals who may have been affected by the breach and highlighted that multiple retailers are notifying customers about the exposure.
* This article is based on publicly available information at the time of writing.