www.securityweek.com 22 Sept 2026, 17:58 UTC

BigCommerce Merchants Hit After Ribon App Key Exposes Customer Data

BigCommerce Merchants Hit After Ribon App Key Exposes Customer Data
CyberSIXT Evidence Panel Source marked as original reporting

BIGCOMMERCE has notified merchants that customer data was stolen after attackers compromised an application key belonging to Ribon, a storefront optimisation app developed by Be A Part Of, a Fastr company. The key was reportedly used between 13 and 17 September 2026 to access data including customers’ names, email addresses, telephone numbers and physical addresses.

UK spirits retailer Master of Malt said the attackers downloaded records “page by page” until the key was revoked on 17 September, one day after Ribon’s developers became aware it was being misused.

BigCommerce began notifying affected merchants on 18 September and uninstalled the Ribon applications from targeted stores. The company said Ribon was installed on hundreds of BigCommerce stores and that compromised credentials were used to inject malicious scripts into a small number of merchant storefronts. BigCommerce stressed that this was not a breach of its own systems or platform, but resulted from a compromise of third-party application credentials.

It said it provided log data to support the developer’s investigation. The method used to compromise Ribon remains unclear, the number of affected organisations has not been confirmed, and neither Be A Part Of nor Fastr had publicly acknowledged the incident at the time of publication.

View full article

Article by CyberSIXT