
BigCommerce breach: Ribon app key exposed shopper data
BigCommerce told merchants that stolen credentials for the third party apps Ribon and Ribon 1.5 let attackers inject scripts and reach shopper records.
BigCommerce has begun telling merchants that attackers used stolen credentials for two third party applications, Ribon and Ribon 1.5, to inject malicious scripts into online stores and reach shopper records. The cloud-based ecommerce platform, which is delivered as Software-as-a-Service (software that runs on the vendor's servers instead of on the customer's own machines), confirmed the credential compromise on September 17, 2026 and said it immediately removed the applications to protect its customers.
According to BigCommerce, the attackers used those compromised credentials to reach shopper data inside its environments between September 13 and September 17. One of the customers that received the notification, the UK online spirits retailer Master of Malt, said the intruder reached shopper information. In its updates on the incident, the retailer said the affected details include full names, email addresses, phone numbers and shipping postal addresses.
Master of Malt said it appeared that hackers had compromised a BigCommerce application key held by Ribon and used it to reach customer data held on BigCommerce's system. An application key is a secret code that lets one piece of software act on another system on the account holder's behalf, so whoever holds it can use the permissions attached to it without needing the store owner's password. That is why a leak of a key can be as serious as a leak of a login: the app, not the merchant, controls how well the key is protected.
BigCommerce said the compromised credentials belong to Ribon and Ribon 1.5, applications owned and operated by Be A Part Of, a Fastr company, which works on shopping experience optimisation. Ribon is one of more than 1,200 third party applications and integrations the platform supports. In a statement to BleepingComputer, BigCommerce underlined that its own systems and the platform itself were not breached, and said that acting in the best interest of its customers and their shoppers it uninstalled the application from affected stores to revoke the attacker's access, notified those merchants directly, and is providing log data to support the investigating developer. BleepingComputer said it had contacted Be A Part Of and Fastr for more information and had not received a response by publication time.
The company also said it stores account passwords and payment card information separately, and that these types of data were not exposed. On the vendor's account, then, this is not a case of card numbers or login credentials being taken from BigCommerce itself, but of shopper contact and delivery details being read through a connected application.
The reach of the incident is still being established. Master of Malt reported it to the UK Information Commissioner's Office (ICO), the country's data protection authority to which organisations report breaches, and noted that the impact may extend well beyond its own customers, potentially to hundreds of other stores. The law firm Emery Reddy said it is seeking potential claimants linked to the incident, adding that several retailers are currently notifying customers about data exposure connected to the Ribon app key theft, without naming any of them. The source material does not say how the credentials were obtained or how many shoppers are affected; BigCommerce has described only a small number of merchant storefronts.
BleepingComputer notes that the incident resembles a 2024 breach at electronics accessory maker ZAGG, where attackers compromised a third party BigCommerce app called FreshClick and injected payment-skimming code into its online store. BigCommerce said at the time that its platform had not been breached and removed the compromised app from customers' stores. The two cases differ in what the attackers were after. In the ZAGG case, the injected code captured payment information as shoppers entered it at checkout. In the Ribon case, the compromised application key was used to reach customer records that were already stored on the platform.
For website owners and online shops, the pattern is the practical lesson. Connected apps are not passive add-ons. When a store owner installs one, that app is normally issued a key that lets it read or change data on the store's behalf, and from that moment the safety of the data depends partly on how the app's developer stores and protects its keys. Reviewing which integrations are installed, removing the ones no longer in use, asking vendors how they handle their own keys, and treating any notice from a platform as a prompt to check records and replace exposed access credentials are sensible responses that cost nothing but attention. Ecommerce platforms can rotate a key and uninstall an app quickly, as BigCommerce says it did here, but the customer data the app could already read cannot be recalled.
Readers who want help reviewing which third party integrations can reach their customer data, and how those connections are secured across their own infrastructure, can look at AEU-I, AEU Group's security-first IT, infrastructure and consulting service (https://aeu-i.com). Shoppers caught up in this incident should watch for messages that quote their name, address or phone number, since that exposed information gives a scam an air of authenticity, and should treat unexpected requests for payment details or logins with suspicion.
How to Protect Yourself
- If a shop where you have an account emails you about this breach, open the message and follow its instructions instead of ignoring it.
- Be wary of any email or text that mentions your name, address or phone number and asks you to click a link or confirm details, because that leaked information helps criminals sound convincing.
- Change the password on any shopping account where you reused the same password as elsewhere, and give each shop its own password from now on.
- Check your bank and card statements for payments you do not recognise, even though the platform says card details were not exposed in this case.
- Turn on two-step verification, where a shop or your email sends a second code to your phone, wherever it is offered.
- If you run an online store, remove app connections you no longer use and check which of the remaining ones can see customer data.
Terms Explained
- Software-as-a-Service Software you use over the internet on someone else's servers, instead of installing and running it on your own computer.
- third party applications Extra apps made by other companies that you connect to a platform to add features, such as reviews or marketing tools.
- credentials The secret details, such as a username and password or a code, that prove a person or program is allowed to log in.
- application key A long secret code that lets one app access another system on your behalf, working much like a password made for software rather than for people.
- malicious scripts Small pieces of code added to a web page that make it do something the site owner never intended, such as stealing information from visitors.
- ICO The Information Commissioner's Office, the UK authority that organisations must tell when personal data is lost or stolen.