BigCommerce alerts merchants of data breach linked to Ribon apps
BigCommerce alerted merchants to a data breach involving compromised credentials of third-party Ribon applications. Attackers used these credentials to inject malicious scripts and access shopper data, including names, emails, phone numbers, and shipping addresses. Payment card information and account passwords were not exposed. The breach affected multiple merchants between September 13 and 17, 2026. BigCommerce removed the compromised apps and revoked attacker access. The platform itself was not breached. The incident may impact hundreds of stores and is under investigation.
AI Analysis
Technical Summary
On September 17, 2026, BigCommerce confirmed that credentials for third-party applications Ribon and Ribon 1.5, operated by Be A Part Of (a Fastr company), were compromised. Attackers used these credentials to inject malicious scripts into some merchant storefronts and accessed shopper data stored within BigCommerce environments. The compromised data included full names, email addresses, phone numbers, and shipping postal addresses. BigCommerce stated that its own systems and platform were not breached, and sensitive data such as account passwords and payment card information were stored separately and not exposed. The company removed the affected applications from stores to revoke attacker access and notified impacted merchants. One affected merchant, Master of Malt, reported the incident to the UK ICO and indicated the breach could affect many other stores. This incident resembles a 2024 breach involving another third-party BigCommerce app but differs in that the attackers accessed existing customer records rather than payment information entered during checkout.
Potential Impact
Attackers gained unauthorized access to shopper personal information (names, emails, phone numbers, shipping addresses) from multiple BigCommerce merchants by compromising third-party application credentials. No payment card or account password data was exposed. The breach potentially affects hundreds of stores and their customers, leading to privacy risks and regulatory notifications. BigCommerce’s platform and core systems were not compromised.
Mitigation Recommendations
BigCommerce removed the compromised Ribon and Ribon 1.5 applications from affected stores to revoke attacker access and notified impacted merchants directly. The platform operator is providing log data to support the developer's investigation. Merchants should follow BigCommerce’s guidance and monitor communications for further updates. No direct patch is applicable as this is a third-party app credential compromise. The platform itself was not breached.
BigCommerce alerts merchants of data breach linked to Ribon apps
Description
BigCommerce alerted merchants to a data breach involving compromised credentials of third-party Ribon applications. Attackers used these credentials to inject malicious scripts and access shopper data, including names, emails, phone numbers, and shipping addresses. Payment card information and account passwords were not exposed. The breach affected multiple merchants between September 13 and 17, 2026. BigCommerce removed the compromised apps and revoked attacker access. The platform itself was not breached. The incident may impact hundreds of stores and is under investigation.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
On September 17, 2026, BigCommerce confirmed that credentials for third-party applications Ribon and Ribon 1.5, operated by Be A Part Of (a Fastr company), were compromised. Attackers used these credentials to inject malicious scripts into some merchant storefronts and accessed shopper data stored within BigCommerce environments. The compromised data included full names, email addresses, phone numbers, and shipping postal addresses. BigCommerce stated that its own systems and platform were not breached, and sensitive data such as account passwords and payment card information were stored separately and not exposed. The company removed the affected applications from stores to revoke attacker access and notified impacted merchants. One affected merchant, Master of Malt, reported the incident to the UK ICO and indicated the breach could affect many other stores. This incident resembles a 2024 breach involving another third-party BigCommerce app but differs in that the attackers accessed existing customer records rather than payment information entered during checkout.
Potential Impact
Attackers gained unauthorized access to shopper personal information (names, emails, phone numbers, shipping addresses) from multiple BigCommerce merchants by compromising third-party application credentials. No payment card or account password data was exposed. The breach potentially affects hundreds of stores and their customers, leading to privacy risks and regulatory notifications. BigCommerce’s platform and core systems were not compromised.
Defensive Guidance
BigCommerce removed the compromised Ribon and Ribon 1.5 applications from affected stores to revoke attacker access and notified impacted merchants directly. The platform operator is providing log data to support the developer's investigation. Merchants should follow BigCommerce’s guidance and monitor communications for further updates. No direct patch is applicable as this is a third-party app credential compromise. The platform itself was not breached.
Technical Details
- Classification
- {"confidence":0.95,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/bigcommerce-alerts-merchants-of-data-breach-linked-to-ribon-apps/","fetched":true,"fetchedAt":"2026-09-21T21:46:37.727Z","wordCount":818}
Threat ID: 6ab1a5bd55bf5e2cf5835b51
Added to database: 09/21/2026, 21:46:37 UTC
Last enriched: 09/21/2026, 21:46:42 UTC
Last updated: 09/21/2026, 23:31:30 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.