Skip to main content

BigCommerce Data Stolen via Ribon Apps Hack

0
High
News
Published: 09/22/2026 (09/22/2026, 17:58:00 UTC)
Source: SecurityWeek

Description

BigCommerce suffered a supply chain attack through a compromised application key belonging to the third-party app Ribon. Attackers used the stolen key to access customer data, including names, emails, phone numbers, and addresses, between September 13 and 17, 2026. The compromised key was revoked on September 17, and affected merchants were notified starting September 18. The incident was due to a compromise of the third-party app's credentials, not a breach of BigCommerce's own systems. BigCommerce uninstalled the Ribon app from affected stores to prevent further access.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/22/2026, 18:02:51 UTC

Technical Analysis

Attackers exploited a compromised API key belonging to the Ribon application, a third-party storefront optimization app installed on hundreds of BigCommerce merchant stores. Using this key, the attackers accessed and exfiltrated customer data from BigCommerce stores between September 13 and 17, 2026. The key was revoked and the Ribon app uninstalled after the compromise was detected. BigCommerce confirmed that the breach originated from a compromise of the third-party app's credentials due to a Fastr system compromise and not from a direct breach of BigCommerce's platform or systems. The attackers injected malicious scripts into some merchant storefronts via the compromised credentials. The full scope of the compromise of Ribon or other entities remains unclear, with no public acknowledgment from the app developer or parent company.

Potential Impact

Customer data including names, email addresses, phone numbers, and physical addresses were accessed and stolen from multiple BigCommerce merchant stores using the compromised Ribon application key. The attackers were able to download data page by page over several days. The incident affected merchants using the Ribon app, potentially exposing their customers to privacy risks and follow-on attacks such as phishing. There was no direct breach of BigCommerce's core platform or systems. The malicious activity was limited to stores where the Ribon app was installed and the compromised credentials were active.

Defensive Guidance

BigCommerce revoked the compromised Ribon API credentials and uninstalled the Ribon application from affected merchant stores to prevent further unauthorized access. Merchants were notified of the incident and provided with log data to support investigation. Since the breach originated from a third-party app compromise, affected merchants should review their installed third-party applications and consider removing or replacing those with known security issues. Monitoring for suspicious activity related to customer data is advised. Patch status is not applicable as this is a credential compromise of a third-party app, not a software vulnerability. Check for any updates or advisories from Ribon or its parent company for further remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.3,"severitySource":"heuristic","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/bigcommerce-data-stolen-via-ribon-apps-hack/","fetched":true,"fetchedAt":"2026-09-22T18:02:46.377Z","wordCount":1076}

Threat ID: 6ab2c2c6f7a7c541068ab2fb

Added to database: 09/22/2026, 18:02:46 UTC

Last enriched: 09/22/2026, 18:02:51 UTC

Last updated: 09/23/2026, 03:40:06 UTC

Views: 16

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses