2026 BigCommerce — Ribon/Ribon 1.5 app keys compromised; merchant shopper PII + storefront scripts
Data compromised
Per Master of Malt merchant notice: shopper full names, email addresses, phone numbers, shipping postal addresses. BigCommerce: passwords and payment-card data stored separately and not exposed. Platform systems not breached. Merchant/shopper census not published.
Technical writeup
Verified BigCommerce statement to BleepingComputer (published September 21, 2026). On September 17, 2026 BigCommerce confirmed credentials for third-party apps Ribon and Ribon 1.5 (owned/operated by Be A Part Of, a Fastr company) were compromised and used to inject malicious scripts into a small number of merchant storefronts. Unauthorized shopper-data access in BigCommerce environments spanned September 13–17. BigCommerce uninstalled the apps from affected stores, notified merchants, and is providing logs to the developer. Core platform not breached; passwords and PCI data stated not exposed. UK spirits merchant Master of Malt confirmed shopper PII access and reported to the UK ICO; noted impact may extend to hundreds of other stores. Headcount unpublished — recordsAffected 0; companyConfirmed true.
Root cause
Compromised third-party Ribon and Ribon 1.5 application credentials (Be A Part Of / Fastr); used for API access and malicious storefront script injection (BigCommerce confirmation)