← Blog

BigCommerce Ribon Apps Breach: Shopper PII Exposed

Share on X

BigCommerce confirmed it: attackers stole credentials for the third-party Ribon and Ribon 1.5 apps, then used that access to pull shopper records and inject malicious scripts into a small number of merchant storefronts. The window was short — September 13 through September 17, 2026 — but long enough for UK spirits retailer Master of Malt to tell customers that full names, emails, phones, and shipping postal addresses left through a compromised application key.

This is a verified BigCommerce data breach tied to Ribon apps, not a leak-site rumor. The platform told BleepingComputer that its core systems were not breached, that passwords and payment cards sit in separate stores and were not exposed, and that it uninstalled the apps from affected merchants once it confirmed the compromise. Canonical record: bigcommerce-ribon2026.

If you shopped a BigCommerce store that had Ribon installed, or you run one, the stakes are concrete. Attackers who already know your name, email, phone, and delivery address do not need your card number to run a convincing phishing play.

What happened

BigCommerce hosts more than 1,200 third-party applications and integrations. Ribon, operated by Be A Part Of (a Fastr brand), sits in that marketplace as a shopping-experience optimization tool — the kind of app merchants install to tune conversion, not to become the front door for a data grab.

On September 17, 2026, BigCommerce confirmed to BleepingComputer that credentials for Ribon and Ribon 1.5 had been compromised. Those credentials were used two ways: to access shopper data in BigCommerce environments, and to inject malicious scripts into a small number of merchant storefronts. Unauthorized shopper-data access ran from September 13 through September 17.

Remediation was platform-side and fast once confirmation landed. BigCommerce uninstalled the application from affected stores to revoke the attacker’s access, notified those merchants directly, and began providing log data to support the developer’s investigation. That sequence matters for shoppers reading a merchant email weeks later: the access path BigCommerce could cut, it cut. The customer file that may already have been copied is a different problem.

Be A Part Of / Fastr had not responded publicly by the time BleepingComputer published. That silence does not erase BigCommerce’s confirmation. It does leave merchants without a developer post-mortem on how the third-party app key left the building.

Timeline

  1. September 13, 2026 — Unauthorized shopper-data access in BigCommerce environments begins, per BigCommerce.
  2. September 13–17, 2026 — Attackers use compromised Ribon / Ribon 1.5 credentials; malicious scripts appear on a small number of storefronts.
  3. September 17, 2026 — BigCommerce confirms the credential compromise, uninstalls the apps from affected stores, notifies merchants, and starts sharing logs with the developer.
  4. Mid-to-late September 2026 — Master of Malt publishes a customer notice describing exposed fields and reports the incident to the UK Information Commissioner’s Office (ICO). The retailer says impact may reach hundreds of other stores.
  5. September 18–21, 2026 — Law firm Emery Reddy says several retailers are notifying customers about Ribon-linked exposure. BleepingComputer publishes BigCommerce’s on-record statement (September 21).

Five calendar days is plenty of time to export CRM-shaped shopper PII and plant storefront JavaScript that looks like a trusted app asset. Anyone waiting for a public headcount is waiting for a number that may never arrive — neither BigCommerce nor Master of Malt has published a verified census.

What shopper data was exposed

Master of Malt is the clearest merchant voice so far. The UK online spirits seller confirmed shopper access and listed the fields: full names, email addresses, phone numbers, and shipping postal addresses. On its public apology page, the company said hackers compromised a BigCommerce application key held by Ribon and used it to reach customer data held on that system.

That inventory is classic ecommerce identity — doorstep PII, not a password dump. Full name plus shipping postal address is enough to spoof a courier. Email plus phone is enough to run SMS “account recovery” and email “order hold” campaigns in parallel. Spirits orders add a social cue: gift recipients, birthdays, corporate hampers, collectors chasing limited bottlings. Attackers who can quote a postcode and a whisky brand do not sound like random spam.

Master of Malt also told customers the problem may extend well beyond its own book — potentially to hundreds of other stores that used the Ribon application. Emery Reddy, seeking claimants, separately said several retailers are notifying without naming them in its public post. Treat “hundreds of stores” as Master of Malt’s assessment of marketplace reach, not as a BigCommerce-published victim list.

What was not exposed, per BigCommerce

BigCommerce says it stores account passwords and payment card information separately, and that this type of data was not exposed. That distinction is the difference between rotating a reused password and freezing every card you used on every BigCommerce checkout this decade.

What this is not: a confirmed PCI card-dump from BigCommerce’s vault. What this also is not: proof that every malicious storefront script failed to capture anything at checkout on the small number of injected sites. BigCommerce’s platform statement covers passwords and payment data stored separately on its side. Magecart-style script injection on a merchant theme is a separate risk surface — one BigCommerce says affected only a small number of storefronts, and one merchants still need to audit in Script Manager after the app is gone.

No public figure for records affected has been attested. “Small number of merchant storefronts” for script injection and “may extend to hundreds of other stores” for Ribon install base are both qualitative. Do not invent millions.

How the attack worked

Two techniques rode the same stolen credentials.

API / application-key access to existing customer records. A BigCommerce third-party app key is not a shopper password. It is a machine credential that lets an integration read and act inside a merchant’s store under the permissions granted at install time. Steal that key at the developer, and you inherit every connected store’s authorized scopes without phishing a single merchant admin. That is how Master of Malt described the path: application key held by Ribon, then customer data reachable through that trust.

Storefront script injection. BigCommerce confirmed the same compromised credentials were used to inject malicious scripts into a small number of merchant storefronts. In ecommerce terms, that is Magecart-family tradecraft — JavaScript that loads in the shopper’s browser through a trusted third-party tag and can skim forms or rewrite checkout behavior. Because the script arrives through an installed app the merchant chose, “we only allow our CDN” assumptions fail quietly.

BigCommerce’s important clarification to BleepingComputer: unlike the 2024 FreshClick / ZAGG case — where attackers primarily captured payment information entered during checkout — the Ribon attackers used a compromised application key to access existing customer records through BigCommerce. Script injection still happened. The headline data path for shopper PII in the merchant notices is the API key into CRM-like records, not a claim that every impacted store ran a successful card skimmer.

For merchant security teams: revoke and remove first, then hunt leftovers. An uninstalled marketplace app does not always delete every script tag a prior version wrote into Script Manager, theme files, or a tag manager. If Ribon or Ribon 1.5 ever lived on your store, treat orphaned JavaScript as in-scope even after BigCommerce’s remote uninstall.

Who is at risk

Shoppers at Master of Malt and other notifying retailers. If you received a notice naming Ribon, Be A Part Of, Fastr, or a BigCommerce application key, assume the Master of Malt field list applies unless your retailer lists something narrower. Watch the email and phone used at checkout, including spam and SMS filters.

Shoppers at stores that had Ribon installed but have not mailed yet. Master of Malt’s “hundreds of other stores” warning is why you stay alert without a letter. Merchants move at legal-review speed. Phishers move the afternoon the BleepingComputer headline drops.

Gift recipients at shipping addresses. The name on the box and the postal address are in the exposed set for Master of Malt. Someone who answers the door can be social-engineered with a “failed whisky delivery” story without ever having placed the order.

BigCommerce merchants who installed Ribon or Ribon 1.5. You are in the notification cohort BigCommerce already contacted if you were on the affected list. Even if you were not, audit Script Manager, theme customizations, and any tag manager for Ribon domains or leftover snippets. Review which other third-party apps hold broad customer-read scopes.

Not automatically every BigCommerce shopper worldwide. The platform was not breached. Stores that never installed Ribon are outside the application-key path described here. Copycat phishing will still try a generic “BigCommerce data breach — verify your card” lure. That is noise, not attestation.

Support agents at affected merchants. Stolen shopper PII becomes inbound ticket fraud: callers who know a real order email and postcode asking for address changes or refunds to a new wallet. Brief support with out-of-band verification before the first convincing call lands.

FreshClick 2024 vs Ribon 2026

BigCommerce merchants have seen this pattern before. In 2024, attackers compromised the third-party FreshClick BigCommerce app and injected payment-skimming code. Electronics accessory maker ZAGG was among the public victims. BigCommerce said then, as now, that its core platform was not breached and removed the compromised app. BreachHistory’s catalog entry is bigcommerce-freshclick2024.

Ribon reuses the supply-chain shape: steal a marketplace app’s trust, hit many merchants at once, let the platform uninstall at scale. The data-path difference is what BigCommerce emphasized. FreshClick / ZAGG centered on capturing payment information at checkout. Ribon centered on using a third-party app key to read existing customer records — with script injection confirmed on a small number of storefronts as parallel abuse of the same credentials.

That distinction changes shopper advice. After FreshClick-style skimming, card replacement and bank alerts dominate. After Ribon-style CRM access, phishing against email and phone dominates, while card exposure stays in the “platform says not exposed; still watch statements if you checked out on an injected storefront” bucket. Merchants should not collapse the two incidents into one slide labeled “Magecart” and stop there.

Same shopper-PII shape shows up off BigCommerce too — see Goose Creek Candle’s 2026 HIBP-indexed customer data. The brand logo on the receipt is not always the system that leaked.

What the companies and regulators said

BigCommerce’s on-record position is the spine: Ribon and Ribon 1.5 credentials compromised; malicious scripts on a small number of storefronts; shopper-data access September 13–17; apps uninstalled; merchants notified; logs going to the developer; core platform not breached; passwords and payment cards stored separately and not exposed.

Master of Malt confirmed shopper access to names, emails, phones, and shipping postal addresses; described the compromised BigCommerce application key; reported to the UK ICO; and warned that hundreds of other stores may be in scope. That ICO report puts a UK regulator clock on at least one merchant’s handling.

Emery Reddy is soliciting potential claimants and says several retailers are notifying customers about Ribon app key theft, without publishing a public victim list in the coverage BleepingComputer cited. Treat law-firm outreach as a signal that notices are circulating, not as a substitute for primary merchant letters. Be A Part Of / Fastr still had no public response at BleepingComputer’s publication.

Phishing and social engineering to expect

Shopper PII from a spirits or general merchandise store is phishing fuel. Expect lures that quote real details:

  • “Master of Malt / [your retailer]: confirm your shipping address after the BigCommerce data breach — click here.”
  • “Your whisky order is on hold with the courier; pay a small redelivery fee.”
  • “Ribon security team: verify your BigCommerce store admin account” (aimed at merchants, not shoppers).
  • SMS that opens with your partial postcode and asks you to “unfreeze” a card BigCommerce already said was not exposed.
  • Voice calls to the shipping-address phone claiming customs clearance for alcohol, complete with your full name.
  • Fake “claim portal” pages that harvest government IDs from people who only wanted status.

What to do after a notice is not “click the link in the scary email to see if you were affected.” Open the retailer’s site by typing the domain you already trust. Use the phone number on a prior packing slip or the retailer’s official contact page. BigCommerce will not need your card CVV to finish a Ribon investigation. Ribon’s developer will not ask shoppers to paste passwords into a Google Form.

Merchants should expect a staff-targeted wave: “BigCommerce Support — emergency re-auth of Ribon replacement app,” complete with a lookalike admin OAuth screen. Verify marketplace security mail through the BigCommerce merchant dashboard you already use, not through a cold email.

What you should do

If you are a shopper

  1. Read any retailer notice carefully. Confirm it names Ribon, a BigCommerce application key, or the September 2026 window before you assume every marketing mail is related.
  2. Treat your checkout email and phone as burned for spear-phishing. Harden that email account; watch SMS filters for courier and “account recovery” traffic.
  3. Do not panic-rotate every payment card solely because of this incident — BigCommerce says passwords and payment card data stored separately were not exposed. Do review statements if you checked out on a store that later admitted storefront script injection.
  4. Warn gift recipients at the shipping address. A “failed delivery” story that knows the postcode is the attack.
  5. Ignore unsolicited claim-status portals. If you want legal advice, you initiate contact with a firm you chose.
  6. Search your inbox for prior BigCommerce-powered store orders so you recognize which brand names phishers might spoof.

If you are a BigCommerce merchant

  1. Confirm whether Ribon or Ribon 1.5 was ever installed. Check BigCommerce’s incident channel and app history, not only the live marketplace listing.
  2. After uninstall, audit Script Manager, theme files, and tag managers for leftover Ribon scripts or unknown third-party JavaScript added in mid-September 2026.
  3. Pull customer-export and API access logs for September 13–17 and preserve them for counsel even if BigCommerce is sharing developer-facing logs.
  4. Prepare a shopper notice that lists concrete fields (follow Master of Malt’s clarity) and states what was not exposed.
  5. Brief support and warehouse teams on out-of-band verification for address changes and refunds.
  6. Review scopes on every remaining third-party app. If an integration can read full customer PII but only needs catalog access, cut the scope.
  7. If you have UK customers, map whether ICO or other regulator duties apply — Master of Malt already set an example by reporting.

If you run a marketplace or ecommerce platform

  1. Treat partner app credentials as crown jewels: rotation, anomaly detection on sudden multi-tenant reads, and kill-switches like the one BigCommerce executed on September 17.
  2. Separate “script write” permissions from “customer PII read” wherever the product model allows. One stolen credential funded both Magecart-style injection and CRM exfiltration here.
  3. Give merchants a post-uninstall orphan-script checklist. Remote app removal without theme hygiene leaves landmines.

Why this BigCommerce data breach matters

Marketplace apps are force multipliers. One developer credential reaches every merchant who clicked Install. Shoppers experience that as a letter from a brand they trust; the failure mode lived one layer down, in Ribon apps and a third-party app key.

“Was the platform breached?” and “was my data accessed?” are different questions. BigCommerce can truthfully say its core platform was not breached while merchants truthfully tell shoppers their names and addresses were read. Both can be accurate. Who pays for notice letters, who faces the ICO, and who gets sued will play out between platform, developer, and merchants. Shoppers still need phishing defenses either way.

For anyone asking what to do after this disclosure: assume the PII fields in the merchant notice are in hostile hands, treat script injection as a narrower risk on the small injected set, and do not wait for a global headcount. The actionable window opened when BigCommerce confirmed the compromise on September 17.

Canonical record and sources

BreachHistory canonical page: https://breachhistory.com/bigcommerce/bigcommerce-ribon2026.

Primary and supporting reporting:

Related BreachHistory records: 2024 FreshClick / BigCommerce marketplace compromise and 2026 Goose Creek Candle customer data (HIBP).