Skip to content
TrustList
News

BigCommerce publishes notice on compromised Fastr app credentials

Editorial

By TrustList Editorial

BigCommerce’s Trust Center now says compromised Fastr app credentials, not its platform, exposed shopper data. Merchants with Fastr apps should check app scopes, question Fastr and weigh ICO reporting.

About BigCommerce publishes notice on compromised Fastr app credentials

BigCommerce publishes notice on compromised Fastr app credentials

23 September 2026 — BigCommerce has posted a security notice in its public Trust Center about the compromise of two third-party storefront apps, Ribon and Ribon 1.5. The notice shows no date on screen, but the page's own data records it as created on 23 September 2026. It is the first statement on the incident that we have found on a BigCommerce domain. Until now the company's account had reached the public only through merchant emails quoted in the press.

What the notice says

The company, which now calls itself Commerce, says it confirmed on 17 September 2026 that API credentials belonging to the app developer Be A Part Of, a Fastr company, had been compromised "as a result of a Fastr system compromise". It says this was not a breach of its own systems or of the BigCommerce platform. It also says a merchant could only be affected if it had independently installed a Fastr-developed app. The company admits it has limited visibility into whether actions taken by the app were legitimate or the work of the attacker, and directs merchants to Fastr's support team.

What has been reported

BleepingComputer (21 September) and SecurityWeek (22 September) reported that the stolen credentials were used between 13 and 17 September. They said BigCommerce uninstalled the apps from affected stores and notified merchants, and that shopper names, email addresses, phone numbers and shipping addresses were exposed. According to those reports, BigCommerce told merchants that passwords and payment card data are stored separately and were not exposed.

The UK drinks retailer Master of Malt told customers it had been affected. According to teiss (23 September), it has also reported the incident to the Information Commissioner's Office. When we checked on 24 September, neither Fastr nor Be A Part Of had published a statement on its own website. Both outlets said the companies had not answered requests for comment.

Who is affected

Any BigCommerce merchant that had Ribon, Ribon 1.5 or another Fastr-built app installed should assume it may be affected until Fastr says otherwise. Shoppers of those stores may receive targeted phishing that uses their real name and address.

What buyers should do

  • Check your control panel for Fastr-developed apps, including any removed on your behalf. Ask Fastr in writing what data its app accessed on your store, and when.
  • If you are a UK or EU controller and shopper data was taken, decide whether the 72-hour reporting duty under UK GDPR applies. Record your reasoning either way.
  • Warn customers about phishing calls and emails that use their details, as Master of Malt did, and never ask them to confirm information.
  • Review every installed app's API scopes. Remove apps you no longer use, and ask the rest which customer fields they read and how they protect their credentials.
  • Add app-developer compromise to your supplier risk register. A platform can be secure while a plug-in with wide read access is not.

Sources