BigCommerce merchants exposed after third-party Ribon app credentials stolen
EditorialBy TrustList Editorial
BigCommerce confirmed on 17 September 2026 that stolen third-party Ribon app credentials let attackers inject scripts into some storefronts, exposing shopper names, emails, phones and addresses; passwords and card data were not affected.
About BigCommerce merchants exposed after third-party Ribon app credentials stolen
BigCommerce merchants exposed after third-party Ribon app credentials stolen
17 September 2026 — BigCommerce, the ecommerce SaaS platform, confirmed on 17 September 2026 that credentials belonging to two third-party storefront apps, Ribon and Ribon 1.5, built by "Be A Part Of," a Fastr company, had been compromised and used to inject malicious scripts into a small number of merchant storefronts. According to reporting on the incident, the unauthorized access ran between 13 and 17 September 2026; BigCommerce says its own platform and stored payment data were not breached.
What was exposed, and what was not
- Shopper data taken through the compromised apps included full names, email addresses, phone numbers and shipping postal addresses, according to affected merchants' own notices.
- BigCommerce says account passwords and payment card information are stored separately from the affected app data and were not exposed in this incident.
- BigCommerce removed the Ribon apps from affected stores to cut off the attacker's access, notified the merchants it identified as affected, and says it provided log data to support the app developer's own investigation.
If you run a BigCommerce storefront
- Check whether your store has ever installed Ribon or Ribon 1.5, even if it is not currently active — the exposure window covers app credentials, not only apps currently in use.
- One affected merchant, Master of Malt, reported the incident to the UK Information Commissioner's Office and has said the exposure may extend well beyond its own customers to potentially hundreds of other stores using the same apps — treat "a small number of merchants" as BigCommerce's current estimate, not a final count.
- If you use any third-party storefront app from any developer, this incident is a reason to review what data each app can reach and whether you still need it installed, since the exposure came through app-level credentials rather than a platform-wide breach.
Sources
- BleepingComputer: BigCommerce alerts merchants of data breach linked to Ribon apps — 21 September 2026
- SecurityWeek: BigCommerce Data Stolen via Ribon Apps Hack — 19 September 2026
- SC Media: BigCommerce merchants impacted by third-party app data breach — 19 September 2026
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.