Skip to content
TrustList
News

BigCommerce merchants exposed after third-party Ribon app credentials stolen

Editorial

By TrustList Editorial

BigCommerce confirmed on 17 September 2026 that stolen third-party Ribon app credentials let attackers inject scripts into some storefronts, exposing shopper names, emails, phones and addresses; passwords and card data were not affected.

About BigCommerce merchants exposed after third-party Ribon app credentials stolen

BigCommerce merchants exposed after third-party Ribon app credentials stolen

17 September 2026 — BigCommerce, the ecommerce SaaS platform, confirmed on 17 September 2026 that credentials belonging to two third-party storefront apps, Ribon and Ribon 1.5, built by "Be A Part Of," a Fastr company, had been compromised and used to inject malicious scripts into a small number of merchant storefronts. According to reporting on the incident, the unauthorized access ran between 13 and 17 September 2026; BigCommerce says its own platform and stored payment data were not breached.

What was exposed, and what was not

  • Shopper data taken through the compromised apps included full names, email addresses, phone numbers and shipping postal addresses, according to affected merchants' own notices.
  • BigCommerce says account passwords and payment card information are stored separately from the affected app data and were not exposed in this incident.
  • BigCommerce removed the Ribon apps from affected stores to cut off the attacker's access, notified the merchants it identified as affected, and says it provided log data to support the app developer's own investigation.

If you run a BigCommerce storefront

  • Check whether your store has ever installed Ribon or Ribon 1.5, even if it is not currently active — the exposure window covers app credentials, not only apps currently in use.
  • One affected merchant, Master of Malt, reported the incident to the UK Information Commissioner's Office and has said the exposure may extend well beyond its own customers to potentially hundreds of other stores using the same apps — treat "a small number of merchants" as BigCommerce's current estimate, not a final count.
  • If you use any third-party storefront app from any developer, this incident is a reason to review what data each app can reach and whether you still need it installed, since the exposure came through app-level credentials rather than a platform-wide breach.

Sources