BigCommerce Ribon was at the center of a data breach when attackers gained access to third-party app credentials and used them to access customer data on online stores. The case involved the Ribon app, not a breach of the platform's core systems.
According to BleepingComputer, BigCommerce notified affected merchants on September 17. The company said that the credentials of the Ribon and Ribon 1.5 apps had been compromised and were used to access shopper data, as well as to introduce malicious scripts to a small number of stores.
See also: Supply chain attacks on Open-Source software

How the BigCommerce Ribon Breach Played Out
The access period is set to run from September 13 to September 17. Master of Malt, one of the merchants that publicly notified its customers, said the attackers appeared to have compromised a BigCommerce application key held by Ribon. The key was revoked on September 17, at which point access was suspended.
Ribon and Ribon 1.5 are owned and operated by Be A Part Of, which is described as a brand of Fastr. The app is used for shopping experience optimization features. The incident shows how a credential on a partner service can pose a risk to multiple stores at once, without the e-commerce provider itself being compromised.
BigCommerce said its platform and systems were not compromised. It has removed or uninstalled the affected app from stores, regained control of access, and sent log data to support the developer's investigation. The exact extent remains unknown, as no number of stores or customers affected has been disclosed.
Incident architecture is particularly important for businesses that rely on add-on applications. A service may need access to order or customer data to function, but these permissions should be limited, recorded, and easily revoked. Using a key that remains active for a long time increases an attacker's window of action.
BigCommerce says it provides affected merchants with logs to track actions taken on each store. This allows businesses to look for code changes, unusual access, and data extraction attempts. However, the lack of a published total means users can't yet accurately assess the extent of the breach.

What data was exposed to customers?
In a statement released by Master of Malt, names, email addresses, phone numbers and postal addresses were listed. The company clarified that passwords and card details were kept on a separate system and were not accessible through the incident.
This distinction is important, but it should not be interpreted as a complete absence of risk. Contact information and addresses can be exploited for targeted phishing, phone scams, or messages impersonating well-known businesses. Master of Malt’s public note urges customers to be especially cautious of requests to click on links, codes, or payment information.
See also: Hackers steal ZAGG customers' credit cards in breach
There is no public list of affected stores yet. Therefore, merchants should not limit themselves to a quick check of the app, but consider what permissions it had, what data it could read, and whether any unusual changes occurred during the period in question. Informing customers should be based on confirmed findings, not assumptions.
What merchants and consumers should do
Merchants using BigCommerce Ribon or Ribon 1.5 should check if the app remains installed, review logs, and confirm that there are no unknown scripts in the store. Revoking keys, reviewing app permissions, and removing unnecessary services will reduce the likelihood of recurrence.

Consumers who have received a notification are advised not to respond to messages requesting codes or card details and to contact the store from its official website, not from a link contained in a message. The SecNews technical team also recommends activating two-factor authentication where available and carefully monitoring suspicious phone calls.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: MageCart attacks target hundreds of legacy Magento sites
Until a more complete assessment is made public, the BigCommerce Ribon incident should be treated as a supply chain breach of unknown total scope. Removing the application and revoking the key limited access, but the exposed contact information can still be used in phishing attacks.
