Back to Feed
Supply ChainSep 22, 2026

BigCommerce Data Stolen via Ribon Apps Hack

Hackers stole BigCommerce customer data via a compromised Ribon app access key.

Summary

BigCommerce, an e-commerce platform provider, has reported a data breach affecting its merchants' customers. Attackers exploited a compromised BigCommerce application key belonging to Ribon, a third-party app developed by Be A Part Of (owned by Fastr). Between September 13 and September 17, the attackers used this key to access and download customer data, including names, email addresses, phone numbers, and physical addresses from affected BigCommerce stores. BigCommerce has since revoked the compromised credentials and uninstalled the Ribon application from affected stores.

Full text

Enterprise eCommerce platform BigCommerce fell victim to a supply chain attack that led to customer data theft. BigCommerce is a SaaS provider that enables merchants to build and manage online stores. It hosts the stores, provides backend tools, and handles server security. Late last week, the company started notifying merchants that customer data was stolen after hackers compromised a BigCommerce application key held by Ribon, a storefront and shopping experience optimization app developed by Fastr-owned Be A Part Of. The hackers used the key between September 13 and September 17 to access customer data, including names, email addresses, phone numbers, and addresses, UK spirits vendor Master of Malt notes in a technical write-up. According to Master of Malt, the hackers downloaded customer data working ‘page by page’ until the compromised key was revoked on September 17, one day after the Ribon developers became aware of its misuse. BigCommerce started notifying merchants of the incident on September 18, after the key had been disabled and the targeted Ribon applications uninstalled.Advertisement. Scroll to continue reading. “The attack was against Ribon, which was installed on hundreds of BigCommerce stores. Once the attackers compromised an access key from Ribon, they used it to access data held inside BigCommerce,” Master of Malt said. BigCommerce, which provides support for over 1,200 third-party applications, has confirmed that the hackers compromised the Ribon application credentials. “On September 17, 2026, Commerce confirmed that API credentials belonging to third-party applications Ribon and Ribon 1.5, owned and operated by “Be A Part Of,” a Fastr company, had been compromised due to a Fastr system compromise. The credentials were used to inject malicious scripts into a small number of merchant storefronts. This was not a breach of Commerce systems or the BigCommerce platform,” BigCommerce told SecurityWeek. “While the Ribon applications are third-party apps independently installed by the merchant where the relationship occurs between the merchant and the third-party application, Commerce acted in the best interest of our customers and their shoppers by uninstalling the application from affected stores to revoke the attacker’s access and limit harm, notifying affected merchants directly, and providing log data to support the developer’s own investigation,” the company added. It is unclear how Ribon was compromised and whether other entities were also affected, as neither Be A Part Of nor Fastr have publicly acknowledged the incident. SecurityWeek has emailed both companies for additional information and will update this article if they respond. Related: CrowdSec Confirms Source Code Stolen in Supply Chain Attack Related: 23 Million User Records Compromised in Gyazo Data Breach Related: Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom Related: First Agentic AI Data Breach Reported to Spanish Regulator Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ StealerRatHat Android Trojan Uses AI for AutomationCrowdSec Confirms Source Code Stolen in Supply Chain AttackOrganizations Warned of 3 Exploited Linux Kernel VulnerabilitiesTigerByte Cyber Emerges From Stealth With $3 Million in FundingNightmareStresser DDoS Service Disrupted in International OperationBrevo Supply Chain Attack Injects Malware Into 100,000 WebsitesCritical Orkes Conductor Vulnerability Exploited in Attacks Latest News Cyera Raises $400 Million at $12+ Billion ValuationNightmare Eclipse Drops New Microsoft Defender Exploit After Revealing IdentityOnly 13% of OT Network Segments Are Fully Isolated: AnalysisRecent ZyXEL Switch Vulnerability Exploited by Chinese HackersMalicious B-tree NPM Package Accumulates Millions of DownloadsWordPress Patches ‘Click2Shell’ VulnerabilityJapan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider SchemeUS Proposes AI Incident Alert System in Talks With China, Bessent Says Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveVeritas Capital has appointed Joel Fulton as Chief Information Security Officer.incident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.Ruben D. Chacon has joined ADM as Vice President and Global CISO.More People On The MoveExpert Insights “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email

Entities

BigCommerce (product)Ribon (product)Be A Part Of (vendor)Fastr (vendor)Master of Malt (product)