What Happened
Ecommerce platform BigCommerce has notified merchants that attackers compromised credentials for the third-party Ribon (and Ribon 1.5) storefront applications, then used those stolen keys to inject malicious scripts into merchant storefronts and pull data out of connected customer databases. BigCommerce's own infrastructure was not breached — the entry point was the app-level credentials Ribon uses to talk to merchant stores via the platform's API.
UK-based online spirits retailer Master of Malt was among the confirmed affected merchants, and BigCommerce says the exposure potentially extends to hundreds of other stores running the Ribon integration.
Data Exposed
Attackers accessed customer records including:
- Full names
- Email addresses
- Phone numbers
- Shipping postal addresses
BigCommerce confirmed that passwords and payment card data are stored separately from the systems Ribon's credentials touched, and were not part of the exposure.
Timeline
- September 13–17, 2026 — Window of unauthorized access using the compromised Ribon credentials
- September 17, 2026 — BigCommerce confirmed the credential compromise and uninstalled the affected applications from impacted stores
Company Response
BigCommerce said: "Acting in the best interest of our customers... we uninstalled the application from affected stores to revoke the attacker's access, notified those merchants directly, and are providing log data to support the developer's investigation."
The company has emphasized that this was a third-party app credential compromise, not a breach of BigCommerce's own platform — a distinction that matters for merchants assessing their own liability, but doesn't change the fact that customer PII moved through Ribon's access into attacker hands.
Why This Matters
This is another entry in a growing pattern: platform-native security controls don't cover the blast radius of every app a merchant installs. A compromised set of API credentials for a single storefront customization tool was enough to reach into customer data across potentially hundreds of independently-run stores, none of which had a direct security failure of their own. Merchants running any third-party BigCommerce app should treat this as a prompt to review installed integrations, rotate any credentials the app vendor controls, and confirm what data scope each app actually needs versus what it's been granted.
Remediation
- If your store uses Ribon or Ribon 1.5, confirm it has been removed or reinstalled with rotated credentials before restoring functionality.
- Review BigCommerce's app permissions for any other third-party integrations and scope down access that isn't required.
- Notify your own customers if you're within the confirmed exposure window and jurisdictional breach-notification requirements apply.
- Watch for injected-script indicators (unexpected storefront JavaScript, altered checkout behavior) even after removing the compromised app.