Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2996+ Articles
168+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. BigCommerce Data Stolen via Ribon Apps Hack
BigCommerce Data Stolen via Ribon Apps Hack
NEWS

BigCommerce Data Stolen via Ribon Apps Hack

A compromised BigCommerce application key held by third-party app Ribon exposed merchant customer data across affected storefronts.

Dylan H.

News Desk

September 22, 2026
5 min read

BigCommerce has begun notifying merchants that customer data was stolen after attackers compromised API credentials belonging to Ribon, a storefront and shopping-experience optimization app installed on hundreds of BigCommerce stores. Rather than breaching BigCommerce's own platform, the attackers reached customer records indirectly — through a trusted third-party app's access key. It is the kind of supply-chain path that has become a recurring theme across e-commerce platforms this year.

What Happened

Ribon and its companion app Ribon 1.5 are owned and operated by Be A Part Of, a Fastr company. According to BigCommerce, the applications' API credentials were compromised as a result of "a Fastr system compromise" — meaning the intrusion point was on the app vendor's side, not BigCommerce's infrastructure.

With the stolen key in hand, the attackers accessed customer data stored inside BigCommerce between roughly 17:21 BST on September 13 and 21:12 BST on September 17, 2026, reportedly pulling records "page by page" until the credential was revoked. BigCommerce says the same access was also used to inject malicious scripts into a small number of merchant storefronts.

The data exposed included customer names, email addresses, phone numbers, and physical addresses. UK spirits retailer Master of Malt, one of the first merchants to publicly disclose the incident, said passwords, card numbers, and other payment details were not affected, since that information is held in a separate system that was not touched.

BigCommerce confirmed the credential compromise on September 17 and began notifying affected merchants on September 18, stating it "acted in the best interest of our customers and their shoppers by uninstalling the application from affected stores to revoke the attacker's access." Master of Malt said it received direct confirmation from Fastr on the evening of September 18 and has since reported the incident to the UK Information Commissioner's Office. Neither Be A Part Of nor Fastr had issued a public statement at the time of reporting.

Third-Party App Ecosystem Risk

BigCommerce's app marketplace supports more than 1,200 third-party integrations, each granted some level of API access to merchant and customer data to do its job — personalizing storefronts, running promotions, syncing inventory, and more. That convenience comes with a tradeoff: every installed app is effectively an extension of the platform's trust boundary.

When an app's credentials are scoped broadly and shared across many merchant installs, compromising a single vendor can expose data from every store that uses it — turning one vendor breach into a mass-merchant incident. Master of Malt has said it plans to push BigCommerce for tighter API authorization controls, arguing that no single third-party application should be able to reach customer records this broadly.

This incident also echoes a 2024 breach involving electronics accessory maker ZAGG, in which attackers used a compromised third-party app called FreshClick to inject payment-skimming code into storefronts. Both cases share the same underlying pattern: the platform itself held, but attackers never needed to breach it directly — a trusted app's credentials were enough.

Why This Matters

For merchants running BigCommerce, Shopify, WooCommerce, or any platform with an open app ecosystem, this incident is a reminder that the platform's own security posture is only part of the picture. A store's actual exposure is the sum of every installed app's access, and that access often persists quietly in the background long after the app was first configured.

Merchants frequently lose track of exactly what data each installed app can reach, especially for apps installed years ago or maintained by small third-party vendors with their own, less mature security programs. A single stolen app credential can silently expose customer PII across every store running that integration — with no warning until the vendor (or a security researcher) discloses it.

Protective Measures

Merchants using app marketplaces on any e-commerce platform should consider the following steps:

  • Audit installed app permissions regularly. Review what data and API scopes each installed app can access, and remove apps that are no longer in active use.
  • Favor least-privilege scoping. Where the platform allows it, restrict apps to the minimum data and endpoints they need rather than accepting broad default access.
  • Rotate API keys and credentials on a schedule, and immediately after any vendor discloses a security incident — even if your store wasn't named as affected.
  • Monitor app-level API activity for unusual volume or timing (such as bulk data pulls outside normal business hours), which can be an early indicator of credential misuse.
  • Track vendor security disclosures. Subscribe to status pages or security advisories for critical apps, and have a plan to quickly disable an app if its vendor reports a compromise.
  • Separate sensitive data stores. Keeping payment credentials in a system isolated from general customer PII, as Master of Malt described, limits the blast radius when an app-level credential is compromised.
#Data Breach#E-commerce#Third-Party Risk#BigCommerce

Related Articles

BigCommerce Alerts Merchants of Data Breach Linked to Ribon Apps

Attackers used stolen Ribon app credentials to inject scripts into BigCommerce storefronts and pull customer contact data.

3 min read

Vercel Breach Tied to Context AI Hack Exposes Limited

Vercel's security breach originated from the compromise of Context.ai, a third-party AI tool used by a company employee, allowing attackers to gain...

4 min read

SickKids Hospital Hit by Cybercriminals Again as Employee Data Stolen

Canada's Hospital for Sick Children suffered a second cyber incident with employee data stolen via a compromised third-party app, four years after a 2022 ransomware attack.

4 min read
Back to all News