Multiple merchants using BigCommerce discovered unauthorized access to customer information following a compromise of credentials belonging to Ribon, a third-party application integrated with the ecommerce platform. On September 17, the SaaS provider identified the credential theft and immediately uninstalled the affected applications to cut off attacker access.

Master of Malt, a UK-based online spirits retailer operating on BigCommerce, was among the affected merchants and disclosed that attackers accessed shopper records. The unauthorized access window spanned from September 13 through September 17, according to BigCommerce's account of the incident.

According to Master of Malt's disclosure, the compromised data included customer full names, email addresses, phone numbers, and shipping postal addresses. The retailer explained the attack vector: "It looks like hackers were able to compromise a BigCommerce Application key held by Ribon, which they were able to use to gain access to customer data held on their system."

BigCommerce operates a marketplace of more than 1,200 third-party applications and integrations. Ribon, the compromised application in this incident, is owned and operated by Be A Part Of, a subsidiary of Fastr, which focuses on shopping experience optimization.

The platform emphasized that account passwords and payment card information are stored separately from other customer data and were not exposed in this incident. In a statement to BleepingComputer, BigCommerce clarified: "On September 17, 2026, Commerce confirmed that credentials belonging to third-party applications Ribon and Ribon 1.5, owned and operated by 'Be A Part Of,' a Fastr company, had been compromised and used to inject malicious scripts into a small number of merchant storefronts."

BigCommerce stressed that neither its systems nor the platform itself experienced a breach. The company stated: "Acting in the best interest of our customers and their shoppers, we uninstalled the application from affected stores to revoke the attacker's access, notified those merchants directly, and are providing log data to support the developer's investigation."

Master of Malt reported the breach to the UK Information Commissioner's Office and warned that the impact likely extends beyond its own customer base to potentially hundreds of additional retailers. Law firm Emery Reddy has begun seeking claimants affected by the incident, noting that multiple retailers are currently notifying their customers about the data exposure stemming from the Ribon app credential theft, though specific retailer names have not been disclosed.

Attempts to reach Be A Part Of and Fastr for additional details about the compromise were unsuccessful at the time of publication.

This incident parallels a 2024 breach involving electronics accessory manufacturer ZAGG, where attackers compromised the FreshClick BigCommerce application and deployed payment-skimming code on the company's storefront. BigCommerce responded similarly in that case by removing the compromised app from customer environments.

The Ribon incident differs from the ZAGG attack in its methodology. While the ZAGG attackers captured payment information during the checkout process, the Ribon attackers leveraged a compromised application key to directly access existing customer records already stored within BigCommerce.