"It looks like hackers were able to compromise a BigCommerce Application key held by Ribon, which they were able to use to gain access to customer data held on their system," Master of Malt stated.
BigCommerce: what happened and the platform response
On September 17, 2026, BigCommerce confirmed that credentials belonging to third‑party applications Ribon and Ribon 1.5 had been compromised and used to inject malicious scripts into a small number of merchant storefronts, the company told BleepingComputer. BigCommerce said it immediately removed the affected applications from customer stores, revoked the attacker's access and notified impacted merchants directly. The company also said it provided log data to support the developer's investigation and underlined that its systems or the BigCommerce platform were not breached.
Master of Malt: shopper records accessed
UK online spirits retailer Master of Malt received direct notification from BigCommerce and reported that the attacker accessed shopper information. The company said impacted shopper details include full names, email addresses, phone numbers, and shipping postal addresses. Master of Malt has reported the incident to the UK Information Commissioner’s Office (ICO) and warned the exposure may extend beyond its own customers, potentially affecting hundreds of other stores.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleRibon, Be A Part Of and Fastr: credentials used to access data
BigCommerce identified the compromised applications as Ribon and Ribon 1.5, which are owned and operated by "Be A Part Of," a Fastr company. BigCommerce noted it supports over 1,200 third‑party applications and integrations, including Ribon, which is described in the reporting as an application specialized in shopping experience optimization. According to BigCommerce, the attacker used the compromised credentials to access shopper data in BigCommerce environments between September 13 and September 17, 2026.
BleepingComputer contacted Be A Part Of and Fastr for comment but had not received a response by publication time.
How this incident differs from the 2024 ZAGG / FreshClick breach
The reporting draws a direct comparison to a 2024 incident affecting electronics accessory maker ZAGG, where attackers compromised the third‑party FreshClick BigCommerce app and injected payment‑skimming code into its online store. In that case attackers captured payment information entered during checkout. By contrast, the Ribon incident involved use of a compromised application key to access existing customer records through the BigCommerce platform rather than capturing payment information at checkout. BigCommerce reiterated that account passwords and payment card information are stored separately and that this type of data was not exposed in the Ribon incident.
What this means for merchants, the ICO, and shoppers
- Merchants: Retailers using third‑party BigCommerce apps that rely on application keys should expect direct notifications from BigCommerce if they were affected; Master of Malt has already notified its customers and reported the incident. Law firm Emery Reddy is publicly seeking potential claimants linked to the incident, saying several retailers are notifying customers about data exposure tied to the Ribon app key theft.
- Regulators (ICO): Master of Malt has reported the breach to the UK Information Commissioner’s Office, signaling that affected UK customers will be brought to the attention of national data protection authorities and that regulatory follow‑up is in motion.
- Shoppers: According to merchant notifications cited by reporting, exposed shopper details include full names, email addresses, phone numbers and shipping postal addresses; BigCommerce stated that account passwords and payment card information were not exposed.
This episode underscores two concrete points observable in the record: first, attackers are reusing a playbook that targets third‑party application credentials to reach merchant data; second, the practical containment step taken by BigCommerce was to remove the compromised app instances while asserting the broader platform itself was not breached. Questions remain about the ultimate scope of stores affected and the developer follow‑up from Be A Part Of and Fastr — matters BleepingComputer sought comment on but did not receive answers to by publication.
Original reporting: https://www.bleepingcomputer.com/news/security/bigcommerce-alerts-merchants-of-data-breach-linked-to-ribon-apps/




