Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

BigCommerce alerts merchants to data breach linked to Ribon apps

BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for the third-party Ribon and Ribon 1.5 applications. The credentials were used to inject malicious scripts into a small number of online stores and access shopper data.

BigCommerce confirmed the compromise on September 17, 2026, and removed the applications from affected stores. The company said the attacker accessed data in BigCommerce environments between September 13 and September 17.

UK-based online spirits retailer Master of Malt said the exposed information included shoppers' full names, email addresses, phone numbers, and shipping postal addresses. It reported the incident to the UK Information Commissioner's Office and said the impact could extend to hundreds of other stores.

BigCommerce said it supports more than 1,200 third-party applications and integrations, including Ribon, which is operated by Be A Part Of, a Fastr brand. The company said account passwords and payment card information are stored separately and were not exposed. BigCommerce also said its systems and platform were not breached.

The incident differs from a 2024 breach involving ZAGG, in which attackers used the FreshClick BigCommerce application to inject payment-skimming code. BleepingComputer said Be A Part Of and Fastr had not responded by publication time.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.