Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

BigCommerce warns customers after third-party app cyberattack

BigCommerce has warned customers about a cyberattack involving the third-party ecommerce app Ribon. According to Master of Malt, unidentified threat actors compromised a BigCommerce application key held by Ribon and used it to access customer data.

The attack began on September 13, 2026, and access was revoked four days later, on September 17. BigCommerce said credentials for Ribon and Ribon 1.5, operated by “Be A Part Of,” a Fastr company, were compromised. The company said malicious scripts were injected into a small number of merchant storefronts, and that affected stores were removed from the app to cut off access.

Master of Malt said Ribon was installed on hundreds of BigCommerce stores, suggesting the incident may have affected more merchants than BigCommerce’s wording indicates. The retailer said attackers accessed customers’ names, email addresses, phone numbers, and addresses, but not passwords or payment information, which were stored in a separate system.

Master of Malt reported the incident to the UK Information Commissioner’s Office. BigCommerce said affected companies were contacted and that there was no further risk of compromise. Emery Reddy warned that customers could face phishing and scam attempts.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.