BigCommerce has notified multiple merchants of a data breach after attackers compromised credentials tied to the third-party Ribon applications and used them to inject malicious scripts into online storefronts. The ecommerce platform confirmed the credential compromise on September 17 and quickly removed the affected apps to cut off attacker access.

UK-based online spirits retailer Master of Malt is among the merchants notified. The company said the attacker used the stolen credentials to access shopper data in its BigCommerce environment between September 13 and September 17. Exposed information reportedly includes full names, email addresses, phone numbers, and shipping postal addresses. Master of Malt said the attacker appeared to have compromised a BigCommerce application key held by Ribon, which was then used to reach customer data stored on the platform.

How the attack happened

Ribon and Ribon 1.5 are third-party applications built by Be A Part Of, a brand operated by Fastr, and used by merchants for shopping experience optimization. BigCommerce supports more than 1,200 third-party apps and integrations, and confirmed that credentials for these two specific Ribon apps were compromised and abused to inject malicious scripts into a small number of merchant storefronts.

BigCommerce emphasized that its own systems and platform were not breached. The company said it uninstalled the app from affected stores to revoke attacker access, directly notified impacted merchants, and is providing log data to support the app developer’s investigation. BigCommerce also noted that account passwords and payment card data are stored separately and were not exposed in this incident.

Wider impact possible

Master of Malt reported the incident to the UK Information Commissioner’s Office and warned that the breach may extend well beyond its own customer base, potentially affecting hundreds of other stores using the Ribon apps. Law firm Emery Reddy said it is seeking potential claimants connected to the incident, stating that several retailers are currently notifying customers about data exposure linked to the stolen Ribon app key, though it did not name specific companies.

BleepingComputer reported it contacted Be A Part Of and Fastr for comment but had not received a response by publication time.

Echoes of a past incident

The breach resembles a 2024 incident affecting ZAGG, where attackers compromised the third-party FreshClick BigCommerce app to inject payment-skimming code. In that case, BigCommerce similarly stated its platform was not breached and removed the compromised app. The key difference this time is that attackers used the stolen Ribon application key to access existing customer records directly, rather than skimming payment details entered at checkout.