
BigCommerce Merchants Hit by Data Breach via Ribon App
.webp)
Attackers have stolen an access key for Ribon, a third-party app that online stores install to improve the shopping experience. They used it to reach shopper records at multiple retailers that run on BigCommerce. The resulting data breach has BigCommerce merchants warning customers that attackers accessed their names, emails, phone numbers and postal addresses. BigCommerce says attackers never compromised its own platform, and it removed the app from affected stores on September 17.
How the Data Breach Reached BigCommerce Stores
Ribon and its newer version, Ribon 1.5, belong to Be A Part Of, a brand of digital commerce firm Fastr. Merchants that install the apps grant them API access to store data. Once the attacker held a valid key for those apps, the platform treated every request as legitimate.
The unauthorized access began at 17:21 BST on September 13 and ran until 21:12 BST on September 17. BigCommerce confirmed the credential compromise that day and uninstalled the apps from affected stores to cut off access. It also alerted the affected merchants directly. The company says it is sharing log data with the developer to support its investigation.
Besides pulling customer records, the attacker used the stolen credentials to inject malicious scripts into a small number of storefronts. Neither BigCommerce nor the app's owner has explained what those scripts did. Be A Part Of and Fastr have not commented publicly on the incident.
Master of Malt Confirms Customer Exposure
UK online spirits retailer Master of Malt has gone public about its exposure. It told customers that the data breach reached its BigCommerce store through the Ribon app. Its founder emailed affected customers on the evening of September 18, a few hours after the platform alerted the retailer. The message said attackers had compromised a BigCommerce application key held by Ribon and used it to reach customer data.
The exposed fields include full names, email addresses, phone numbers and shipping addresses. Passwords and payment card details sit in a separate system. Both the retailer and the platform say the attacker never touched it. Master of Malt has also reported the incident to the UK Information Commissioner's Office.
The retailer believes the impact could reach hundreds of other stores that ran the app. No one has confirmed that figure, and no other merchants have come forward by name. However, a US law firm says several retailers have already sent breach notices linked to the stolen key.
Why a Single App Key Reached So Much Data
Nobody had to break into BigCommerce itself to cause this data breach. Ecommerce platforms let merchants extend their stores through app marketplaces. BigCommerce alone supports more than 1,200 third-party apps and integrations. Each installed app receives its own credentials and a set of permissions over store data.
So an app becomes a standing door into every store that installed it. If the app's permissions cover customer records, anyone holding its key can read those records across its whole install base. The merchant never sees the attack, because the traffic arrives from an app they approved.
After the data breach, Master of Malt said it will push BigCommerce for more granular API authorization controls. The retailer argues that a single compromised credential should never unlock customer data at this scale. That request goes to the center of how platforms scope marketplace apps, and other merchants may well add their voices.
An Echo of the 2024 ZAGG Incident
BigCommerce has faced a similar pattern before. In 2024, attackers compromised FreshClick, another BigCommerce app, and planted payment-skimming code on the store of accessory maker ZAGG. BigCommerce said then that attackers had not breached its platform, and it removed the compromised app from customer stores.
The two cases differ in what the attackers took. In the ZAGG incident, the skimmer captured card details as shoppers typed them at checkout. In the data breach now affecting BigCommerce retailers, the attacker pulled records that already existed. The attacker did not need to wait for a single purchase.
That difference changes the risk profile for shoppers. Card data loses its value once banks cancel the cards. Names, phone numbers and home addresses stay valid for years. Attackers can reuse them in phishing and social engineering long after the incident itself closes.
What Merchants and Shoppers Should Do Now
BigCommerce store owners can cut their exposure to a similar data breach by auditing installed apps. Removing any app no longer in use is the first step. For the rest, check which permissions each app holds and if it truly needs access to customer records. Merchants that ran Ribon should also ask the platform if their store appears in its logs, even without a notice.
For shoppers caught up in the data breach at BigCommerce stores, the main risk is targeted phishing. A message that knows your name and address and mentions a real order looks far more credible than generic spam. Treat unexpected emails, texts and calls about refunds or delivery problems with caution. Contact the retailer through its official website instead of clicking links in a message.
Shoppers do not need to change passwords because of this incident, since the attacker did not reach them. Even so, the exposed details can support later account takeover attempts through password resets or phone-based scams. Turning on two-factor authentication for shopping and email accounts closes off much of that risk.
An Investigation Still Missing Key Answers
The full reach of the incident remains unclear. Nobody has confirmed how many stores ran Ribon when the key went missing. The attacker's entry point and the purpose of the injected scripts also remain unknown. Answers on those points will have to come from Be A Part Of and Fastr, which have yet to speak.
Until then, the data breach at BigCommerce merchants stands as a clear case of third-party risk in ecommerce. The platform and the payment systems held, yet shopper data still left through an app merchants had trusted. For retailers, the lesson sits in their own app list, where each integration carries access they may have forgotten granting.
Subscribe to receive the latest blog posts to your inbox every week.