BigCommerce has notified affected merchants after attackers used compromised credentials associated with Ribon, a third-party storefront optimization application, to access customer information held through the e-commerce platform.
The incident was attributed to a compromise at Fastr, the parent company of Be A Part Of, which operates the Ribon and Ribon 1.5 applications. BigCommerce said the event did not involve a breach of its own systems or platform infrastructure.
Third-Party Credentials Used in Attack
According to BigCommerce, the compromised application API credentials were used between September 13 and September 17, 2026. The company said attackers used the access to place malicious scripts on a limited number of merchant storefronts.
UK retailer Master of Malt, which published details of its response, said the attackers also accessed customer records and appeared to retrieve information incrementally. The potentially exposed data included customer names, email addresses, telephone numbers, and physical addresses.
Master of Malt said the activity ended after the affected key was revoked on September 17. BigCommerce began informing merchants the following day, after disabling the credentials and removing the affected applications from impacted stores.
Response and Open Questions
BigCommerce said it removed Ribon applications from affected merchants as a protective measure, despite the apps being independently installed and managed through the relationship between merchants and the third-party developer. The company also provided relevant log data to support the developer's investigation.
- Compromised credentials belonged to the Ribon and Ribon 1.5 apps.
- Attackers reportedly accessed customer data and injected malicious storefront code.
- BigCommerce said its core platform was not breached.
- The number of affected merchants and shoppers has not been disclosed.
It remains unclear how the Ribon credentials were obtained, whether data was accessed from additional merchants, or whether other organizations connected to the developer were affected. Neither Be A Part Of nor Fastr had publicly detailed the compromise at the time of reporting.
