Close Menu
Mozbot
    Facebook X (Twitter) Instagram
    Button
    MozbotMozbot
    Facebook X (Twitter) Instagram YouTube
    • About us
    • Technology
    • Gadgets
    • Apps & Software
      • Computing
    • News
    • Contact Us
    • Article Submissions
    Mozbot
    Home » News » BigCommerce Ribon app breach exposes shoppers at Master of Malt and beyond
    Technology

    BigCommerce Ribon app breach exposes shoppers at Master of Malt and beyond

    Gary BehanBy Gary Behan30/09/2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    BigCommerce Ribon app breach
    Share
    Facebook Twitter Pinterest Reddit WhatsApp Email

    The BigCommerce Ribon app breach has prompted the ecommerce platform to alert a number of merchants after attackers stole credentials for third-party Ribon applications and used them to inject malicious scripts into online storefronts. BigCommerce confirmed the credential compromise on 17 September 2026 and immediately uninstalled the affected apps from merchants’ stores.

    The window of exposure ran from 13 September to 17 September, during which the attacker used the compromised credentials to access shopper data held within BigCommerce environments. According to SecurityWeek, BigCommerce began formally notifying affected merchants on 18 September, after the compromised application key had been disabled and the Ribon and Ribon 1.5 apps uninstalled.

    What data was accessed in the BigCommerce Ribon app breach

    UK-based online spirits vendor Master of Malt is among the merchants that received a breach notification. The retailer confirmed that the attacker accessed shopper information, with impacted data including full names, email addresses, phone numbers, and shipping postal addresses. Passwords and payment card data were not exposed: BigCommerce stores that type of information separately, and it was not reachable via the compromised application key.

    ‘It looks like hackers were able to compromise a BigCommerce Application key held by Ribon, which they were able to use to gain access to customer data held on their system,’ Master of Malt stated. The retailer has since reported the incident to the UK Information Commissioner’s Office and has noted that the impact may extend well beyond its own customer base, potentially to hundreds of other stores.

    According to SafeState, Master of Malt’s founder emailed affected customers on the evening of 18 September, within hours of the platform alerting the retailer. That rapid communication stands in contrast to the opacity that often follows third-party supply-chain incidents, where the chain of responsibility between platform, developer, and retailer can slow disclosure considerably.

    Law firm Emery Reddy is already seeking potential claimants linked to the incident, saying several retailers are currently notifying customers about data exposure linked to the Ribon app key theft, without naming them specifically.

    Ribon, Fastr, and the third-party app supply chain

    Ribon is operated by Be A Part Of, a brand under Fastr, which specialises in shopping experience optimisation. In a statement to BleepingComputer, BigCommerce was direct about where the failure occurred: ‘On 17 September 2026, BigCommerce confirmed that credentials belonging to third-party applications Ribon and Ribon 1.5, owned and operated by “Be A Part Of,” a Fastr company, had been compromised and used to inject malicious scripts into a small number of merchant storefronts.’ The company underlined that its own systems and platform were not breached.

    BigCommerce added that it had revoked the attacker’s access by uninstalling the application, notified affected merchants directly, and is providing log data to support Fastr’s investigation. BleepingComputer contacted both Be A Part Of and Fastr but had received no response by publication time.

    The scale of potential exposure across the platform is not trivial. BigCommerce supports over 1,200 third-party applications and integrations, and according to Wiser Review, 75% of BigCommerce merchants use third-party apps from that marketplace. A compromised credential at a single developer can therefore ripple quickly across a large segment of the merchant base, which is precisely what appears to have happened here.

    The incident echoes a 2024 breach involving ZAGG, where attackers compromised the third-party FreshClick BigCommerce app and injected payment-skimming code into its storefront. BigCommerce’s response then was similar: it told BleepingComputer its platform was not breached and removed the compromised app. There is, however, a meaningful difference between the two cases. In the ZAGG incident, attackers captured payment information entered by customers during checkout in real time. In the Ribon case, the attacker used the stolen application key to access existing customer records held within BigCommerce, a direct data extraction rather than a checkout intercept. The distinction matters for affected shoppers: no card details were skimmed, but personal contact and address data was pulled from stored records.

    Master of Malt’s ICO report means UK regulators are now formally in the loop, and with Emery Reddy already assembling potential claimants, the legal dimensions of this breach are unlikely to stay quiet for long.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleMicrosoft 365 Companion Apps Retirement Set for 16 December
    Next Article Zyxel GS1900 Switch Exploit Hits 996 Devices as CISA Orders Federal Patch
    Gary Behan

    Software engineer and video game uber-nerd.

    Related Posts

    EvilTokens PhaaS Takedown: Microsoft Seizes 50 Sites, Two Arrested in UK

    01/10/2026

    BigDiskBuster Windows Defender zero-day exploit freezes antivirus updates

    01/10/2026

    Zyxel GS1900 Switch Exploit Hits 996 Devices as CISA Orders Federal Patch

    01/10/2026

    Microsoft 365 Companion Apps Retirement Set for 16 December

    30/09/2026

    Ireland’s DPC hits Google with €403m location data fine

    30/09/2026

    September Windows Updates Trigger File History Backup Bug Across Windows 10 and 11

    29/09/2026
    Add A Comment

    Comments are closed.

    Categories
    • Apps & Software
    • Artificial Intelligence
    • Business
    • Computing
    • Education
    • Energy
    • Featured
    • Finance
    • Gadgets
    • Gaming
    • Health and Safety
    • Home
    • Lifestyle
    • Marketing
    • Medical
    • News
    • NFT
    • Opinions
    • Social
    • Technology
    • Travel & Tourism
    Mozbot
    Facebook X (Twitter) Instagram Pinterest
    © 2026 M0ZBOT. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.