BigCommerce Merchants Hit by Data Breach Via Compromised Ribon Apps
Multiple merchants utilizing the **BigCommerce** e-commerce platform have been alerted to data breaches. Attackers leveraged compromised credentials for the third-party **Ribon** applications to inject malicious scripts and access shopper information on various online stores.

Cloud-based Software-as-a-Service (SaaS) e-commerce platform **BigCommerce** has confirmed a data breach impacting several of its merchants. The incident stems from the compromise of credentials for third-party **Ribon** applications, leading to the injection of malicious scripts into online storefronts and unauthorized access to customer data.
### Compromise and Immediate Response
The credential compromise was confirmed on September 17, with **BigCommerce** swiftly removing the affected **Ribon** and **Ribon 1.5** apps to protect its customer base. The company emphasized that its core platform systems were not breached; rather, the attack exploited vulnerabilities within the third-party application's credentials.
### Impact on Merchants and Shoppers
**Master of Malt**, a UK-based online spirits vendor, is among the **BigCommerce** customers who received breach notifications. The retailer stated that attackers accessed shopper information between September 13 and September 17.
Details exposed include full names, email addresses, phone numbers, and shipping postal addresses. Crucially, **BigCommerce** has assured that account passwords and payment card information are stored separately and were not compromised in this incident.
### The Role of Third-Party Applications
**BigCommerce** supports over 1,200 third-party applications and integrations. **Ribon**, operated by **Be A Part Of** (a **Fastr** company), specializes in optimizing shopping experiences. The attackers exploited an application key held by **Ribon** to gain access to customer data stored within the **BigCommerce** environment.
**Master of Malt** has reported the incident to the **UK Information Commissionerβs Office (ICO)**, highlighting concerns that the breach could extend to hundreds of other stores beyond its own customer base. Law firm **Emery Reddy** is actively seeking potential claimants related to the incident, noting that several retailers are notifying customers about data exposure linked to the **Ribon** app key theft.
### Similarities to Past Incidents
This incident bears resemblance to a 2024 breach affecting electronics accessory maker **ZAGG**. In that case, attackers compromised the third-party **FreshClick BigCommerce** app to inject payment-skimming code. While both incidents involved third-party app compromises, the **Ribon** attack specifically targeted existing customer records via a compromised application key, rather than directly skimming payment information during checkout as seen in the **ZAGG** case.