AI News Feed
Market watch
Cybersecurity

BigCommerce Confirms Supply-Chain Breach After Ribon App Credentials Compromised

BigCommerce confirmed a supply-chain breach tied to compromised Ribon app credentials, exposing merchant customer data.

Master of Malt said the attackers did not obtain passwords, credit card details or other payment information because those are held in a separate system that was not compromised. The retailer said it reported the incident to the UK Information Commissioner's Office. It also disputed BigCommerce's characterization of the scope, saying the attack was not directed at Master of Malt but at Ribon, which was installed on hundreds of BigCommerce stores. Once attackers compromised an access key from Ribon, Master of Malt said, they used it to access data held inside BigCommerce.

BigCommerce told BleepingComputer that credentials belonging to Ribon and Ribon 1.5, owned and operated by 'Be A Part Of,' a Fastr company, had been compromised and used to inject malicious scripts into a small number of merchant storefronts. The company said it uninstalled the application from affected stores to revoke the attacker's access, notified those merchants directly and is providing log data to support the developer's investigation. According to Master of Malt, BigCommerce also told it that the attack had been stopped, that there was no further risk of compromise and that all companies affected by the breach had been contacted.

Ribon is a third-party ecommerce app that provides tools intended to improve the online shopping experience. Some merchants integrate it into their stores to add functionality to customer-facing storefronts and optimize how visitors interact with different parts of a website. It is not known exactly how many stores use Ribon.

BigCommerce is an ecommerce platform similar to Shopify. Businesses use it to build and operate online stores without developing the entire commerce infrastructure themselves. It offers storefronts, shopping carts, integrations with payment providers, product inventories, SEO and marketing tools. The platform has operated since 2009, and a late 2024 SEC filing said it served 5,884 accounts with at least one unique enterprise plan subscription. A 2025 press release said BigCommerce is used by tens of thousands of B2C and B2B companies across 150 countries.

Law firm Emery Reddy is calling for potential claimants over the incident, saying several retailers are notifying customers about data exposure related to the breach, according to BleepingComputer. The firm warned of potential phishing and scam attacks. Master of Malt has reported the attack to the UK ICO.

Editor's Summary BigCommerce confirmed a supply-chain breach in which compromised credentials for the third-party Ribon and Ribon 1.5 apps were used to inject malicious scripts into merchant storefronts between Sept. 13 and Sept. 17, 2026. BigCommerce described the affected group as a small number of storefronts, while Master of Malt said Ribon was installed on hundreds of BigCommerce stores. Master of Malt customers had names, emails, phone numbers and addresses exposed, and the incident has been reported to the UK ICO as a law firm warns of phishing risks.