Protect.Computer
NEWS

BigCommerce Merchants Hit by Ribon App Data Breach

· 1 min read · Got hacked Identity theft
BigCommerce Merchants Hit by Ribon App Data Breach

Ecommerce platform BigCommerce has notified merchants after attackers compromised API credentials for the third-party Ribon and Ribon 1.5 applications — shopping-experience tools made by Fastr (formerly Be A Part Of) and used by a number of stores on the platform. With those credentials in hand, the attackers injected malicious scripts into affected storefronts and accessed existing customer records stored in BigCommerce. The breach window ran from September 13 to September 17, 2026, when BigCommerce confirmed the compromise and immediately uninstalled the apps to revoke access.

UK spirits retailer Master of Malt is one of the confirmed affected merchants. According to their notification, shoppers’ full names, email addresses, phone numbers, and shipping postal addresses were exposed. BigCommerce says account passwords and payment card numbers are stored in separate systems and were not part of this breach — so the immediate risk is identity-oriented phishing rather than card fraud. Law firm Emery Reddy is already seeking claimants, citing notifications from several retailers, suggesting more affected merchants have not yet been named publicly. The incident echoes a 2024 breach of BigCommerce via the FreshClick app, where attackers instead injected payment-skimming code; this time the access was to stored records rather than live checkout data.

How to check if you’re affected

Affected products include any BigCommerce store that had the Ribon or Ribon 1.5 app installed. As a shopper, you are potentially affected if you placed an order at a UK online retailer between September 13–17, 2026 and have since received an email notification about a data incident. Steps to take:

  • Watch for a direct notification email from any UK online retailer where you shopped recently — merchants are required to notify affected customers.
  • If you receive one, assume your name, email, phone number, and shipping address have been exposed.
  • Be alert for phishing emails in the coming weeks that use your real name and address to appear credible. Treat unexpected delivery, account, or billing emails with extra suspicion.
  • No password change or payment card cancellation is needed — those were not part of this breach.

Sources

Related reading