By MFJ Staff | Sources: BleepingComputer, Master of Malt, and Emery Reddy
Key takeaway: Even when payment data itself stays protected, exposed names, emails, phone numbers, and addresses still trigger breach-notification obligations, regulatory reports like Master of Malt’s ICO filing, and potential legal exposure. Merchants relying on third-party storefront apps should treat vendor credential security as part of their own compliance surface, not someone else’s problem.
Attackers compromised credentials for the third-party Ribon and Ribon 1.5 applications used by stores on the BigCommerce platform. They injected malicious scripts into a small number of merchant storefronts, exposing shopper data at multiple retailers.
BigCommerce confirmed the credential compromise on September 17, 2026. Unauthorized access to shopper data occurred between September 13 and September 17, the company said.
Ribon is operated by Be A Part Of, a brand of commerce-technology company Fastr. It’s one of more than 1,200 third-party apps and integrations available on BigCommerce’s platform. UK-based online spirits retailer Master of Malt confirmed it was affected. The company told customers that hackers compromised a BigCommerce application key held by Ribon and used it to access customer data stored on Ribon’s system. Exposed shopper details include full names, email addresses, phone numbers, and shipping addresses.
BigCommerce emphasized that its own platform and systems were not breached, and that the incident was limited to the compromised third-party application. The company said it uninstalled Ribon from affected stores to revoke the attacker’s access. It also notified impacted merchants directly and is providing log data to support the app developer’s investigation.
Account passwords and payment card information are stored separately by BigCommerce and were not exposed in this incident. Master of Malt reported the breach to the UK Information Commissioner’s Office. Based on how widely the Ribon app is used, the retailer said the exposure could extend well beyond its own customers to potentially hundreds of other stores. However, this is Master of Malt’s own estimate rather than a confirmed figure. Law firm Emery Reddy is separately seeking potential claimants tied to the incident. Reportedly, several retailers are notifying customers about the exposure without naming them publicly.
Why it matters: This is the second known BigCommerce third-party app compromise in recent years. A 2024 incident involving the FreshClick app led to payment-card skimming at consumer electronics accessories maker ZAGG. Together, the two incidents underscore that a merchant’s data-security compliance posture depends not just on its own systems but on every third-party app with access to customer data.
Ribon’s breach ran through a compromised application key rather than a platform-level flaw. That gives any merchant using a third-party BigCommerce app reason to review which app credentials can reach customer records, and how quickly those credentials could be revoked if compromised.
Source: BleepingComputer; Master of Malt; Emery Reddy












