Security1 publisher3 min readPublished
Attackers used a stolen Ribon app key to read shopper records across BigCommerce stores
A credential held by a third-party app vendor gave attackers four days of access to shopper records in BigCommerce stores. Cutting off that access meant uninstalling the app.
The Watch · Security desk

What happened
- BigCommerce confirmed on September 17, 2026 that credentials for the third-party apps Ribon and Ribon 1.5, operated by Be A Part Of, a Fastr company, had been compromised and used to inject malicious scripts into merchant storefronts.
- The attacker used those credentials to reach shopper data inside BigCommerce environments between September 13 and September 17, according to the company.
- Master of Malt, a UK online spirits vendor that received a notification, says affected shopper details include full names, email addresses, phone numbers and shipping postal addresses.
- BigCommerce says neither its systems nor its platform were breached, and that account passwords and payment card data are stored separately and were not exposed.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- contradiction BigCommerce describes a small number of storefronts while Master of Malt has told regulators and customers the incident may reach hundreds of stores, and the two readings imply very different notification duties across the merchant base.
- exposure A merchant that was never itself compromised still lost shopper records, because the key that opened its store was kept by an app vendor it does not control.
- capability Reading stored customer records through a platform API puts years of order history within reach in one pass, where a checkout skimmer only ever collected what shoppers typed while it was live.
- constraint Merchants cannot close this out on their own timetable: revocation came from the platform uninstalling the app, and the account of what was taken depends on an investigation run by the developer.
Master of Malt, the UK spirits vendor that received one of the notices, told its own customers what happened. "It looks like hackers were able to compromise a BigCommerce Application key held by Ribon, which they were able to use to gain access to customer data held on their system," the retailer said [6]. The credential sat with the app developer, outside the systems the affected merchants run.
BigCommerce's account covers the injection. Credentials for Ribon and Ribon 1.5 "had been compromised and used to inject malicious scripts into a small number of merchant storefronts," the company told BleepingComputer [8]. Master of Malt's account covers the records: full names, email addresses, phone numbers and shipping postal addresses [5]. BigCommerce says account passwords and payment card information are held separately and were not exposed [7].
Access ran from September 13 to September 17, the day BigCommerce confirmed the compromise and removed the apps, so the attacker had four days inside merchant environments [4][2][17]. To revoke that access, BigCommerce uninstalled the app. "Acting in the best interest of our customers and their shoppers, we uninstalled the application from affected stores to revoke the attacker's access, notified those merchants directly, and are providing log data to support the developer's investigation," BigCommerce said [9].
The two public accounts of scope do not agree. BigCommerce's phrase is "a small number of merchant storefronts" [8]. Master of Malt reported the incident to the UK Information Commissioner's Office and said it may extend well beyond its own customers, potentially to hundreds of other stores [10]. Law firm Emery Reddy is seeking claimants and says several unnamed retailers are currently notifying customers about exposure linked to the Ribon app key theft [11]. Be A Part Of and Fastr had not responded to BleepingComputer's questions by publication [12].
Attackers have now stolen an app vendor's BigCommerce key twice. In 2024, attackers compromised the FreshClick app on BigCommerce and injected payment-skimming code into ZAGG's store [13]. BigCommerce said then, as it says now, that its platform was not breached, and it removed the app [14][16]. What the attackers went after was different this time: this key was used to read existing customer records through BigCommerce, where the ZAGG skimmer captured card data as shoppers typed it [15].
Ribon's key is one of many. BigCommerce lists more than 1,200 third-party applications and integrations, Ribon among them, operated by Be A Part Of, a brand of Fastr, which works on shopping experience optimisation [3]. Every one of those that holds a key holds a route into the stores that installed it, and in this incident the forensic work belongs to the developer, with the platform supplying logs [9].
What to watch
- Whether Be A Part Of or Fastr publishes a timeline and a count of affected stores; neither had responded to BleepingComputer by publication.
- Whether the UK Information Commissioner's Office opens an inquiry following Master of Malt's report.
- How many further retailers issue notifications. That count is the public test of BigCommerce's "small number of merchant storefronts" characterisation.