Skip to content
feed: live
>_0dayNews
supply chain
● Breaking

BigCommerce Merchants Breached via Ribon App Credentials

Attackers compromised API keys for third-party Ribon loyalty apps and used them to inject scripts into BigCommerce storefronts, exposing customer contact data from Sept 13-17.

BigCommerce Merchants Breached via Ribon App Credentials
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
airgapMorgan "airgap" Reyes·Published ·1 min read

Compromised API credentials for a third-party integration gave attackers access to an unspecified number of BigCommerce merchant storefronts between September 13 and 17, 2026. BigCommerce confirmed the breach and removed the affected applications on September 17.

The compromised applications were Ribon and Ribon 1.5, loyalty and rewards tools operated by Be A Part Of, a Fastr company. Attackers obtained valid API keys for those apps, then used them to inject malicious scripts into merchant storefronts and pull existing customer records through the BigCommerce API. BigCommerce’s own systems were not compromised, per the company’s statement to BleepingComputer. The apps were the entry point.

Customer data confirmed exposed: full names, email addresses, phone numbers, and shipping postal addresses. Account passwords and payment card data were stored separately and were not in scope, BigCommerce stated.

UK spirits retailer Master of Malt publicly confirmed its storefront was affected and filed a notification with the UK Information Commissioner’s Office. A law firm involved in merchant notifications indicated “several retailers” are now disclosing to customers. BigCommerce has not published a total merchant or customer count.

BigCommerce provided log data to the developer and sent direct notifications to affected merchants. The Ribon applications have been removed from the platform.

Confidence: confirmed, sourced to BigCommerce’s merchant notifications as reported by BleepingComputer. Total affected merchants and customers: unconfirmed as of publication.

Third-party application compromise as a platform entry point is a recurring pattern. September 21 saw attackers steal CrowdSec source code through a TanStack supply-chain attack. In September, JFrog Artifactory flaws were chained to plant backdoors in developer pipelines. API key access with insufficient scope controls is the common denominator across all three.

Found this useful? Share it.