Sep 23, 2026 · 8 min read
BigCommerce Ribon Breach Leaks Shopper Emails and Addresses
Between September 13 and 17, 2026, attackers used a stolen key for Ribon, a third party storefront app from Fastr's Be A Part Of, to read customer records inside BigCommerce stores. UK spirits retailer Master of Malt was hit and has reported it to the ICO. It says hundreds of other stores may be in the same position.
You never installed Ribon. You probably never heard of it. You bought a bottle of whisky, or a phone case, or a pair of running shoes from an online shop, and that shop had once clicked "install" on a small app meant to make its product pages convert better. That click gave the app a key to the store's customer list. Last week somebody else was holding that key, and they read the list page by page for four days.
Key Takeaways
- BigCommerce confirmed on September 17, 2026 that credentials for the third party apps Ribon and Ribon 1.5, owned by Be A Part Of, a Fastr company, had been compromised.
- Master of Malt says the stolen key was used between September 13 and September 17 to access shopper full names, email addresses, phone numbers and shipping postal addresses.
- BigCommerce says account passwords and payment card information are stored separately and were not exposed, and that its own platform was not breached.
- Master of Malt reported the incident to the UK Information Commissioner's Office and says Ribon was installed on hundreds of BigCommerce stores.
- Shoppers at affected stores should expect targeted phishing by email and text that uses their real name, address and the name of a shop they actually buy from.
What Happened in the BigCommerce Ribon Breach?
Attackers obtained API credentials belonging to Ribon, a shopping experience optimization app, and used them to query customer data stored inside BigCommerce merchant accounts. In a statement to SecurityWeek, BigCommerce said the Ribon and Ribon 1.5 credentials "had been compromised due to a Fastr system compromise" and added: "This was not a breach of Commerce systems or the BigCommerce platform."
The timeline, pieced together from both companies' accounts:
- September 13: the attacker starts using the Ribon key to access shopper data.
- September 16: Ribon's developers become aware the key is being misused.
- September 17: the key is revoked and BigCommerce confirms the compromise, then uninstalls the apps from affected stores.
- September 18: BigCommerce begins notifying merchants.
Master of Malt, one of the notified merchants, gave the plainest description. "It looks like hackers were able to compromise a BigCommerce Application key held by Ribon, which they were able to use to gain access to customer data held on their system," the retailer said, as reported by BleepingComputer. Neither Be A Part Of nor Fastr had publicly acknowledged the incident when SecurityWeek and BleepingComputer published.
What Shopper Data Was Exposed?
Master of Malt lists four fields: full names, email addresses, phone numbers and shipping postal addresses. BigCommerce says passwords and card data live in a separate system and were not exposed. The attacker downloaded records "page by page" until the key was cut off, according to Master of Malt's technical writeup cited by SecurityWeek.
One detail deserves more attention than it has received. BigCommerce's own statement says the credentials "were used to inject malicious scripts into a small number of merchant storefronts." Master of Malt describes something different: a bulk read of existing customer records through the API. Those are two separate capabilities. A data pull takes what the store already knows about you. A script on a storefront can watch what you type into that page right now. Nobody has yet said what the injected scripts did or which stores carried them, so shoppers should not assume the "passwords and cards were safe" line covers anything typed into an affected storefront during those four days.
No source says order contents or purchase histories were taken. What the attacker does hold, by definition, is the link between each record and the shop it came from, and that is enough to build a convincing lure.
Why Does a Third Party App Have Access to Customer Records?
Because the merchant granted it. BigCommerce apps receive an access token per store installation, limited by OAuth scopes the merchant approves at install time. The BigCommerce API documentation lists customer scopes such as store_v2_customers and store_v2_customers_read_only, and tells developers to "set the scopes to the minimum level of access your implementation needs."
Here is the uncomfortable part. The same page notes that for app level accounts there is no manual revocation; the token only refreshes when the store owner's email changes or the scopes are modified. So when the developer's systems are breached, an individual merchant has few fast levers. Uninstalling the app is the kill switch, which is exactly what BigCommerce did on the merchants' behalf.
BigCommerce supports over 1,200 third party applications. Each one that holds a customer scope is a route into shopper data that bypasses the platform's own defenses entirely, which is why "the platform was not breached" is accurate and also beside the point for the people whose addresses are now in someone else's spreadsheet.
Has This Happened Before?
Yes, and on the same platform. In 2024 attackers compromised FreshClick, another third party BigCommerce app, and injected payment skimming code into the online store of electronics accessory maker ZAGG. BigCommerce said then, as now, that its platform was not breached and removed the app from customers' stores, BleepingComputer reports.
Put the two incidents side by side and the pattern is clear. The platform hardens its core; attackers go around it through the smallest vendor with a token. We saw the same shape this month when a Brevo supply chain attack pushed malicious scripts onto customer sites, and in August when a fulfilment partner breach exposed 13,689 Trezor customers. The brand on the receipt was never the one that got hacked.
What This Means for Your Inbox
A list of names and emails is spam fodder. A list of names, emails, phone numbers and home addresses tied to a specific shop is a phishing kit. The attacker can write "Hi Sarah, your recent Master of Malt order to 14 Elm Road could not be delivered" and every detail in that sentence except the delivery problem could be real. That is far more convincing than the generic lures that the US Federal Trade Commission warns about, such as messages that "claim there's a problem with your account or your payment information."
If you shop at BigCommerce stores, here are the lures to expect over the coming weeks:
- Delivery problems: a failed delivery or customs fee, sent by text to your leaked phone number, with a link to "reschedule."
- Payment issues: "your card was declined, reenter your details to release your order," which is ironic given card data was not stolen.
- Refunds and compensation: "we are sorry about the data breach, claim your voucher," which turns the breach notice itself into the bait.
- Account resets: a fake "we have reset your password after a security incident" email pointing to a lookalike login page.
The compensation lure is the one to watch. Real breach notices are arriving right now, and the law firm Emery Reddy is already seeking claimants, so a fake notice will sit comfortably in an inbox full of genuine ones. We covered a similar move in the fake ChatGPT billing emails campaign, where a routine account message was the whole trick.
What Should Shoppers Do Now?
You cannot see which apps a store has installed, so the practical signal is a notice from the retailer. Until then, treat order messages from any small online shop with some suspicion:
- Never follow a link in an order, delivery or refund message. Type the shop's address into your browser and check your account there.
- Ignore any request to reenter card details for an order you already paid for.
- Treat texts about parcels with extra caution, since phone numbers were part of the leak.
- In the UK, forward suspicious emails to the NCSC at report@phishing.gov.uk, as the NCSC's reporting service explains.
- If you entered anything into a store's checkout between September 13 and 17, watch your card statement and ask the retailer directly whether its storefront was one of those that carried injected scripts.
What Should Merchants Do Now?
Under UK GDPR the merchant, not the app developer, is typically the controller facing the shopper. The ICO's breach guidance says that if a risk is likely you must notify the regulator "as soon as possible, and where feasible within 72 hours," and tell affected people "without undue delay" when the risk to them is high. Master of Malt has already filed. For any merchant that ran Ribon:
- Check whether BigCommerce contacted you directly, and ask BigCommerce and the app developer for API access logs covering September 13 to 17 for your store.
- Audit every installed app and remove the ones you no longer use. Each unused app with a customer scope is dormant liability.
- Review scopes on the apps you keep. An app that only needs to read product data should not hold customer access.
- Delete and recreate any store level API accounts that share credentials with integrations you cannot vouch for.
- Warn your customers in plain words about the specific lures above, and tell them how you will and will not contact them.
Looking Ahead
The open questions are the important ones. How was Fastr compromised? Were other Fastr products or platforms affected? Which storefronts received injected scripts, and what did those scripts collect? SecurityWeek notes that neither Be A Part Of nor Fastr has said anything publicly.
Until they do, assume the list is out there. The email that lands in your inbox next week will know your name, your street, and where you shop. It will not know your password, which is why it will ask you for it.