// 2 ZERO-DAY · 2 CVE · 3 EXPLOIT IN THE LAST 24H
BigCommerce confirmed on September 17, 2026 that compromised credentials for the third-party Ribon app were used to inject malicious scripts into merchant storefronts and access customer data between September 13 and 17. The platform itself was not breached; the attack exploited the legitimate access granted to an external application.

BigCommerce confirmed on September 17, 2026 that compromised credentials for the third-party Ribon application were used to inject malicious scripts into merchant storefronts and access customer data between September 13 and 17. The platform itself was not breached; the attack exploited the legitimate access perimeter granted to an external app.

Key Takeaways
  • Credentials for Ribon and Ribon 1.5, operated by Be A Part Of (brand Fastr), were compromised and used to inject malicious scripts into a limited number of storefronts
  • Unauthorized access to customer data — names, emails, phone numbers, shipping addresses — occurred from September 13 to 17, 2026
  • BigCommerce uninstalled the compromised apps from affected stores to revoke attacker access; account passwords and payment data were not exposed, according to the company statement
  • The case mirrors the 2024 FreshClick breach on the same platform: third-party credential compromise with storefront impact but no direct BigCommerce breach

How the Attack Worked: Ribon's Access Perimeter

Ribon is a shopping experience optimization application operated by Be A Part Of, a Fastr brand. As a third-party app on a SaaS platform, it held privileges sufficient to interact with customer data through BigCommerce interfaces.

According to BigCommerce's statement to BleepingComputer, the app's credentials "were compromised and used to inject malicious scripts into a limited number of merchant storefronts." The source does not specify the technical nature of the "malicious scripts" injected, nor whether they had functionality beyond data access.

Master of Malt, a confirmed affected UK spirits merchant, provided an incident description: "It appears the hackers managed to compromise a BigCommerce application key held by Ribon, which they were able to use to access customer data stored on their system." The phrasing — "BigCommerce application key held by Ribon" — indicates that BigCommerce infrastructure was not breached, but rather the legitimate access channel granted to an external operator.

BigCommerce stated it provided log data to the developer to support their investigation. BleepingComputer contacted Be A Part Of and Fastr without receiving a response by publication time.

Timeline and Exposed Data: Four Days of Unauthorized Access

Unauthorized access occurred between September 13 and 17, 2026, according to convergent statements from BigCommerce, Emery Reddy, and BornCity. BigCommerce confirmed the compromise and revoked credentials on September 17, proceeding to uninstall the apps from affected stores.

Exposed data, per the Master of Malt update cited by BleepingComputer, includes: full names, email addresses, phone numbers, and shipping postal addresses. BigCommerce emphasized that "account passwords and payment card information are stored separately and this type of data was not exposed." This assertion, reported by multiple outlets, has not been independently verified by news organizations.

Master of Malt indicated the breach "could extend well beyond its own customers, potentially to hundreds of other stores." This is an unverified estimate. The exact number of affected merchants and end customers is unknown: sources converge on a "limited number" of directly involved storefronts.

"In the interest of our customers and their shoppers, we have uninstalled the application from affected stores to revoke the attacker's access, notified those merchants directly, and are providing log data to support the developer's investigation." — BigCommerce, via statement to BleepingComputer

The 2024 FreshClick Precedent: A Repeating Pattern

BleepingComputer linked the Ribon incident to a similar 2024 case: the compromise of the third-party FreshClick app, which hit electronics accessory maker ZAGG. In both cases, the mechanism is identical: compromised external application credentials, lateral access to multiple storefronts' data, no direct BigCommerce breach, and a response centered on app uninstallation.

The recurring pattern raises documentable questions. BigCommerce supports approximately 1,200 third-party apps, a figure the brief explicitly classifies as context not directly related to the incident. The brief does not document whether BigCommerce announced changes to third-party app authorization architecture following the FreshClick case. The absence of such information in available sources does not permit asserting that no changes were implemented.

What Changes

The Ribon incident highlights a documented structural constraint: SaaS e-commerce platforms delegate access to third-party apps that can propagate compromises across multiple storefronts. The reactive response — credential revocation, uninstallation, notification — is the standard protocol documented by BigCommerce in both known cases.

For merchants, available verification is limited to checking whether Ribon or Ribon 1.5 are installed in their store and whether BigCommerce sent direct notification. The source does not specify automated audit tools or preventive checks for installed apps.

Master of Malt reported the incident to the UK ICO. Law firm Emery Reddy is seeking potential claimants and indicates several retailers are notifying customers. Emery Reddy explicitly states it has not independently verified certain claims.

Unanswered Questions and Source Limitations

The brief documents significant limits in available information. It is unknown how Ribon credentials were compromised: phishing, leak, brute force, and insider remain unexcluded but unconfirmed vectors. The content and functionality of the injected "malicious scripts" are not specified in sources.

It remains unclear whether exposed data resided on Ribon or BigCommerce systems: sources diverge on this point. No post-compromise activity beyond data access is documented, nor are outcomes of the investigation supported by BigCommerce-provided logs. No CVE or formal security advisory has been identified in sources.

Be A Part Of/Fastr did not respond to BleepingComputer's comment requests. Any regulatory actions beyond Master of Malt's ICO notification are not documented.

Source note: this article relies on corporate statements and journalistic reporting. No independent primary security source with technical analysis of the malicious code or autonomous verification of BigCommerce's claims is available.

Information has been verified against cited sources and is current as of publication.

Sources


Sources and references
  1. bleepingcomputer.com
  2. radar.offseq.com
  3. blog.netmanageit.com
  4. emeryreddy.com
  5. borncity.com
  6. deals.bleepingcomputer.com