BigCommerce: Ribon / Ribon 1.5 app credentials compromised; malicious scripts on merchant stores (13–17 Sep)
BleepingComputer (21 September 2026) reports BigCommerce alerted merchants after attackers compromised credentials for third-party Ribon and Ribon 1.5 applications (owned/operated by Be A Part Of, a Fastr company) and used them to inject malicious scripts into a small number of merchant storefronts. BigCommerce told BleepingComputer it confirmed the credential compromise on 17 September 2026, uninstalled the apps from affected stores to revoke attacker access, notified merchants, and is providing log data for the developer investigation; it stated BigCommerce platform systems were not breached. UK spirits retailer Master of Malt says shopper data (full names, email, phone, shipping postal addresses) in its BigCommerce environment was accessed between 13 and 17 September and that it reported to the UK ICO; it attributes access to a compromised BigCommerce application key held by Ribon. BigCommerce says account passwords and payment card data are stored separately and were not exposed in this pattern. Wire-primary pending a public Be A Part Of / Fastr advisory. Australia relevance: BigCommerce merchants and any store using Ribon-class experience apps — rotate app keys, review storefront script injections, and run NDB assessment if Australian personal information was in scope.
- Product
- BigCommerce third-party apps Ribon / Ribon 1.5 (Be A Part Of / Fastr) — merchant storefronts
- Exploited in Australia?
- unknown
- Patch to
- BigCommerce Ribon users: confirm app removed / keys revoked; audit storefront scripts and API access logs for 13–17 Sep 2026; rotate remaining third-party app credentials; if Australian personal information may have been accessed, start NDB assessment clock
Primary: BleepingComputer — BigCommerce alerts merchants (Ribon apps; 21 Sep 2026) · Vendor: BigCommerce status (platform operational; no Ribon incident banner at pass time) · OAIC — Notifiable Data Breaches (AU entities assessing vendor/app-key exposure)
